Instead of only using the Picturepark IDS, you can connect an OpenID Provider, which will serve as an Identity Provider to the Picturepark IDS. The desired selected Identity Provider (IdP) must support the standardized Open ID Connect protocol, which itself allows a flexible implementation that varies in required metadata or ACR values.
Expand |
---|
title | Choose Identity Provider |
---|
|
Choose Identity ProviderThe user opens Picturepark by providing the Picturepark URL. She chooses They choose to log in with Picturepark IDS credentials by providing an email and password (1). This will authenticate the user with Picturepark IDS as Identity Provider. If configured she , they can also choose also another external identity provider (2) that will handle the authentication. In the Customer Default Settings, you can set the accent color for the IdP. |
Expand |
---|
title | Create Identity Provider |
---|
|
Create Identity ProviderYou can configure one or many external Identity Providers for authentication. Include Page |
---|
| TERMS:Identity Provider |
---|
| TERMS:Identity Provider |
---|
|
PrerequisitesSetupAdding an external Identity Provider in Picturepark means adding it to the Picturepark IDS. Setup an Identity Provider Open Settings > IdP setup. In the list, choose "Create new identity provider ". - Provide
Enter the details. Save.
Info |
---|
Newly created IdP's or changes made to existing ones could take around a minute to take effect. |
SettingsSetting | Value Example | Description | Name | PictureparkADFSWinServer2016 | A meaningful name that is used as a reference, it cannot be changed afterward. | Display name | Picturepark AD | Something users can relate to, which is shown to the users next to "Continue with" | Type | ADFS | ADFS currently supported in Picturepark. Azure AD currently supported in Picturepark. Others planned to support, but currently not in use.
| Connection protocol | OpenID Connect | IdP must support OpenID Connect. | URL | https://ad.customer.ch/adfs | The Endpoint for OpenID with https. For ADFS something like https://ad.customer.com/adfs. Check this with your IT. For other identity providers, it is the Open ID Connect configuration e.g. https://login.microsoftonline.com/99292bdd-6686-4f0b-817b-f8e8571cf07c/v2.0/.well-know/openid-configuration (Remove everything after the version number of the open id config URL)
Warning |
---|
Do not use the /ls endpoint. If your ADFS URL is https://adfs02.domain.com/adfs/ls then use the URL without /ls: https://adfs5684.domain.com/adfs. |
| Client ID | Application ID e.g. 9df5684-1f10f-4125684-7feb535684 | The ID of your application: | Client secret | GBAyfVL7YWtP6gudLIjbRZV_N0dW4f3x ETiIxqtokEAZ6FAsBtgyIq0MpU1uQ7J0 8xOTO2zwP0OuO3pMVAUTid | This is not needed. You can leave this empty. The authentication flow is the definition of how the tokens to identify users are exchanged. Picturepark external Identity Provider must support Authorization Code Flow with PKCE. PKCE, pronounced “pixy” is an acronym for Proof Key for Code Exchange, which does not require users to provide a client_secret. The standard Authorization Code flow would require this. The main benefit is the reduced risk for native apps, as there are no embedded secrets in the source code and this in return limits exposure to reverse engineering. If the Identity Provider does not support Authorization Code Flow with PKCE, the Client secret can be used. Then the client secret must match the applications client secret. | Sort order | 0 | A number, starting from 0 for the first position, and 1 as the second position. |
After Creating the Identity ProviderAdd claim mappings Add group mappings Add Identity Provider to users
|
Expand |
---|
title | Create Identity Provider (Claim) Mappings |
---|
|
Create Identity Provider (Claim) MappingsYou can configure claim mappings and group mappings for your external Identity Provider. Include Page |
---|
| TERMS:Identity Provider |
---|
| TERMS:Identity Provider |
---|
|
PrerequisitesCreate Claim MappingsOpen Settings > IdP Settings. You will see a setting entry for your new Identity Provider in the list. Doubleclick Double-click to open it. On the right side, in the first tab, you can add the claim mapping: Add claim mapping. Provide the claim name from your AD, which holds the user attributes e.g., company, telephone number. Ensure the correct spelling! Map to Picturepark user attributes.
On the right side in the second tab, you can add the group mapping: Add group mappings. Provide the claim name (issued claims) from your AD, which holds your user group assignments, e.g., Groups. Ensure the spelling is correct spelling!
Define a Fallback user role. The fallback user role of the IdP will only be used if none of the group mappings find a matching role or the default user role is not defined for the Picturepark. This cannot be Super Admins. Map Group names from your AD to user roles in Picturepark.
Note |
---|
Without group mappings , your users will be able to login to Picturepark but will either have only the default role or fallback user role of your Picturepark assigned (if there is any these are configured). You cannot , or will not have any access. Be aware that you can also manually add roles to federated users in Picturepark, but only through group mappings. |
Automatic Claim MappingsThe following attributes are mapped automatically in CP (if not overridden by a claim mapping). Further information about claims here: https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/technical-reference/the-role-of-claims User attribute | Claim types (first to have a value wins) | Email | email, that will be used as a username in Picturepark (mandatory). | sub | User identifier of the user within the IdP (mandatory; provided by ADFS in basic configuration). | First name | given_name | Last name | family_name | Language code | locale |
After Creating Identity Provider MappingsAdd Identity Provider to users
|
Expand |
---|
title | Update Identity Provider |
---|
|
Update Identity ProviderOpen Settings > IdP setup. In the list, choose your desired Identity Provider. Edit the details. You can not cannot update the name, but only the display name.
Save.
Info |
---|
Newly created IdP's or changes made to existing ones could take around a minute to take effect. |
Effects of Updating Identity ProviderUsers cannot log in when their assigned Identity Provider is disabled. The display name will be updated on the login screen. The protocol cannot be changed. If you change the URL, your users' login requests will, from now on, be sent to the new URL. If you change the client ID your ID, your users' login requests will, from now on, contain the new client ID, so you must ensure to have a working IdP with this client ID available. Changes to the Client secret have no effect if authorization code flow with PKCE is used; otherwise, otherwise the client secret must match with the application. Changing the sort order will change the sort order of the buttons on the login form, where 0 is the first position.
|
Expand |
---|
title | Delete Identity Provider |
---|
|
Delete Identity ProviderOpen Settings > IdP setup. In the list, delete your desired Identity Provider.
Before Deleting deleting Identity ProviderOpen Users. Switch Search Mode to Advanced. Search for all users which have the Identity Provider assigned identityProviderId:<id> Update those users, as otherwise, they can no longer login log in to Picturepark.
Effects of Deleting deleting Identity Provider |
Expand |
---|
title | Purge Identity Provider |
---|
|
Purge Identity ProviderOpen Settings > IdP setup. In the list, select your desired Identity Provider. Choose “Purge”. In the confirmation dialogue choose “Purge”dialog, select Purge.
Effects of Purging purging Identity Provider |
...