API Gateway, Policy Manager, and Developer Portal: Authentication and Authorization Configuration
search cancel

API Gateway, Policy Manager, and Developer Portal: Authentication and Authorization Configuration

book

Article ID: 208588

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

This article provides guidance on integrating external identity providers (IdP) such as LDAP or Okta with the Layer7 API Management suite. Customers frequently request these integrations to replace default internal accounts or to enable centralized management for appliance-level (SSH) and application-level (Policy Manager/Portal) access.

Environment

Release : 11.x

Component : API GATEWAY

Resolution

The Layer7 suite supports external authentication across all primary components. Follow the relevant section below for your specific integration needs:

1. API Gateway Appliance (SSH/Shell Access) - Configure Authentication Method

The local system accounts (ssgadminssgconfig) can be supplemented with LDAP-authenticated users for SSH access.

  • Access the Gateway Configuration Menu (SSH as ssgconfig).
  • Select Option 4: Configure authentication method.
  • Configure the SSH to Gateway with LDAP users support option.
  • Note: Do not disable the local ssgconfig or root accounts entirely, as they are required for console access if the network or IdP is unavailable.

2. Policy Manager Administration - LDAP Identity Providers

Policy Manager uses the Internal Identity Provider by default, but can be configured for LDAP/Okta:

  • Log in to Policy Manager as an administrator.
  • Navigate to Tasks > Identity Providers > Create LDAP Identity Provider.
  • Complete the wizard to point to your LDAP or Okta (via LDAP interface) server.
  • Mandatory: Select the "Allow assignment to administrative roles" checkbox in the wizard to allow mapping external users to administrative roles.

3. API Developer Portal - Configure Authentication Schemes

The Portal supports various authentication schemes, including LDAP and OAuth2/OpenID Connect (Okta).

  • Log in to the Portal as an administrator.
  • Navigate to Set up and Maintenance > Configure Authentication Schemes.
  • Add a new LDAP Authentication Scheme or OpenID Connect scheme for Okta.