Setting Up Authentication for OpenID Connect with Yahoo
3 min
adding a new application on https //developer yahoo com https //developer yahoo com/ , create a new application with the following settings type web application redirect url https // /handlers/sso/oidc/authresulthandler ashx api permissions openid connect permissions, email, and profile information required for configuration in client id client secret creating a neurons for itsm authentication provider to set up users for authentication via the , refer to setting up itsm users for authentication via the neurons platform docid\ wnkkhhscs2a4b5njr5ng4 and authentication https //help ivanti com/ht/help/en us/cloud/vnow/authentication htm this feature is early access only and may not be available in your environment for more information, please contact your customer success manager open the configuration console click configure > security controls > authentication providers to open the authentication providers workspace from the new record menu list, select new openid connect delete the default data from the existing fields enter information into the fields field description default specifies if this authentication provider is called automatically set by the application to set the authentication provider as default, you must first set default to false for all other authentication providers and then change the default settings for this authentication provider to true disabled specifies if this authentication provider is disabled name the name of the openid connect provider authentication url enter https //api login yahoo com/oauth2/request auth for more details about authentication, refer to https //developer yahoo com/oauth2/guide/openid connect/getting started html https //developer yahoo com/oauth2/guide/openid connect/getting started html token verification url enter https //api login yahoo com/oauth2/get token for more details about token verification, refer to https //developer yahoo com/oauth2/guide/openid connect/getting started html https //developer yahoo com/oauth2/guide/openid connect/getting started html logout url enter the url that sign out from yahoo account when the you log out from , after logging out from , the end session of openid connect endpoint is called and clients in the same browser session are also signed out session renewal url url used to request to renew the session if this field is empty, the application uses the value of the authentication url field must be able to initiate an outbound https (port 443) connection to this url client id enter the yahoo client id this is the client id captured from new application client secret enter the client secret value from your yahoo application this is the client secret captured from new application oidc hosted domain not used for yahoo oidc realm enter the tenant url you can enter the following url https // certificate url not used for yahoo certificate issuer not used for yahoo expiration date not used for yahoo force login the force login option is applicable to users reaching concurrent session limits, in the case of external authentication if the option is selected, when you reach a concurrent session limit, the application terminates all existing sessions and devices, and automatically logs them into a new session if the option is not selected, when you reach a concurrent session limit, an error message will appear on the page then you need to log out of existing sessions or devices, and then try logging in again auto provisioning adds new users via authentication you have the option to auto provision the role, status, and team for the new user by selecting auto provisioning , the application creates an employee record if a user logs in using authentication and does not already have an employee record profile information url not used for yahoo auto provision role role associated with the new user auto provision status status of the new user auto provision team team associated with the new user auto provision user business object type of user record to create you can select the following types employee external contact click save to verify your configuration, click test authentication you must have an employee record with an appropriate external authentication linking to this provider before the test runs successful a successful test looks similar to the below screenshot
