1"use strict";(self.webpackChunkrabbitmq_website=self.webpackChunkrabbitmq_website||[]).push([["19114"],{18816(e,n,t){t.r(n),t.d(n,{metadata:()=>s,default:()=>d,frontMatter:()=>o,contentTitle:()=>a,toc:()=>c,assets:()=>l});var s=JSON.parse('{"id":"oauth2-examples-okta","title":"Use Okta as OAuth 2.0 server","description":"\x3c!--","source":"@site/versioned_docs/version-4.0/oauth2-examples-okta.md","sourceDirName":".","slug":"/oauth2-examples-okta","permalink":"/docs/4.0/oauth2-examples-okta","draft":false,"unlisted":false,"editUrl":"https://github.com/rabbitmq/rabbitmq-website/tree/main/versioned_docs/version-4.0/oauth2-examples-okta.md","tags":[],"version":"4.0","frontMatter":{"title":"Use Okta as OAuth 2.0 server","displayed_sidebar":"docsSidebar"},"sidebar":"docsSidebar","previous":{"title":"Keycloak","permalink":"/docs/4.0/oauth2-examples-keycloak"},"next":{"title":"Multiple OAuth 2.0 Servers","permalink":"/docs/4.0/oauth2-examples-multiresource"}}'),i=t(74848),r=t(28453);let o={title:"Use Okta as OAuth 2.0 server",displayed_sidebar:"docsSidebar"},a="Use Okta as OAuth 2.0 server",l={},c=[{value:"Prerequisites to follow this guide",id:"prerequisites-to-follow-this-guide",level:2},{value:"Create your app integration in Okta UI",id:"create-your-app-integration-in-okta-ui",level:2},{value:"Create Okta OAuth 2.0 Authorization Server, Scopes and Claims",id:"create-okta-oauth-20-authorization-server-scopes-and-claims",level:2},{value:"Create Groups to Allow Access to Management UI",id:"create-groups-to-allow-access-to-management-ui",level:3},{value:"Assign App and Users to Groups",id:"assign-app-and-users-to-groups",level:2},{value:"Configure RabbitMQ to use Okta as OAuth 2.0 Authentication Backend",id:"configure-rabbitmq-to-use-okta-as-oauth-20-authentication-backend",level:2},{value:"Start RabbitMQ",id:"start-rabbitmq",level:2},{value:"Verify RabbitMQ Management UI Access",id:"verify-rabbitmq-management-ui-access",level:2}];function h(e){let n={a:"a",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,r.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.header,{children:(0,i.jsx)(n.h1,{id:"use-okta-as-oauth-20-server",children:"Use Okta as OAuth 2.0 server"})}),"\n",(0,i.jsx)(n.p,{children:"Demonstrate how to authenticate using OAuth 2.0 protocol\nand Okta as Authorization Server using the following flows:"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["Access ",(0,i.jsx)(n.a,{href:"./management/",children:"management UI"})," via a browser"]}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"prerequisites-to-follow-this-guide",children:"Prerequisites to follow this guide"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:["Have an ",(0,i.jsx)(n.a,{href:"https://www.okta.com",children:"Okta account"})]}),"\n",(0,i.jsx)(n.li,{children:"Docker"}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.code,{children:"git clone https://github.com/rabbitmq/rabbitmq-oauth2-tutorial"}),". This github repository\ncontains all the configuration files and scripts used on this example"]}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"create-your-app-integration-in-okta-ui",children:"Create your app integration in Okta UI"}),"\n",(0,i.jsxs)(n.p,{children:["When using ",(0,i.jsx)(n.strong,{children:"Okta as OAuth 2.0 server"}),", your client app (in our case RabbitMQ) needs a way to trust the security tokens issued to it by the ",(0,i.jsx)(n.strong,{children:"Okta OIDC Sign-In Widget"}),"."]}),"\n",(0,i.jsxs)(n.p,{children:["The first step in establishing that trust is by ",(0,i.jsx)(n.strong,{children:"creating your app"})," with the identity platform in Okta. To learn more about App registration in Okta,\nplease refer to ",(0,i.jsx)(n.a,{href:"https://help.okta.com/en-us
1/Content/Topics/Apps/Apps_App_Integration_Wizard_OIDC.htm",children:"Okta documentation"}),"."]}),"\n",(0,i.jsxs)(n.p,{children:["Once you have logged onto your account in ",(0,i.jsx)(n.a,{href:"https://www.okta.com",children:"Okta"}),", follow below steps:"]}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsx)(n.li,{children:"In the Admin Console, go to Applications."}),"\n",(0,i.jsx)(n.li,{children:"Click Create App Integration."}),"\n",(0,i.jsx)(n.li,{children:"To create an OIDC app integration, select OIDC - OpenID Connect as the Sign-in method."}),"\n",(0,i.jsx)(n.li,{children:"Choose the type of application to integrate with Okta. Select Web Application, Single-Page Application, or Native Application. In our use case it is Single-Page Application(SPA)."}),"\n",(0,i.jsx)(n.li,{children:"Click Next."}),"\n"]}),"\n",(0,i.jsx)(n.p,{children:"The App Integration Wizard for OIDC has three sections:"}),"\n",(0,i.jsx)(n.p,{children:"In General Settings, provide the following information:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Name"}),": App integration name: Specify a name for your app integrationn (ex: ",(0,i.jsx)(n.em,{children:"rabbitmq-oauth2"}),")"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Grant type"}),": Select ",(0,i.jsx)(n.strong,{children:"Authorization Code"})," and ",(0,i.jsx)(n.strong,{children:"Refresh Token"})]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Redirect URI"}),":","\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:["On the ",(0,i.jsx)(n.strong,{children:"Sign-in redirect URIs"})," type ",(0,i.jsx)(n.a,{href:"http://localhost:15672/js/oidc-oauth/login-callback.html",children:"http://localhost:15672/js/oidc-oauth/login-callback.html"})]}),"\n",(0,i.jsxs)(n.li,{children:["Configure the ",(0,i.jsx)(n.strong,{children:"Sign-out redirect URIs"})," to ",(0,i.jsx)(n.a,{href:"https://localhost:15672",children:"https://localhost:15672"})]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,i.jsxs)(n.p,{children:["In Trusted Origins (for Web and Native app integrations), choose ",(0,i.jsx)(n.strong,{children:"keep the default values"}),"."]}),"\n",(0,i.jsxs)(n.p,{children:["In Assignments, choose ",(0,i.jsx)(n.strong,{children:"Allow everyone in your organization to access"}),"."]}),"\n",(0,i.jsxs)(n.p,{children:["Finally, click on ",(0,i.jsx)(n.strong,{children:"Save"})," and write down the following values, as you will need them later to configure RabbitMQ:"]}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:(0,i.jsx)(n.strong,{children:"ClientID"})}),"\n",(0,i.jsx)(n.li,{children:(0,i.jsx)(n.strong,{children:"Okta domain name"})}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"create-okta-oauth-20-authorization-server-scopes-and-claims",children:"Create Okta OAuth 2.0 Authorization Server, Scopes and Claims"}),"\n",(0,i.jsx)(n.p,{children:"An authorization server is used to authenticate users and issue access tokens that can be used to access protected resources. In Okta, an authorization server can be used to define scopes, which are essentially permissions that determine what resources a user can access. By defining scopes, you can control the level of access that different users have to your resources."}),"\n",(0,i.jsxs)(n.p,{children:["Here are the steps to create scopes for ",(0,i.jsx)(n.code,{children:"admin"})," and ",(0,i.jsx)(n.code,{children:"dev"})," groups using the default authorization server in Okta:"]}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Log in to your Okta account and navigate to the ",(0,i.jsx)(n.strong,{children:"Authorization Servers"})," tab in the Okta Console under ",(0,i.jsx)(n.strong,{children:"Security-> API"}),"."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Click on the default authorization server that is provided."}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Click on the ",(0,i.jsx)(n.strong,{children:"Scopes"})," tab and then click the ",(0,i.jsx)(n.strong,{children:"Add Scope"})," button."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Enter ",(0,i.jsx)(n.code,{children:"admin"})," as the name of the scope and a description if desired."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Repeat step 4 to create a scope for ",(0,i.jsx)(n.code,{children:"dev"}),"."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Save your changes."}),"\n"]}),"\n"]}),"\n",(0,i.jsxs)(n.p,{children:["And below are the steps to create a claim for ",(0,i.jsx)(n.strong,{children:"role"})," to distinguish ",(0,i.jsx)(n.code,{children:"admin"})," and ",(0,i.jsx)(n.code,{children:"dev"})," groups when authenticating using the default authorization server in Okta:"]}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Log in to your Okta account and navigate to the ",(0,i.jsx)(n.strong,{children:"Authorization Servers"})," tab in the Okta Console under ",(0,i.jsx)(n.strong,{children:"Security-> API"}),"."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Click on the default authorization server that is provided."}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Click on the ",(0,i.jsx)(n.strong,{children:"Claims"})," tab and then click the ",(0,i.jsx)(n.strong,{children:"Add Claim"})," button."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Enter ",(0,i.jsx)(n.code,{children:"role"})," as the name of the claim."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Choose ",(0,i.jsx)(n.strong,{children:"Access Token"})," as Include in token type."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Choose ",(0,i.jsx)(n.strong,{children:"Expression"})," as Value type"]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["In ",(0,i.jsx)(n.strong,{children:"Value"})," field enter the following expression:\n",(0,i.jsx)(n.code,{children:'isMemberOfGroupName("admin") ? "admin" : isMemberOfGroupName("monitoring") ? "monitoring" : ""'})]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Click on create."}),"\n"]}),"\n"]}),"\n",(0,i.jsxs)(n.p,{children:[(0,i.jsx)(n.strong,{children:"Note"}),": the expression above returns a claim named ",(0,i.jsx)(n.code,{children:"role"})," with value ",(0,i.jsx)(n.code,{children:"admin"})," if the user is a member of the ",(0,i.jsx)(n.code,{children:"admin"})," group, and ",(0,i.jsx)(n.code,{children:"monitoring"})," if the user is a member of the ",(0,i.jsx)(n.code,{children:"monitoring"})," group:"]}),"\n",(0,i.jsx)(n.h3,{id:"create-groups-to-allow-access-to-management-ui",children:"Create Groups to Allow Access to Management UI"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Log in to your Okta Admin Dashboard and navigate to the ",(0,i.jsx)(n.strong,{children:"Groups"}
1)," page by clicking on the ",(0,i.jsx)(n.strong,{children:"Groups"})," tab in the top menu."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Click the ",(0,i.jsx)(n.strong,{children:"Add Group"})," button in the top right corner of the page."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["In the ",(0,i.jsx)(n.strong,{children:"Add Group"})," dialog box, enter a name for the group in the ",(0,i.jsx)(n.strong,{children:"Group Name"})," field. You can also enter a description for the group in the ",(0,i.jsx)(n.strong,{children:"Description"})," field, although this is optional."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["If you want to add members to the group right away, you can do so by clicking the ",(0,i.jsx)(n.strong,{children:"Add People"})," button in the ",(0,i.jsx)(n.strong,{children:"Members"})," section of the dialog box. You can search for users by name or email address, and add them to the group by selecting their name and clicking the ",(0,i.jsx)(n.strong,{children:"Add"})," button."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["If you want to set group rules, you can do so by clicking the ",(0,i.jsx)(n.strong,{children:"Rules"})," tab in the dialog box. Group rules allow you to automatically add or remove users from the group based on criteria such as their email domain, job title, or department."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Once you've finished configuring the group, click the ",(0,i.jsx)(n.strong,{children:"Create Group"})," button to create the group."]}),"\n"]}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"assign-app-and-users-to-groups",children:"Assign App and Users to Groups"}),"\n",(0,i.jsxs)(n.p,{children:["Next step is to assign a user to a group in Okta, and grant them access to an app associated with that group. For our use case we want to assign some users\nto ",(0,i.jsx)(n.code,{children:"dev"})," and ",(0,i.jsx)(n.code,{children:"admin"})," group and assign the ",(0,i.jsx)(n.code,{children:"rabbitmq-oauth2"})," app to both groups."]}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Log in to your Okta Admin Dashboard and navigate to the ",(0,i.jsx)(n.strong,{children:"Users"})," page by clicking on the ",(0,i.jsx)(n.strong,{children:"Directory"})," tab in the top menu, and then selecting ",(0,i.jsx)(n.strong,{children:"People"}),"."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Find the user you want to assign to the groups, and click on their name to open their user profile."}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["In the user profile, click on the ",(0,i.jsx)(n.strong,{children:"Groups"})," tab to view the groups that the user is currently a member of."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["To add the user to a group, click the ",(0,i.jsx)(n.strong,{children:"Add Group"})," button in the top right corner of the page. Select the group you want to add the user to from the list of available groups, and click the ",(0,i.jsx)(n.strong,{children:"Add"})," button to add the user to the group."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["To grant the user access to an app associated with the group, navigate to the ",(0,i.jsx)(n.strong,{children:"Applications"})," tab in the user profile. Find the app you want to grant access to, and click on the app name to open its settings."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["In the app settings, click on the ",(0,i.jsx)(n.strong,{children:"Assignments"})," tab to view the users and groups that are currently assigned to the app."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["To add the user to the app, click the ",(0,i.jsx)(n.strong,{children:"Assign"})," button in the top right corner of the page. Select the group you want to assign the user to from the list of available groups, and click the ",(0,i.jsx)(n.strong,{children:"Assign"})," button to assign the user to the app for that group."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Repeat steps 4-7 to add the user to any additional groups and apps."}),"\n"]}),"\n"]}),"\n",(0,i.jsx)(n.p,{children:"Once you've added the user to the appropriate groups and apps, they should have access to the app and any resources associated with those groups."}),"\n",(0,i.jsx)(n.h2,{id:"configure-rabbitmq-to-use-okta-as-oauth-20-authentication-backend",children:"Configure RabbitMQ to use Okta as OAuth 2.0 Authentication Backend"}),"\n",(0,i.jsx)(n.p,{children:"The configuration on the Okta side is now done. The next step is to configure RabbitMQ\nto use the resources created earlier."}),"\n",(0,i.jsxs)(n.p,{children:[(0,i.jsx)(n.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/tree/main/conf/okta/rabbitmq.conf.tmpl",children:"rabbitmq.conf"})," is an example RabbitMQ configuration that uses Okta for OAuth 2-based authentication and authorization. And ",(0,i.jsx)(n.a,{href:"https://github.com/rabbitmq/rabbitmq-oauth2-tutorial/tree/main/conf/okta/advanced.config",children:"advanced.config"})," is the RabbitMQ advanced configuration that maps RabbitMQ scopes to the permissions previously configured in Okta."]}),"\n",(0,i.jsx)(n.p,{children:"Update it with the following values from the earlier steps:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"okta-domain-name"}),": the Okta domain name"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"okta_client_app_ID"}),": the Okta app registered above to be used with RabbitMQ"]}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"start-rabbitmq",children:"Start RabbitMQ"}),"\n",(0,i.jsx)(n.p,{children:"Run the following commands to run RabbitMQ docker image:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"export MODE=okta\nmake start-rabbitmq\n"})}),"\n",(0,i.jsx)(n.h2,{id:"verify-rabbitmq-management-ui-access",children:"Verify RabbitMQ Management UI Access"}),"\n",(0,i.jsxs)(n.p,{children:["Go to RabbitMQ Management UI ",(0,i.jsx)(n.code,{children:"https://localhost:15671"}),". Depending on your browser, ignore the security warnings (raised by the fact that a ",(0,i.jsx)(n.a,{href:"./ssl#peer-verification",children:"self-signed certificate"})," is used)\nto proceed."]}),"\n",(0,i.jsxs)(n.p,{children:["Once on the RabbitMQ Management UI page, click on the ",(0,i.jsx)(n.strong,{children:"Click here to log in"})," button,\nauthenticate with your ",(0,i.jsx)(n.strong,{children:"okta user"}),"."]}),"\n",(0,i.jsx)(n.p,{children:"When login succeeds, you will be redirected back to the RabbitMQ Management UI."})]})}function d(e={}){let{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(h,{...e})}):h(e)}},28453(e,n,t){t.d(n,{R:()=>o,x:()=>a});var s=t(96540);let i={},r=s.createContext(i);function o(e){let n=s.useContext(r);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:o(e.components),s.createElement(r.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.