Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC OpenManage Enterprise 3.9 User's Guide

Configure an OpenID Connect provider policy in Keycloak for role-based access to OpenManage Enterprise

To enable OpenManage Enterprise OpenID Connect login using Keycloak, you must first add and map a scope dxcua to the Client ID and define the user privileges as follows:

About this task

NOTE The Discovery URI specified in the OpenID Connect provider configuration wizard should have a valid endpoint of the provider listed.

Steps

  1. In the Attributes section of Keycloak Users, define the 'Key and Value' for OpenManage Enterprise login roles using one of the following attributes:
    • Administrator : dxcua : [{"Role": "AD"}]
    • Device Manager: dxcua : [{"Role": "DM"}]
      NOTE To restrict access of the device manager to select device groups, say G1 and G2, in OpenManage Enterprise use dxcua : [{“Role": "DM", "Entity":"G1, G2"}]
    • Viewer: dxcua : [{"Role": "VE"}]
  2. Once the client is registered in Keycloak, in the Mappers section, add a "User Attribute" mapper type with below values:
    • Name: dxcua
    • Mapper Type: User Attribute
    • User Attribute: dxcua
    • Token Claim Name: dxcua
    • Claim Json Type: String
    • Add to ID Token: enable
    • Add to access Token: Enable
    • Add to user info: Enable

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\