4 User Management and Identity Providers
You can choose to use the built-in OpenLDAP service or use your own identity provider.
In addition to LDAP-based authentication, Blockchain Platform Manager supports integration with external Identity Management systems (IdMs) via OpenID Connect (OIDC). This enables the use of industry-standard authentication protocols for enhanced interoperability.
If you use OpenLDAP, you can create users in LDAP which can then log into the Blockchain Platform Manager.
If you use an external OIDC provider, you must create a confidential client in the provider, log in to Blockchain Platform Manager, save the configuration with the client credentials of the confidential client, and then save and mark it as active. You will then get a Blockchain Platform Manager callback URL which you can configure as a redirect URI in the confidential client in the provider. After this, any user in the provider assigned to confidential client can log in to the Blockchain Platform Manager console.
All groups must be created in the provider as expected in Blockchain Platform Manager, desired users must be mapped to the groups and both the users and the groups must be assigned to confidential client in the provider. Role-based access control in the platform enforced through group membership of users.
Note:
Only one identity provider is allowed per installation. You cannot enable both the default OpenLDAP identity provider and then enable an external OIDC provider.