Chapter 2. Red Hat Single Sign On for the 3scale Admin Portal
This guide provides information about how to configure and use Red Hat Single Sign On (RH SSO) with the 3scale Admin Portal.
2.1. Enable RH SSO or Auth0 member authentication
3scale supports single sign on (SS0) authentication for your members and admins.
The 3scale Admin Portal supports the following SSO providers, each which support a number of identity brokering and member federation options:
You can enable multiple SSO member authentication types
Only users that have been added to RH SSO or Auth0 will be able to access your 3scale Admin Portal through SSO. If you want to further restrict the access by either roles or user groups you should refer to the corresponding step by step tutorials on the RH SSO or Auth0 support portals.
Once you have established SSO through your chosen provider, you must configure it and enable it on the 3scale Admin Portal.
2.1.1. RH SSO prerequisites
- An RH SSO instance and realm configured as described under the Developer Portal authentication section of the documentation.
2.1.2. Auth0 prerequisites
- An Auth0 Subscription and account
2.1.3. Enable RH SSO
As an administrator, perform the following steps in the 3scale admin panel to enable RH SSO or Auth0:
- Ensure your preferred SSO provider, highlighted in the prerequisites, has been properly configured
Navigate to SSO Integrations in the Account Settings:
- Click the gear icon in the upper right corner of the page
- Navigate to Account Settings (gear icon) > Users > SSO Integrations, and click New SSO Integration.
- Select your SSO provider from the dropdown list
Enter the required information, provided when you configured your SSO:
- Client
- Client Secret
- Realm or Site
- Click Create Authentication Provider
If, during testing, you encounter a callback URL mismatch, add the callback URL shown in the error message to your Auth0 allowed callback URLs.
2.2. Using RH SSO with 3scale
Once you have configured SSO, members can sign on using the account credentials in connected IdPs.
Follow these steps to log in to the 3scale Admin Portal using SSO:
Navigate to your 3scale login page:
https://<organization>-admin.3scale.net/p/login
- Authorize 3scale with your IdP
- If necessary, complete sign up by entering any needed information
Once you successfully sign up, you will have a member account under the API provider organization, and you will be automatically logged in.
2.3. Redirecting a 3scale login to a RH SSO option
These steps will show the 3scale API Management administrator how to redirect to an Identity Provider (IdP) login screen (RH SSO). Complete these steps and your 3scale account will be accessible through an optional single sign-on (SSO) login page.
2.3.1. Prerequisites
- 3scale 2.5
- An RH SSO instance and realm configured as described under the Configuring RH SSO section of the Developer Portal authentication documentation.
Before you can integrate RH SSO with 3scale, you must have a working RH SSO instance. Refer to the RH SSO documentation for installation instructions: Installing RH-SSO 7.2.
2.3.2. Required steps
- Access and follow the instructions for setting up RH SSO under the Red Hat Single Sign On for the 3scale Admin Portal section of the 3scale documentation.
Provide your RH SSO administrator with your 3scale URL. The URL will form the basis for a redirect within RH SSO for your secure logon.
https://<organization>-admin.3scale.net/auth/<system_name>/bounce
The system_name assumes RH SSO has been used as the SSO provider in your 3scale instance with an id of rhsso:
https://<organization>-admin.3scale.net/auth/rhsso/bounce
To get the id in your 3scale instance navigate to:
https://<organization>.3scale.net/p/admin/account/authentication_providers/<ID>
You will see:
The Callback URL
https://<organization>.3scale.net/auth/keycloak_0123456aaaaa/callback
- Where keycloak_0123456aaaaa is the system name and is used in the bounce URL.
- Navigate to the new RH SSO URL and securely log in to your 3scale account.