PingAuthorize

Setting up Kong Gateway

Download, install, and configure the ping-auth plugin to set up Kong Gateway with PingAuthorize.

Steps

  1. Install the plugin by running the luarocks install kong-plugin-ping-auth command.

  2. After installation, load the plugin into Kong by editing the plugins = bundled,ping-auth property in the kong.conf file.

  3. Restart Kong Gateway.

  4. To confirm the plugin loads successfully, look for the debug-level Loading plugin: ping-auth message in Kong’s error.log file.

Use the Kong Gateway UI or the Kong Gateway API to complete Kong Gateway setup.

Setting up Kong Gateway using the UI

Steps

  1. In Kong Manager, select the default workspace, and then click Plugins.

    Screen capture of the Plugins window in the default workspace of Kong Manager with the ping-auth plugin loaded
  2. Next to the ping-auth plugin, click Edit, and then click the toggle to enable the plugin.

    Screen capture of the Update ping-auth plugin window enabling the ping-auth plugin in Kong Manager
  3. (Optional) To enable the plugin for specific consumers, services, or routes, click Scoped, and then enter Service, Route, and Consumer information as needed.

  4. Connect Kong Gateway to PingAuthorize.

    1. In the Config.Service URL field in Kong Manager, enter the hostname of your PingAuthorize Server instance and the port of the HTTPS Connection Handler.

      For example, https://pingauthorize:8443.

      To find the HTTPS Connection Handler port number in the PingAuthorize administrative console, go to Configuration > System > Connection Handlers.

    2. In the PingAuthorize administrative console, copy the PingAuthorize sideband client’s shared secret you created in Preparing PingAuthorize for Kong Gateway integration.

    3. In the Config.Shared Secret field, paste the shared secret.

    4. Make sure the Config.Secret Header Name value in Kong Manager matches the secret header name configured for the Sideband API Servlet Extension in PingAuthorize.

      Screen capture of the Config.Shared Secret and Config.Service Url configuration for the ping-auth plugin in Kong Manger
  5. (Optional) Configure the rest of the optional fields in Kong Manager or the API.

    Option API Field Name Description

    Config.Connection KeepAlive Ms

    connection_keepAlive_ms

    The duration to keep the connection alive for reuse. The default is 60000.

    Config.Connection Timeout Ms

    connection_timeout_ms

    The duration to wait before the connection times out. The default is 10000.

    Config.Enable Debug Logging

    enable_debug_logging

    Controls if requests and responses are logged at the debug level. The default is false. For log messages to show in error.log, you must set log_level = debug in kong.conf.

    Config.Verify Service Certificate

    verify_service_certificate

    Controls whether the service certificate is verified. This is intended for testing purposes and the default is true.

  6. Click Update, and then click Update Plugin.

Result

Kong Gateway is now configured to work with PingAuthorize.