Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC OpenManage Enterprise Version 3.5 User's Guide

Configure an OpenID Connect provider policy in PingFederate for role-based access to OpenManage Enterprise

To enable OpenManage Enterprise OpenID Connect login using PingFederate, you must add and map a scope dxcua (Dell extended claim for user authentication) to the Client ID and define the user privileges as follows:

NOTE The default assigning algorithm should be RS256 (RSA Signature with SHA-256).
  1. Add an 'exclusive' or 'default' scope called dxcua under Scope Management in OAuth Settings.
  2. Map the scope created in OpenID Connect Policy Managment > Policy using the following steps:
    1. Enable Include User info in Token
    2. In the Attribute Scope, add the scope and attribute value as dxcua.
    3. In Contract fulfillment, add dxcua and select the type as 'Text'. Then, define the user privileges for OpenManage Enterprise OpenID Connect provider login using one of the following attributes:
      1. Administrator: dxcua : [{“Role": "AD"}]
      2. Device Manager: dxcua : [{“Role": "DM"}]
      3. Viewer: dxcua : [{“Role": "VE"}]
    4. If an 'exclusive' scope is configured after the client registration in OpenManage Enterprise, edit the configured client in PingFederate and enable the created 'dxcua' exclusive scope.
  3. Dynamic client registration should be enabled in PingFederate for OpenManage Enterprise client registration. If the 'Require Initial access token' option is unselected in OpenID Connect provider client settings, the registration will work with Username and password. If the option is enabled, then the registration will work only with the Initial Access token.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\