Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This is Step 3 of the DSPM DRA Setup

Initial setup

  1. Login to https://DSPM_URL/auth/admin

  2. Use default login and password admin/admin

  3. Change the default login and password for admin

    1. Select the Realm master in the top left corner

    2. Select Users in the left menu

    3. Select admin user from the users table

      SCR-20240604-pdxw.png
  4. Select Credentials from the top menu

    1. Select Reset password and follow the instructions in the modal window

      SCR-20240604-pesf.png
  5. Change realm to gv:

    1. In the top left corner select gv from a dropdown

      image-20240604-162326.png
  6. Navigate to Clients in the left menu and select Dashboard from the table

    SCR-20240604-pamf.png
  7. Select Root URL and Valid redirect URIs

    1. for Root URL set the URL to refer to your DSPM URL ending with /ui

    2. for Valid redirect URIs set the URL to refer to your DSPM URL ending with /ui/*

      SCR-20240604-paro.png
  8. Select Web origins and Admin URL

    1. for Web origins set the URL to refer to your DSPM URL ending with /ui

    2. for Admin URL set the URL to refer to your DSPM URL ending with /ui

      SCR-20240604-pavo.png
  9. Select Front-channel logout URL

    1. for Front-channel logout URL set the URL to refer to your DSPM URL ending with /auth/realms/gv/protocol/openid-connect/logout

      SCR-20240604-pays.png
  10. Press Save at the bottom of the page

Configuring roles and groups

  1. Importing permissions setup to Keycloak (which is the Identity and Access Management Engine used by our apps)

    1. Select the realm gvRealm SettingPartial Importin the tool:

      SCR-20240604-ogak-20240604-150915.png
    2. In the popup click browse and provide these files: https://drive.google.com/file/d/1jkPOb6hSK50WeGONotP9cfAG-xtkM6je/view?usp=sharingand https://drive.google.com/file/d/1hN2BL4qJX-8YmzU2gZqPWrpxl3Zy37uK/view?usp=sharing, then make sure all the options in the popup are selected as in the picture and set to SKIP for existing items and click Import button.

      SCR-20240605-kqqf-20240605-104621.png

      You should then see a positive confirmation window!

Create a new user and assign roles

  1. Make sure you operate in the gv realm (front left corner)

  2. Navigate to Users and select Add user

    SCR-20240604-pbgm.png
  3. Give a name to your user by setting username

    SCR-20240604-pbkp.png
  4. Select Join Groups

    1. Select two groups

    2. Select Join

      SCR-20240604-pbpz.png
    3. Select Create

  5. Navigate to Credentials and press Set password

    SCR-20240604-pbte.png
    1. Set and save a password in the modal window

      SCR-20240604-pbxk.png
  6. Navigate to Role mapping

    1. Select Assign role

      SCR-20240604-pcbx.png
    2. Select ADMIN and USER from the list and press Assign

      SCR-20240604-pcen.png
    3. Select Assign role again

      1. From a modal window dropdown select Filter by clients

        SCR-20240604-pchc.png
      2. Add the following roles with a check-box:

        1. realm-admin

        2. view-users

        3. DATA_REGISTER_READ

        4. DATA_RISK_WRITE

        5. ANALYTICS_WRITE

        6. PATTERN_MATCHING_WRITE

        7. DATA_REGISTER_WRITE

        8. REPORTS_WRITE

        9. USER_MANAGEMENT_WRITE

        10. ADMIN

        11. DEPARTMENTS_PARTIAL_WRITE

        12. USER

        13. CONNECTIONS_WRITE

        14. DEPARTMENTS_FULL_READ

        15. DEPARTMENTS_FULL_WRITE

        16. EXPLORE_PAGE_WRITE

        17. COMPLIANCE_HUB_WRITE

        18. AGENT_CONFIGURATION_WRITE

        19. TAGGING_WRITE

        20. COMPLIANCE_HUB_READ

        21. LANGUAGE_SETTINGS_WRITE

        22. DEPARTMENTS_PARTIAL_READ

          SCR-20240604-pckq.png
      3. Press Assign

...

Now, go to the Step 4, which is available via this link – Enabling DRA in Rancher-based deployment