User Management with OpenLDAP
Blockchain Platform Manager uses an integrated OpenLDAP server for initial Identity and Access Management (IAM) during installation. This OpenLDAP server manages user credentials and enforces Role-Based Access Control (RBAC) using preconfigured groups. All user information such as credentials and group memberships is stored on this OpenLDAP server.
Enabling the Default LDAP Server
If you choose to enable the default LDAP server for testing, do the following:
- Open Blockchain Platform Manager at
https://controlplane.domainname/console/index.html. - Log in to Blockchain Platform Manager by using the
obpadminusername and the password that you provided during installation. - On the Configuration page, select Authentication Servers.
- Select Save and Set Active.
- Add a new user by selecting Add User.
- Create the Blockchain Platform Manager Administrator user. Once you log out of Blockchain Platform Manager you can log back in with this user rather than the default
obpadminuser created by the installation. - Add any other users as needed. See User Groups and Roles for details about authorization.
Token Issuance and Group Membership Propagation
When an instance is created, Blockchain Platform Manager configures the authentication server to enable token issuance with required claims, including user identity and relevant client/party information. Each token includes group membership information, encapsulated in a payload claim. Instance components use these claims to authorize or block external access to workload pods.
You can add users directly to the OpenLDAP server by using OpenLDAP browsers such as jXplorer. Blockchain Platform Manager administrators can use the administrator user name and password that was provided during installation to connect to openldap.<cp-name>.<cp-domain>:443 with SSL enabled. Once connected, administrators can then add users and assign or modify groups to give the appropriate access levels.