1"use strict";(self.webpackChunkrabbitmq_website=self.webpackChunkrabbitmq_website||[]).push([["18085"],{6873(e,n,t){t.r(n),t.d(n,{metadata:()=>i,default:()=>d,frontMatter:()=>o,contentTitle:()=>a,toc:()=>c,assets:()=>l});var i=JSON.parse('{"id":"oauth2-examples-entra-id/index","title":"Use Microsoft Entra ID (previously known as Azure AD) as OAuth 2.0 server","description":"\x3c!--","source":"@site/versioned_docs/version-4.1/oauth2-examples-entra-id/index.md","sourceDirName":"oauth2-examples-entra-id","slug":"/oauth2-examples-entra-id/","permalink":"/docs/4.1/oauth2-examples-entra-id/","draft":false,"unlisted":false,"editUrl":"https://github.com/rabbitmq/rabbitmq-website/tree/main/versioned_docs/version-4.1/oauth2-examples-entra-id/index.md","tags":[],"version":"4.1","frontMatter":{"title":"Use Microsoft Entra ID (previously known as Azure AD) as OAuth 2.0 server","displayed_sidebar":"docsSidebar"},"sidebar":"docsSidebar","previous":{"title":"Auth0","permalink":"/docs/4.1/oauth2-examples-auth0"},"next":{"title":"Google","permalink":"/docs/4.1/oauth2-examples-google"}}'),s=t(74848),r=t(28453);let o={title:"Use Microsoft Entra ID (previously known as Azure AD) as OAuth 2.0 server",displayed_sidebar:"docsSidebar"},a="Use Microsoft Entra ID (formerly known as Microsoft Azure AD) as OAuth 2.0 server",l={},c=[{value:"Prerequisites to follow this guide",id:"prerequisites-to-follow-this-guide",level:2},{value:"Register your app",id:"register-your-app",level:2},{value:"Create OAuth 2.0 roles for your app",id:"create-oauth-20-roles-for-your-app",level:2},{value:"Create a role to allow access to Management UI",id:"create-a-role-to-allow-access-to-management-ui",level:3},{value:"Create a role to grant configure permission on all resources",id:"create-a-role-to-grant-configure-permission-on-all-resources",level:3},{value:"Assign App Roles to Users",id:"assign-app-roles-to-users",level:2},{value:"Create a Scope for Management UI Access",id:"create-a-scope-for-management-ui-access",level:2},{value:"Configure Custom Signing Keys",id:"configure-custom-signing-keys",level:2},{value:"Configure RabbitMQ to Use Entra ID as OAuth 2.0 Authentication Backend",id:"configure-rabbitmq-to-use-entra-id-as-oauth-20-authentication-backend",level:2},{value:"Start RabbitMQ",id:"start-rabbitmq",level:2},{value:"Automatic generation of a TLS Certificate and Key Pair",id:"automatic-generation-of-a-tls-certificate-and-key-pair",level:2},{value:"Verify RabbitMQ Management UI access",id:"verify-rabbitmq-management-ui-access",level:2}];function h(e){let n={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"use-microsoft-entra-id-formerly-known-as-microsoft-azure-ad-as-oauth-20-server",children:"Use Microsoft Entra ID (formerly known as Microsoft Azure AD) as OAuth 2.0 server"})}),"\n",(0,s.jsx)(n.p,{children:"This guide explains how to set up OAuth 2.0 for RabbitMQ\nand Microsoft Entra ID as Authorization Server using the following flows:"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:"Access the management UI via a browser using Entra ID (API version 2.0)"}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"prerequisites-to-follow-this-guide",children:"Prerequisites to follow this guide"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["Have an ",(0,s.jsx)(n.a,{href:"https://portal.azure.com.",children:"Azure account"})]}),"\n",(0,s.jsx)(n.li,{children:"Docker"}),"\n",(0,s.jsx)(n.li,{children:"OpenSSL"}),"\n",(0,s.jsxs)(n.li,{children:["A local clone of a ",(0,s.jsx)(n.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/tree/next",children:"GitHub repository"})," (the ",(0,s.jsx)(n.code,{children:"next"})," branch) that contains all the configuration files and scripts used on this example."]}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"register-your-app",children:"Register your app"}),"\n",(0,s.jsxs)(n.p,{children:["When using ",(0,s.jsx)(n.strong,{children:"Entra ID as OAuth 2.0 server"}),", your client app (in our case RabbitMQ) needs a way to trust the security tokens issued to it by the ",(0,s.jsx)(n.strong,{children:"Microsoft identity platform"}),"."]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["The first step in establishing that trust is by ",(0,s.jsx)(n.strong,{children:"registering your app"})," with the identity platform in Entra ID."]}),"\n",(0,s.jsx)(n.admonition,{type:"tip",children:(0,s.jsxs)(n.p,{children:["Learn more about ",(0,s.jsx)(n.a,{href:"https://docs.microsoft.com/en-us
1/azure/active-directory/develop/quickstart-register-app",children:"app registration in Entra ID"})]})}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Once you have logged onto your account in ",(0,s.jsx)(n.a,{href:"https://portal.azure.com",children:"Entra ID Portal"}),", go to **Entra ID ** (use the search bar if you are not able to easily find it)."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["In the left-hand navigation menu, click on ",(0,s.jsx)(n.strong,{children:"App Registrations"}),". Then, select ",(0,s.jsx)(n.strong,{children:"New registration"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["In the ",(0,s.jsx)(n.strong,{children:"Register an application"})," pane, provide the following information:"]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Name"}),": the name you would like to give to your application (ex: ",(0,s.jsx)(n.em,{children:"rabbitmq-oauth2"}),")"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Supported Account Types"}),": select ",(0,s.jsx)(n.strong,{children:"Accounts in this organizational directory only (Default Directory only - Single tenant)"})," (this guide will focus on this option for simplicity)"]}),"\n",(0,s.jsxs)(n.li,{children:["On the ",(0,s.jsx)(n.strong,{children:"Select a platform"})," drop-down list, select ",(0,s.jsx)(n.strong,{children:"Single-page application (SPA)"})]}),"\n",(0,s.jsxs)(n.li,{children:["Configure the ",(0,s.jsx)(n.strong,{children:"Redirect URI"})," to: ",(0,s.jsx)(n.code,{children:"https://localhost:15671/js/oidc-oauth/login-callback.html"})]}),"\n"]}),"\n",(0,s.jsx)(n.admonition,{type:"important",children:(0,s.jsxs)(n.p,{children:["Entra ID only allows ",(0,s.jsx)(n.code,{children:"https"})," URIs as ",(0,s.jsx)(n.strong,{children:"Redirect URI"}),". To learn how to ",(0,s.jsx)(n.a,{href:"./management#single-listener-https",children:"enable HTTPS for RabbitMQ management UI"}),"\non port ",(0,s.jsx)(n.code,{children:"15671"}),", see the management UI guide."]})}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Register"}),"."]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.img,{alt:"Entra ID OAuth 2.0 App",src:t(68505).A+"",width:"1902",height:"469"})}),"\n",(0,s.jsxs)(n.p,{children:["Note the following values, as you will need it later to configure the ",(0,s.jsx)(n.code,{children:"rabbitmq_auth_backend_oauth2"})," on RabbitMQ side:"]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:"Directory (tenant ID)"}),"\n",(0,s.jsx)(n.li,{children:"Application (client) ID"}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"create-oauth-20-roles-for-your-app",children:"Create OAuth 2.0 roles for your app"}),"\n",(0,s.jsxs)(n.p,{children:["App roles are defined by using the ",(0,s.jsx)(n.a,{href:"https://portal.azure.com",children:"Entra ID portal"})," during the app registration process. When a user signs in to your application, Entra ID emits a ",(0,s.jsx)(n.code,{children:"roles"})," claim for each role that the user or service principal has been granted (you will have a look at it at the end of this tutorial)."]}),"\n",(0,s.jsx)(n.admonition,{type:"info",children:(0,s.jsxs)(n.p,{children:["To learn more about roles in Entra ID, see ",(0,s.jsx)(n.a,{href:"https://docs.microsoft.com/en-us/azure/active-directory/develop/howto-add-app-roles-in-azure-ad-apps",children:"Entra ID documentation"})]})}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Still in ",(0,s.jsx)(n.a,{href:"https://portal.azure.com",children:"Entra ID Portal"}),", go back to ",(0,s.jsx)(n.strong,{children:"Entra ID"})," home page."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["In the left-hand menu, click on ",(0,s.jsx)(n.strong,{children:"App Registrations"})," and then click on your ",(0,s.jsx)(n.strong,{children:"application name"})," to open your application ",(0,s.jsx)(n.strong,{children:"Overview"})," pane."]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(n.h3,{id:"create-a-role-to-allow-access-to-management-ui",children:"Create a role to allow access to Management UI"}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["In the left-hand menu, click on ",(0,s.jsx)(n.strong,{children:"App Roles"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Then, click on ",(0,s.jsx)(n.strong,{children:"Create App Role"})," to create an OAuth 2.0 role that will be used to give access to the RabbitMQ Management UI."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsx)(n.p,{children:"On the right menu that has just opened, provide the requested information:"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Display Name"}),": the name you want to give to the role (ex: ",(0,s.jsx)(n.em,{children:"Management UI Admin"}),")"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Allowed member types"}),": Both (Users/Groups + Applications)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Value"}),": ",(0,s.jsx)(n.code,{children:"{Application_ID}.tag:administrator"})," (where ",(0,s.jsx)(n.em,{children:"Application_ID"})," is the value of the ",(0,s.jsx)(n.em,{children:"Application (client) ID"})," noted earlier in this tutorial)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Description"}),": briefly describe what this role aims to (here just to give admin access to the RabbitMQ Management UI)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Do you want to enable this app role"}),": ",(0,s.jsx)(n.code,{children:"yes"})," (check the box)"]}),"\n"]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Apply"}),"."]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(n.h3,{id:"create-a-role-to-grant-configure-permission-on-all-resources",children:"Create a role to grant configure permission on all resources"}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Create App Role"})," again. You are now going to create an OAuth 2.0 role that will be used to give configure access to all the resources on all the RabbitMQ vhosts."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsx)(n.p,{children:"On the right menu that has just opened, fill the form as below:"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Display Name"}),": the name you want to give to the role (ex: ",(0,s.jsx)(n.em,{children:"Configure All Vhosts"}),")"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Allowed member types"}),": Both (Users/Groups + Applications)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Value"}),": ",(0,s.jsx)(n.code,{children:"{Application_ID}.configure:*/*"})," (where ",(0,s.jsx)(n.em,{children:"Application_ID"})," is the value of the ",(0,s.jsx)(n.em,{children:"Application (client) ID"})," noted earlier in this tutorial)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Description"}),": briefly describe what this role aims to (here to give permissions to configure all resources on all the vhosts available on the RabbitMQ instance)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Do you want to enable this app role"}),": ",(0,s.jsx)(n.code,{children:"yes"})," (check the box)"]}),"\n"]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Apply"}),"."]}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"assign-app-roles-to-users",children:"Assign App Roles to Users"}),"\n",(0,s.jsx)(n.p,{children:"Now that some roles have been created for your application, you still need to assign these to some users."}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Still in ",(0,s.jsx)(n.a,{href:"https://portal.azure.com",children:"Entra ID Portal"}),", go back to ",(0,s.jsx)(n.strong,{children:"Entra ID"})," home page and, in the left-hand menu, click on ",(0,s.jsx)(n.strong,{children:"Enterprise Applications"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["In the new left-hand menu, select ",(0,s.jsx)(n.strong,{children:"Manage -> All applications"}),". Use the ",(0,s.jsx)(n.strong,{children:"Search Bar"})," and/or the available filters to find your application."]}),"\n",(0,s.jsx)(n.p,{children:(0,s.jsx)(n.img,{alt:"Entra ID Enterprise Applications",src:t(78701).A+"",width:"1905",height:"379"})}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on the application you just created, for which you want to assign roles to users/groups, then, in the left-hand navigation menu, Select ",(0,s.jsx)(n.strong,{children:"Manage -> Users and groups"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Add user/group"})," to open the ",(0,s.jsx)(n.strong,{children:"Add Assignment"})," pane."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Below ",(0,s.jsx)(n.strong,{children:"Users"}),", click on ",(0,s.jsx)(n.em,{children:"None Selected"})," and, on the ",(0,s.jsx)(n.strong,{children:"Users"})," pane that has just opened on the right, search and select the users/groups you want to assign roles to."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Once you've selected users and groups, click on the ",(0,s.jsx)(n.strong,{children:"Select"})," button."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Back to the ",(0,s.jsx)(n.strong,{children:"Add assignment"})," pane, below ",(0,s.jsx)(n.strong,{children:"Select a Role"}),", click on ",(0,s.jsx)(n.em,{children:"None Selected"})," and, on the ",(0,s.jsx)(n.strong,{children:"Select a role"})," pane that has just opened on the right, search and select the role you want to assign to the selected users."]}),"\n",(0,s.jsx)(n.admonition,{type:"tip",children:(0,s.jsx)(n.p,{children:"If only one role is available for your application, it would be automatically selected and greyed by default."})}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsxs)(n.p,{children:["Choose a role (only a single role can be selected at a time), click on the ",(0,s.jsx)(n.strong,{children:"Select"})," button, and click on the ",(0,s.jsx)(n.strong,{children:"Assign"})," button to finalize the assignment of users and groups to the app."]}),"\n"]}),"\n",(0,s.jsxs)(n.li,{children:["\n",(0,s.jsx)(n.p,{children:"Repeat the operations for all the roles you want to assign."}),"\n"]}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"create-a-scope-for-management-ui-access",children:"Create a Scope for Management UI Access"}),"\n",(0,s.jsxs)(n.p,{children:["There is one last configuration step required. Without this step, the ",(0,s.jsx)(n.code,{children:"access_token"})," returned\nby ",(0,s.jsx)(n.strong,{children:"Entra ID"}
1)," is invalid. RabbitMQ cannot validate its signature because the ",(0,s.jsx)(n.code,{children:"access_token"})," is meant for Microsoft resources.\nFirst, you need to create a scope associated to the application you registered for RabbitMQ management UI as follows:"]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["Go to ",(0,s.jsx)(n.strong,{children:"App registrations"}),"."]}),"\n",(0,s.jsx)(n.li,{children:"Click on your application."}),"\n",(0,s.jsxs)(n.li,{children:["Go to ",(0,s.jsx)(n.strong,{children:"Manage"})," option on the left menu and choose the option ",(0,s.jsx)(n.strong,{children:"Expose an API"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Add a scope"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:["Enter a name, eg. ",(0,s.jsx)(n.code,{children:"management-ui"}),". Enter the same name for ",(0,s.jsx)(n.strong,{children:"Admin consent display name"})," and a description and save it."]}),"\n",(0,s.jsxs)(n.li,{children:["The scope is named ",(0,s.jsx)(n.code,{children:"api://{Application (client) ID}/{scope_name}"}),"."]}),"\n"]}),"\n",(0,s.jsx)(n.p,{children:"Check out the last section to see how this scope is used to configure RabbitMQ."}),"\n",(0,s.jsx)(n.h2,{id:"configure-custom-signing-keys",children:"Configure Custom Signing Keys"}),"\n",(0,s.jsxs)(n.p,{children:["While creating a signing key for the application is optional, if a custom key is created, RabbitMQ must be configured accordingly.\nIn the following example, replace ",(0,s.jsx)(n.code,{children:"{Application(client) ID}"})," with the actual ",(0,s.jsx)(n.em,{children:"Application(client) ID"}),"."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-ini",children:"auth_oauth2.discovery_endpoint_params.appid = {Application(client) ID}\n"})}),"\n",(0,s.jsxs)(n.p,{children:["For more information, check out Microsoft Entra documentation about ",(0,s.jsx)(n.a,{href:"https://learn.microsoft.com/en-us/entra/identity-platform/jwt-claims-customization#validate-token-signing-key",children:"configuring custom signing keys"}),"."]}),"\n",(0,s.jsx)(n.h2,{id:"configure-rabbitmq-to-use-entra-id-as-oauth-20-authentication-backend",children:"Configure RabbitMQ to Use Entra ID as OAuth 2.0 Authentication Backend"}),"\n",(0,s.jsxs)(n.p,{children:["The configuration on ",(0,s.jsx)(n.strong,{children:"Entra ID"})," side is done. Next, configure RabbitMQ to use these resources."]}),"\n",(0,s.jsxs)(n.p,{children:["Clone ",(0,s.jsx)(n.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/tree/next/conf/entra/rabbitmq.conf.tmpl",children:"rabbitmq.conf.tmpl"})," from the tutorial repository\nto ",(0,s.jsx)(n.code,{children:"rabbitmq.conf"}),". It must be in the same directory as ",(0,s.jsx)(n.code,{children:"rabbitmq.conf.tmpl"}),"."]}),"\n",(0,s.jsxs)(n.p,{children:["Edit the new ",(0,s.jsx)(n.code,{children:"rabbitmq.conf"})," file and proceed as follows:"]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:["Replace ",(0,s.jsx)(n.code,{children:"{Directory (tenant) ID}"})," with the value gathered earlier as ",(0,s.jsx)(n.strong,{children:"Application (client) ID"})]}),"\n",(0,s.jsxs)(n.li,{children:["Replace ",(0,s.jsx)(n.code,{children:"{Application(client) ID}"})," with the value gathered as ",(0,s.jsx)(n.strong,{children:"Application (client) ID"})]}),"\n",(0,s.jsxs)(n.li,{children:["If you decide to configure your application with custom signing(s), you need to uncomment the following configuration line. This is required otherwise the ",(0,s.jsx)(n.code,{children:"jwks_uri"})," endpoint announced by the OpenID Discovery endpoint does not contain applications' custom signing keys."]}),"\n"]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-ini",children:"#...\n\nmanagement.oauth_enabled = true\nmanagement.oauth_client_id = {Application(client) ID}\nmanagement.oauth_scopes = openid profile api://{Application(client) ID}/rabbitmq\n\nauth_oauth2.resource_server_id = {Application(client) ID}\nauth_oauth2.additional_scopes_key = roles\nauth_oauth2.issuer = https://login.microsoftonline.com/{Directory (tenant) ID}/v2.0\n\n#...\n"})}),"\n",(0,s.jsx)(n.h2,{id:"start-rabbitmq",children:"Start RabbitMQ"}),"\n",(0,s.jsx)(n.p,{children:"Run the following commands to run RabbitMQ docker image:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"export MODE=entra\nmake start-rabbitmq\n"})}),"\n",(0,s.jsxs)(n.p,{children:["This starts a Docker container named ",(0,s.jsx)(n.code,{children:"rabbitmq"}),", with RabbitMQ Management UI/API with HTTPS enabled, and configured to use your Entra ID as OAuth 2.0 authentication backend,\nbased on the information you provided in ",(0,s.jsx)(n.code,{children:"rabbitmq.conf"})," in the previous steps of this tutorial."]}),"\n",(0,s.jsx)(n.h2,{id:"automatic-generation-of-a-tls-certificate-and-key-pair",children:"Automatic generation of a TLS Certificate and Key Pair"}),"\n",(0,s.jsx)(n.admonition,{type:"important",children:(0,s.jsxs)(n.p,{children:["Entra ID only allows ",(0,s.jsx)(n.code,{children:"https"})," URIs as ",(0,s.jsx)(n.strong,{children:"Redirect URI"}),". To learn how to ",(0,s.jsx)(n.a,{href:"./management#single-listener-https",children:"enable HTTPS for RabbitMQ management UI"}),"\non port ",(0,s.jsx)(n.code,{children:"15671"}),", see the management UI guide."]})}),"\n",(0,s.jsxs)(n.p,{children:["When you run ",(0,s.jsx)(n.code,{children:"make start-rabbitmq"})," for the first time with ",(0,s.jsx)(n.code,{children:"MODE=entra"}),", before RabbitMQ is deployed, a TLS certificate is generated for RabbitMQ so that it listens on HTTPS port 15671."]}),"\n",(0,s.jsxs)(n.p,{children:["The script generates the following files in ",(0,s.jsx)(n.code,{children:"conf/entra/certs"}),":"]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"cacert.pem"}),": a custom certificate authority that is used to generate and sign a self signed certificate for RabbitMQ"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"cert.pem"}),": a self-signed certificate (cn=localhost)"]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"key.pem"}),": the private key associated to the ",(0,s.jsx)(n.code,{children:"cert.pem"})," certificate"]}),"\n"]}
1),"\n",(0,s.jsxs)(n.p,{children:["These files will be mounted into the ",(0,s.jsx)(n.code,{children:"rabbitmq"})," container later in this tutorial,\nwhere they will be used to configure HTTPS for the RabbitMQ Management UI and HTTP API."]}),"\n",(0,s.jsx)(n.h2,{id:"verify-rabbitmq-management-ui-access",children:"Verify RabbitMQ Management UI access"}),"\n",(0,s.jsxs)(n.p,{children:["Go to RabbitMQ Management UI ",(0,s.jsx)(n.code,{children:"https://localhost:15671"}),". Depending on your browser, ignore the security warnings (raised by the fact that you are using a self-signed certificate) to proceed."]}),"\n",(0,s.jsxs)(n.p,{children:["Once on the RabbitMQ Management UI page, click on the ",(0,s.jsx)(n.strong,{children:"Click here to log in"})," button,\nauthenticate with your ",(0,s.jsx)(n.strong,{children:"Entra ID user"}),". The first time, you are likely going to have to give your\nconsent (it depends on the policies applied to Entra AD on your side)."]}),"\n",(0,s.jsxs)(n.admonition,{type:"tip",children:[(0,s.jsxs)(n.p,{children:["At first login, you may run into an error name ",(0,s.jsx)(n.code,{children:"AADSTS90008"}),". This is a ",(0,s.jsx)(n.a,{href:"https://docs.microsoft.com/en-us/ansrs/questions/671457/after-34accept34-on-consent-prompt-on-azure-sso-lo.html#answer-893848",children:"known issue"}),"."]}),(0,s.jsxs)(n.p,{children:["Click on ",(0,s.jsx)(n.strong,{children:"Click here to log in"})," button again and it will disappear."]})]}),"\n",(0,s.jsx)(n.p,{children:"At the end, you should be redirected back to the RabbitMQ Management UI."}),"\n",(0,s.jsxs)(n.p,{children:["Entra AD issues an access token like this one below. The permissions are managed in the ",(0,s.jsx)(n.code,{children:"roles"})," claim.\nYou have configured RabbitMQ with ",(0,s.jsx)(n.code,{children:'{extra_scopes_source, <<"roles">>},'})," which means RabbitMQ uses\nthe scopes in the ",(0,s.jsx)(n.code,{children:"roles"})," claim to define permissions for a logged-in user."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-javascript",children:'{\n "aud": "30b61ef8-72d7-4e40-88f2-6e16c8d3fd88",\n "iss": "https://sts.windows.net/1ffc6121-590e-4aa5-bf47-c348674069cb/",\n "iat": 1655740039,\n "nbf": 1655740039,\n "exp": 1655744211,\n "acr": "1",\n "aio": "AUQAu/8TAAAAjvwucwL4nZe83vNZvg6A7sAPscI9zsGvRs8EuT7aVhubpmhRnxJ+X7nbkISoP5eBBMxoi2yiCclnH2Ocjjzsqw==",\n "amr": [\n "wia"\n ],\n "appid": "30b61ef8-72d7-4e40-88f2-6e16c8d3fd88",\n "appidacr": "1",\n "email": "[email protected]",\n "idp": "https://sts.windows.net/b3f4f7c2-72ce-4192-aba4-d6c7719b5766/",\n "in_corp": "true",\n "ipaddr": "xxx.xxx.xxx.xxx",\n "name": "Baptiste DA ROIT",\n "oid": "cf2df3b4-03df-4e1e-b5c0-f232932aaead",\n "rh": "0.AR8AgCG80x7L90C1mhVBBXQzQjgoklctsdBMtgYVWFwc4tgfAMQ.",\n "roles": [\n "30b61ef8-72d7-4e40-88f2-6e16c8d3fd88.tag:monitoring",\n "30b61ef8-72d7-4e40-88f2-6e16c8d3fd88.configure:*/*"\n ],\n "scp": "User.Read",\n "sub": "6aBzW3a1FOTTrnlZEuC1SmwG0sRjVgQU49DvrYK6Rqg",\n "tid": "1ffc6121-590e-4aa5-bf47-c348674069cb",\n "unique_name": "[email protected]",\n "uti": "QHqwThTqQEK9iMdnRuD_AA",\n "ver": "1.0"\n}\n'})})]})}function d(e={}){let{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(h,{...e})}):h(e)}},78701(e,n,t){t.d(n,{A:()=>i});let i=t.p+"assets/images/entra-id-enterprise-application-5096b0a8ab809b3d1807c36a215c7ea1.png"},68505(e,n,t){t.d(n,{A:()=>i});let i=t.p+"assets/images/entra-id-oauth-registered-app-42abf8a92f1960c11d7b574c72355966.png"},28453(e,n,t){t.d(n,{R:()=>o,x:()=>a});var i=t(96540);let s={},r=i.createContext(s);function o(e){let n=i.useContext(r);return i.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:o(e.components),i.createElement(r.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.