Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
This article describes how to connect Nexus Smart ID Identity Manager (PRIME) to the Nexus Smart ID Digital Access component (Hybrid Access Gateway) Extension Programming Interface (XPI), to enable provisioning of users and Smart ID Mobile App (Personal Mobile) profiles.
Prerequisites
Expand | ||
---|---|---|
| ||
|
Step-by-step instruction
Expand | ||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||||||||||||||
To be able to use the XPI interface of HAG an SSL server certificates needs to be provided. For demo use cases it’s sufficient to create a self-signed certificate including private keys. Skip these steps if a real server certificate exists.
|
Expand | |||||
---|---|---|---|---|---|
| |||||
To install the server certificate in Hybrid Access Gateway:
|
Expand | |||||||||
---|---|---|---|---|---|---|---|---|---|
| |||||||||
The server certificate needs to be added to the trust store, to make the PRIME server trust the certificate during the XPI call.
|
Expand | ||
---|---|---|
| ||
An Authentication Method of type Password must be set up, so that PRIME can authenticate against Hybrid Access Gateway XPI.
|
Expand | ||
---|---|---|
| ||
To authenticate to the XPI with username and password, a delegated administrator must be defined. The user must be in the already connected user storage. See Add user storage for more information. To assign the delegated administrator role to a user:
|
Expand | ||
---|---|---|
| ||
For PRIME to get access to Hybrid Access Gateway over the XPI, the XPI must be enabled. To enable the Hybrid Access Gateway XPI:
|
Expand | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||
To activate the HAG Settings option in PRIME Explorer under the Admin tab:
|
Expand | ||
---|---|---|
| ||
To enter the Hybrid Access Gateway XPI credentials in PRIME:
|
Expand | ||
---|---|---|
| ||
To define which data should be provision from PRIME to HAG, the settings in the HAG provisioning task must be adapted. For more information, see The task is used in the PRIME processes that provision the data to HAG. There are processes available in the Base configuration package (BIM), called BaseProcActivateAndProvisionUserToHag and BaseProcDeactivateAndProvisionUserToHag. To adapt the settings in the HAG provisioning task, do the following for each process:
|
This article is valid from Nexus PRIME 3.6.