<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Use openid-configuration file for OIDC login setup in ArcGIS Enterprise Ideas</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-ideas/use-openid-configuration-file-for-oidc-login-setup/idi-p/1368641</link>
    <description>&lt;P&gt;Add a button in the OIDC login setup to read the openid-configuration metadata endpoint.&lt;/P&gt;&lt;P&gt;ArcGIS Enterprise Portal supports OpenIDConnect (OIDC) login from an upstream identity provider; this is a modern standard which is replacing the older SAML authentication.&lt;/P&gt;&lt;P&gt;In the configuration documentation (&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm" target="_blank"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm&lt;/A&gt;), it suggests that the user should open the [server]/.well-known/openid-configuration JSON file and extract 6 values from it and put them into the login configuration fields.&amp;nbsp; This should be automated by having the form pull values from that configuration file directly.&amp;nbsp; The openid-configuration JSON follows a standard (&lt;A title="OpenID-Connect Metadata Standard" href="https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata" target="_self"&gt;https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata&lt;/A&gt;) designed precisely for this use case, where an application needs to be configured to work with an upstream identity provider.&lt;/P&gt;&lt;P&gt;By adding an input for the openid-configuration endpoint and a button to pull that data, 6 fields could be auto-populated: Provider issuer ID, OAuth 2.0 authorization URL, Token URL, JWKS URL, User profile URL, and Logout URL.&amp;nbsp; Having this automated would simplify the setup experience for the user and reduce the potential for errors.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint" style="width: 892px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/91139i0E97AFBF708680B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="openid-configuration-esri.png" alt="Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 21:30:03 GMT</pubDate>
    <dc:creator>BillMitchell</dc:creator>
    <dc:date>2024-01-10T21:30:03Z</dc:date>
    <item>
      <title>Use openid-configuration file for OIDC login setup</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/use-openid-configuration-file-for-oidc-login-setup/idi-p/1368641</link>
      <description>&lt;P&gt;Add a button in the OIDC login setup to read the openid-configuration metadata endpoint.&lt;/P&gt;&lt;P&gt;ArcGIS Enterprise Portal supports OpenIDConnect (OIDC) login from an upstream identity provider; this is a modern standard which is replacing the older SAML authentication.&lt;/P&gt;&lt;P&gt;In the configuration documentation (&lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm" target="_blank"&gt;https://enterprise.arcgis.com/en/portal/latest/administer/windows/openid-connect-logins.htm&lt;/A&gt;), it suggests that the user should open the [server]/.well-known/openid-configuration JSON file and extract 6 values from it and put them into the login configuration fields.&amp;nbsp; This should be automated by having the form pull values from that configuration file directly.&amp;nbsp; The openid-configuration JSON follows a standard (&lt;A title="OpenID-Connect Metadata Standard" href="https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata" target="_self"&gt;https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata&lt;/A&gt;) designed precisely for this use case, where an application needs to be configured to work with an upstream identity provider.&lt;/P&gt;&lt;P&gt;By adding an input for the openid-configuration endpoint and a button to pull that data, 6 fields could be auto-populated: Provider issuer ID, OAuth 2.0 authorization URL, Token URL, JWKS URL, User profile URL, and Logout URL.&amp;nbsp; Having this automated would simplify the setup experience for the user and reduce the potential for errors.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint" style="width: 892px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/91139i0E97AFBF708680B1/image-size/large?v=v2&amp;amp;px=999" role="button" title="openid-configuration-esri.png" alt="Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Screenshot of the OIDC configuration screen in ArcGIS Portal, showing several fields that could be populated from the openid-configuration metadata endpoint&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 21:30:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/use-openid-configuration-file-for-oidc-login-setup/idi-p/1368641</guid>
      <dc:creator>BillMitchell</dc:creator>
      <dc:date>2024-01-10T21:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Use openid-configuration file for OIDC login setup</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-ideas/use-openid-configuration-file-for-oidc-login-setup/idc-p/1566245#M4029</link>
      <description>&lt;P&gt;For what it's worth, this would be relatively simple enhancement to incorporate.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 15:33:26 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-ideas/use-openid-configuration-file-for-oidc-login-setup/idc-p/1566245#M4029</guid>
      <dc:creator>BillMitchell</dc:creator>
      <dc:date>2024-12-09T15:33:26Z</dc:date>
    </item>
  </channel>
</rss>

