Authentication for service Accounts in Aveksa
I want to create a local account in Aveksa, similar to AveksaAdmin but with least privileges and to use default Aveksa Authentication, mainly to by pass SSO.
I have followed the steps in the below link
- Created a trusted source system using a csv to store service account and password.
- Added the aveksa priveleges to call the webservices
- But the next step tells to add the trusted source system as an authentication source but i can only see 3 types of authentiction sources present LDAP/AD or SSO. or TestProvider
How do i "Add the trusted source system as an authentication source".
- Access & Change Requests
- Community Thread
- Forum Thread
- Identity G&L
- Identity Governance & Lifecycle
- RSA Identity
- RSA Identity G&L
- RSA Identity Governance & Lifecycle
- RSA Identity Governance and Lifecycle
- RSA IGL
LDAP is the only source (for direct bind) supported.
You should create the service account in AD in specific OU and collect them as identities. You can configure an AD auth source.
I was referring to the below discussion:-
My requirement is to have some local accounts who can authenticate in Aveksa like Aveksa Admin
I would like some clarity on the below.
"Create the service account in a trusted source system. This could a directory, a database or even a CSV file if you adequately secure the file. Add the service account with a secure password to the trusted source. Collect the service account into Aveksa as an identity. Add the relevant Aveksa privileges to the user to be able to call the web services that are required. Add the trusted source system as an authentication source. When you login using the web service authenticate with the credentials in your source system. You only need to do this for web services that require authentication, some REST web services do not require an authentication token."
That's true. In my use-case we wanted just two additional accounts so we created two such IDCs and gave different password for each.
I will be interested too in any alternate solution.