Click Settings and then go to .
- Go to Common Token Provider . and select
- In the Issuer field, enter the OIDC provider’s issuer identifier.
- Optional: In the Description field, enter a description for the token provider.
- To record requests to the OIDC provider to the audit store, select the Audit check box.
- If required, click + Add Query Parameter and enter custom query parameter name and value pairs used by the OIDC provider.
In the Trusted Certificate Group list, select the group
of certificates to use when authenticating to the OIDC provider.
PingAccess requires the certificate in use by the OIDC provider to anchor to a certificate in the associated Trusted Certificate Group.
To configure advanced settings, click Show
To use a configured proxy, select the Use Proxy
If the node is not configured with a proxy, requests are made directly to the token provider. See Adding proxies for more information about creating proxies.
Select the Use Single-Logout check box to enable
single logout (SLO)when the /pa/oidc/logout/ endpoint receives a request to clear the cookie containing the PingAccess token. single logout (SLO) SLO The process of signing a user out of multiple sites where the user has started a single sign-on (SSO) session.
If you select this option, PingAccess sends a logout request to the token provider after receiving a request at the /pa/oidc/logout/ endpoint. The token provider then completes a full SLO flow.Note:
To use this feature, you must configure SLO on the OIDC provider.
Select the Track id_token check box to track the
id_token that the authorization server provides
after authentication within the PingAccess session cookie.
Token providers can use the id_token attribute to identify and locate a user’s session. Some token providers may require an id_token_hint parameter for SLO, but not all. For more information on this configuration, see the table entry Include id_token_hint in SLO in step 8 of Configuring admin UI SSO authentication.Important:
Tracking the id_token attribute increases the PingAccess cookie's size. This could make the cookie exceed the browser's limit. For more information, see Minimizing the PingAccess cookie size.
- Select Request Supported Scopes Only to limit the requested scopes to those advertised in the OIDC metadata.
- To use a configured proxy, select the Use Proxy check box.
- Click Save.
After you have successfully configured the token provider, click View Metadata to display the metadata provided by the token provider. To update the metadata, click .