API authentication with the NetScaler appliance
Token types
API Access with OAuth
set aaaparameter -APITokenCache <ENABLED>
Virtual server for API Access
Add lb vserver lb-api-access SSL <IP> 443 -authn401 On -AuthnVsName auth-api-access
Bind ssl vserver lb-api-access -certkeyName <ssl-cert-entity>
Add authentication vserver auth-api-access SSL
OAuth Configuration for ID Tokens
Add authentication OAuthAction oauth-api-access -clientid <your-client-id> -clientsecret <your-client-secret> -authorizationEndpoint <URL to which users would be redirected for login> -tokenEndpoint <endpoint at which tokens could be obtained> -certEndpoint <URL at which public keys of IdP are published>
-
Client ID – Unique string that identifies SP. Authorization server infers client configuration using this ID. Maximum Length: 127.
-
Client Secret – Secret string established by user and authorization server. Maximum Length: 239.
-
authorizationEndpoint - URL at which users would normally log in (when using interactive clients).
-
tokenEndpoint - URL on Authorization Server at which tokens/code are obtained/exchanged
-
certEndpoint - URL at which Authorization Server publishes public keys used to sign the tokens. Authorization Server can publish more than one key and choose one of them to sign tokens.Note:Client ID/Client Secret/authorizationEndpoint/TokenEndpoint are optional parameters for API Access. However, it is a good practice to provide values for these parameters as the action entity can be reused for different purposes.
OAuth Configuration for opaque access tokens
set oauthAction oauth-api-acccess -introspectURL <URL of the Authorization Server for introspection>
https://tools.ietf.org/html/rfc7662#section-2.1 as follows:
POST /introspect HTTP/1.1
Host: server.example.com
Accept: application/json
Content-Type: application/x-www-form-urlencoded
Authorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW
token=mF_9.B5f-4.1JqM&token_type_hint=access_token
Binding policy to Authentication virtual server
add authentication policy oauth-api-access -rule <> -action <oauth-api-access>
bind authentication vserver auth-api-access -policy oauth-api-access -pri 100
Additional security settings on a NetScaler appliance
add policy patset oauth_audiences
bind patset oauth_audiences https://app1.company.com
bind patset oauth_audiences https://app2.company.com
bind patset oauth_audiences httpsL//app1.company.com/path1
set oAuthAction oauth-api-access -audience oauth_audiences
set oAuthAction oauth-api-access -allowedAlgorithms RS256 RS512
Bypassing certain traffic from authentication
add authentication policy auth-bypass-policy -rule <> -action NO_AUTHN
bind authentication vserver auth-api-access -policy auth-bypass-policy -pri 110