Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC OpenManage Enterprise 3.9 User's Guide

OpenManage Enterprise login using OpenID Connect providers

You can log in using OpenID Connect (OIDC) providers. OpenID Connect providers are the identity and user management software that allow users to securely access applications. Currently, OpenManage Enterprise provides support for PingFederate and Keycloak.

WARNING User roles and scopes are reset to 'default' on client re-registration with OIDC provider PingFederate (PingIdentity). This issue might lead to resetting of the privileges and scope of non-admin roles (DM and Viewer) to that of the Administrator. Re-registration of the appliance console with OIDC provider is triggered in the event of an appliance upgrade, change in network configuration, or change in SSL certificate.

To avoid security concerns post any of the above-mentioned re-registration events, the administrator must reconfigure all the OpenManage Enterprise Client IDs on the PingFederate site. Also, it is highly recommended that Client IDs are created only for Administrator users with Pingfederate till this issue is resolved.

NOTE

Prerequisites:

Before enabling an OpenID Connect provider login you must:
  1. Add an OIDC provider in the OpenManage Enterprise: In OpenManage Enterprise Application Settings, add an OpenID Connect provider. When you add the OpenID Connect provider, a Client ID is generated for the OpenID Connect provider. For more information, see: Add an OpenID Connect provider to OpenManage Enterprise.
  2. Configure the OpenID Connect provider using the Client ID: In the OpenID Connect provider, locate the Client ID and define a login role (Administrator, Device Manager or Viewer) by adding and mapping the scope called dxcua (Dell extended claim for user authentication). For more information, see:
When you add an OpenID Connect provider in OpenManage Enterprise, it is listed on the Application Settings > Users > OpenID Connect Providers page. The following OIDC provider details are displayed:
  • Name - The OpenID Connect provider's name when it was added in the appliance
  • Enabled - A 'check' on this field indicates that the OpenID Connect provider is enabled in the appliance
  • Discovery URI - The URI (Uniform Resource Identifier) of the OpenID Connect provider
  • Registration Status - Can be one of the following:
    • Successful - Indicates a successful registration with the OpenID Connect provider
    • Failed - Indicates an unsuccessful registration with the OpenID Connect provider. The 'Failed' OpenID Connect provider registration will not be allowed even when they are enabled.
    • In Progress - This status is displayed when the appliance tries to register with OpenID Connect provider.

On the right pane, Client ID, Registration Status, Discovery URI are displayed for the selected OpenID Connect provider. You can click See details to view the certificate details of the OpenID Connect provider.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\