Integrating with the Identity Management Service
Upgrade to IBM Software Hub Version 5.1 before IBM Cloud Pak for Data Version 4.7 reaches end of support. For more information, see Upgrading IBM Software Hub in the IBM Software Hub Version 5.1 documentation.
By default, IBM Cloud Pak for Data user records are stored in an internal repository database. However, it is strongly recommended that you use an enterprise-grade password management solution, such as single sign-on (SSO) or LDAP.
If you use LDAP, you can choose between the following options:
| Mechanism | Benefits | Drawbacks |
|---|---|---|
| LDAP integration provided by Cloud Pak for Data (deprecated) | You can use LDAP with or without SAML SSO. You can choose the level of integration with
the LDAP server. You can use LDAP to:
|
You can connect to a single LDAP server from each instance of Cloud Pak for Data. This method is deprecated and will be removed in a future release. |
| LDAP integration provided by the IBM Cloud Pak foundational services Identity Management Service | The Identity Management Service supports:
|
There are no known drawbacks with this mechanism. |
To use the LDAP integration provided by Cloud Pak for Data, see Connecting to your identity provider.
- Who needs to complete this task?
-
Instance administrator An instance administrator can complete this task.
- When do you need to complete this task?
- If you want to use the LDAP integration provided by the Identity Management Service, you must integrate Cloud Pak for Data with the Identity Management Service before you onboard users or create user
groups.
When you integrate with the Identity Management Service, you delegate all authentication to the Identity Management Service. If you onboard users before you integrate with the Identity Management Service, existing users might not be able to log in to Cloud Pak for Data.
Before you begin
Ensure that you source the environment variables before you run the commands in this task.
About this task
Contact IBM® Support to reset Cloud Pak for Data to the previous state.
Procedure
What to do next
- Determine whether you need to update name of the default administrative user that is created by the Identity Management Service.
- Connect to your LDAP servers. For more information, see Configuring an LDAP connection in the IBM Cloud Pak foundational services documentation.