Configuring single sign-on
Upgrade to IBM Software Hub Version 5.1 before IBM Cloud Pak for Data Version 4.8 reaches end of support. For more information, see Upgrading from IBM Cloud Pak for Data Version 4.8 to IBM Software Hub Version 5.1.
You can use Security Assertion Markup Language (SAML) for single sign-on (SSO) to the IBM Cloud Pak for Data web client.
- Configuring single sign-on using SAML
- Configuring single sign-on using OpenID Connect
For information about which version of IBM Cloud Pak foundational services is installed on your cluster, see Operator and operand versions.
- Who needs to complete this task?
- To complete this task, you must have one of the following roles:
- Cluster administrator
- Instance administrator
- When do you need to complete this task?
- Complete this task if you want to use SAML for SSO to the web client.
It is strongly recommended that you complete this task before you add users to Cloud Pak for Data. If you add users to Cloud Pak for Data before you configure SSO, you must re-add the users with their SAML ID to enable them to use SSO.
Before you begin
Ensure that you source the environment variables before you run the commands in this task.
You must have an existing SAML SSO identity provider (IdP).
Work with your IdP administrator to review this task and gather the information required to connect to your IdP.
Procedure
What to do next
Wait for the usermgmt pods to restart before you attempt to log in to the web
client. If the pods are not running, you will not be able to log in.
- Go directly to the web client log in page by appending the following path to your Cloud Pak for Data URL:
/auth/login/zen-login.html. - Log in to the web client as an administrator with the Manage users permission.
- Add users with their SAML IDs. For details, see Managing users.
Disabling SAML
Procedure
To disable SAML: