OAuth authentication
Points to note
-
NetScaler Advanced Edition and higher is required for the solution to work.
-
A NetScaler appliance must be on version 12.1 or later for the appliance to work as an OAuth IdP using OIDC.
-
OAuth on a NetScaler appliance is qualified for all SAML IdPs that are compliant with "OpenID connect 2.0".
Configure the OpenID Connect protocol
Advantages of having the OpenID Connect support
-
OIDC eliminates the overhead of maintaining multiple authentication passwords as the user has a single identity across the organization.
-
OIDC provides a robust security for your password as the password is shared only with your identity provider and not with any application you access.
-
OIDC has vast interoperability with various systems making it easier for the hosted applications to accept OpenID.
-
OIDC is a simple protocol that enables native clients to easily integrate with servers.
To configure a NetScaler appliance as an IdP using the OpenID Connect protocol by using GUI
-
Navigate to Configuration > Security > AAA-Application Traffic > Policies > Authentication > Advanced Policies > OAuth IdP.
-
Click Profile and click Add.On the Create Authentication OAuth IDP Profile screen, set values for the following parameters and click Create.
-
Name – Name of the authentication profile.
-
Client ID – Unique string that identifies SP.
-
Client Secret – Unique secret that identifies SP.
-
Redirect URL – Endpoint on SP to which code/token has to be posted.
-
Issuer Name – String that identifies IdP.
-
Audience – Target recipient for the token being sent by IdP. This might be checked by the recipient.
-
Skew Time – The time for which the token remains valid.
-
Default Authentication Group – A group added to the session for this profile to simplify policy evaluation and help in customizing policies.
-
-
Click Policies and click Add.
-
On the Create Authentication OAuth IDP Policy screen, set values for the following parameters and click Create.
-
Name – The name of the authentication policy.
-
Action – Name of profile created earlier.
-
Log Action –Name of message log action to use when a request matches this policy. Not a mandatory filed.
-
Undefined-Result Action – Action to perform if the result of policy evaluation is undenfined(UNDEF). Not a mandatory field.
-
Expression – Advanced policy expression that the policy uses to respond to specific request. For example, true.
-
Comments – Any comments about the policy.
-
Binding the OAuthIdP policy and LDAP policy to the authentication virtual server
-
Navigate to Configuration > Security > AAA-Application Traffic > Policies >Authentication > Advanced Policies > Actions > LDAP.
-
On LDAP Actions screen, click Add.
-
On Create Authentication LDAP Server screen, set the values for the following parameters, and click Create.
-
Name – The name of the LDAP action
-
ServerName/ServerIP – Provide FQDN or IP of the LDAP server
-
Choose appropriate values for Security Type, Port, Server Type, Time-Out
-
Make sure Authentication is checked
-
Base DN – Base from which to start LDAP search. For example, dc=aaa,dc=local.
-
Administrator Bind DN: User name of the bind to LDAP server. For example, admin@aaa.local.
-
Administrator Password/Confirm Password: Password to bind LDAP
-
Click Test Connection to test your settings.
-
Server Logon Name Attribute: Choose “sAMAccountName”
-
Other fields are not mandatory and hence can be configured as required.
-
-
Navigate to Configuration > Security > AAA-Application Traffic > Policies >Authentication > Advanced Policies > Policy.
-
On Authentication Policies screen, click Add.
-
On Create Authentication Policy page, set the values for the following parameters, and click Create.
-
Name – Name of the LDAP Authentication Policy.
-
Action Type – Choose LDAP.
-
Action – Choose the LDAP action.
-
Expression – Advanced policy expression that the policy uses to respond to specific request. For example, true**.
-
To configure the NetScaler appliance as an IdP using the OpenID Connect protocol by using CLI
-
add authentication OAuthIDPProfile <name> [-clientID <string>][-clientSecret ][-redirectURL <URL>][-issuer <string>][-audience <string>][-skewTime <mins>] [-defaultAuthenticationGroup <string>] -
add authentication OAuthIdPPolicy <name> -rule <expression> [-action <string> [-undefAction <string>] [-comment <string>][-logAction <string>] -
add authentication ldapAction aaa-ldap-act -serverIP 10.0.0.10 -ldapBase "dc=aaa,dc=local" -
ldapBindDn <administrator@aaa.local> -ldapBindDnPassword <password> -ldapLoginName sAMAccountName -
add authentication policy aaa-ldap-adv-pol -rule true -action aaa-ldap-act -
bind authentication vserver auth_vs -policy <ldap_policy_name> -priority 100 -gotoPriorityExpression NEXT -
bind authentication vserver auth_vs -policy <OAuthIDPPolicyName> -priority 5 -gotoPriorityExpression END -
bind vpn global –certkey <>
jwks\_uri query (https://gw/oauth/idp/certs).