Create a PCA, OIDC, or PKCS#7 federated credential for an M2M application in Alibaba Cloud IDaaS. Each credential uses one authentication type and carries the verification condition that a client request must meet before IDaaS issues an access token.
Credential types
| Credential type | What the credential verifies | Value to prepare |
| PCA | The content of the client certificate. | The common name (CN) of the client certificate, or the certificate fields that your expression references. |
| OIDC | The claims in the service account token that the client passes to the token endpoint. | The namespace and service account of your Kubernetes cluster, or the sub value of the service account token. |
| PKCS#7 | The fields in the PKCS#7 signature. | The instance ID of an Alibaba Cloud ECS or ECI instance, or of an Amazon EC2 instance. |
For the features and scenarios of each provider type, see Introduction to federated credential providers.
Prerequisites
-
A federated credential provider of the same type: create the provider before the credential. See Create a PCA federated credential provider, Create an OIDC federated credential provider, or Create a PKCS#7 federated credential provider.
-
An M2M application: add the credential to a new or existing M2M application in your IDaaS instance.
-
The identity material that the credential verifies: collect the value that your credential type requires, as listed in Credential types.
Procedure
-
Log on to the IDaaS console. In the left-side navigation pane, choose EIAM. Find your IDaaS instance and click Console in the Actions column.
-
Choose to create an M2M application. To use an existing application, open it from the M2M application list instead.
-
On the General tab of the application, go to the Certificate Management section. Under Authentication Type, add a PCA, OIDC, or PKCS#7 federated credential.
-
Click Add Application Federated Credential. Configure the common parameters and the parameters for your credential type as described in the following sections, and then click Confirm.
Common parameters
These parameters apply to all three credential types.
| Parameter | Description |
| Federated Credential Provider | Select an existing provider whose type matches the credential type. If none is available, create one as described in Prerequisites. |
| Application Federated Credential Type | Select PCA, OIDC, or PKCS#7. The type determines the available verification modes. |
| Application Federated Credential Name | The name of the federated credential cannot be changed once saved. Please enter it carefully. Supported characters: lowercase letters, digits, underscores (_), and hyphens (-). |
| Verification Expression | Required if you select an expression verification mode. The expression verifies the parameters that a client submits to the token endpoint of the M2M authorization server, so that only requests that meet the verification condition receive an access token. Maximum length: 10,240 characters. |
| Description | Optional. Describes the purpose of the credential. Maximum length: 128 characters. |
| Attribute Mapping | An advanced feature that customizes the sub field in the access token. After the resource server enables a custom principal ID, the system replaces the original sub field value with the attribute mapping expression, which is the unique client identity. The format changes from <clientId> to <clientId>:<client:activeSubjectUrn>, where <client:activeSubjectUrn> is the result of that expression. |
Both Verification Expression and Attribute Mapping accept federated credential expressions. For the syntax, see Use federated credential expressions.
PCA verification parameters
Configure the following parameters when Application Federated Credential Type is set to PCA.
Verification determines how IDaaS generates the verification condition. Select one of the following modes:
-
Certificate: a shortcut mode for verifying only the common name (CN) of the client certificate. Enter the CN value, and IDaaS generates the verification condition automatically.
-
Expression Verification for Client Certificate Field : an advanced mode. Customize expressions to verify multiple client certificate fields.
The mode determines which additional field to configure:
-
Client Certificate Common Name (CN): required if you select Certificate.
-
Verification Expression: required if you select Expression Verification for Client Certificate Field. The expression verifies the client certificate content.
IDaaS validates the trust condition on the PCA federated credential provider first, and the verification condition on the credential only after that condition passes.
OIDC verification parameters
Configure the following parameters when Application Federated Credential Type is set to OIDC.
Verification determines how IDaaS generates the verification condition. Select one of the following modes:
-
Kubernetes: specify the Namespace, Service Account, and Principal ID of your Kubernetes cluster. IDaaS generates the principal ID in the
system:serviceaccount:<namespace>:<serviceaccount>format. -
Principal ID: enter the
subfield from the service account token of your Kubernetes cluster. -
Expression Verification for Claims Field: an advanced mode. Customize expressions to verify multiple claims in the service account token.
If you select Expression Verification for Claims Field, Verification Expression is required. The expression verifies the claims in the service account token.
PKCS#7 verification parameters
Configure the following parameters when Application Federated Credential Type is set to PKCS#7.
Verification determines how IDaaS generates the verification condition. Select one of the following modes:
-
Cloud Server: enter the instance ID of an Alibaba Cloud ECS or ECI instance, or an Amazon EC2 instance. IDaaS generates the expression automatically.
-
Expression Verification for Signature Value Field: an advanced mode. Customize expressions to verify fields in the PKCS#7 signature.
The mode determines which additional field to configure:
-
Instance ID: required if you select the cloud server mode. Enter the instance ID of the cloud server to verify.
-
Verification Expression: required if you select Expression Verification for Signature Value Field. The expression verifies the fields in the PKCS#7 signature.
Next steps
-
To call the token endpoint with the credential, see M2M client token call examples.
-
To compare the provider types, see Introduction to federated credential providers.
-
To update or delete a federated credential provider, see Manage federated credential providers.