Integrating with the Identity Management Service
By default, IBM Cloud Pak for Data user records are stored in an internal repository database. However, it is strongly recommended that you use an enterprise-grade password management solution, such as single sign-on (SSO) or LDAP.
If you use LDAP, you can choose between the following options:
| Mechanism | Details |
|---|---|
| LDAP integration provided by Cloud Pak for Data (deprecated) | When you install Cloud Pak for Data, the
Identity Management Service is automatically enabled. If
you want to use the LDAP integration provided by Cloud Pak for Data, see Configuring Cloud Pak for Data to use the embedded LDAP integration. After you configure Cloud Pak for Data to use the embedded LDAP integration, see Connecting to your identity provider.
|
| LDAP integration provided by the IBM Cloud Pak foundational services Identity Management Service | When you install Cloud Pak for Data, the
Identity Management Service is automatically enabled.
However, if you upgrade from an older release of Cloud Pak for Data and the Identity Management Service is not enabled, you can use the
|
- Who needs to complete this task?
-
Instance administrator An instance administrator can complete this task.
- When do you need to complete this task?
-
Complete this task if you upgraded Cloud Pak for Data to Version 5.0 and you want to use the LDAP integration provided by the Identity Management Service.
If you installed Cloud Pak for Data Version 5.0, you don't need to complete this task. Cloud Pak for Data is already integrated with the Identity Management Service.
Before you begin
Ensure that you source the environment variables before you run the commands in this task.
About this task
You can use the setup-iam-integration command to integrate
Cloud Pak for Data with the Identity Management Service. When you integrate with the Identity Management Service, you delegate all authentication to the
Identity Management Service.
If you onboard users before you integrate with the Identity Management Service, existing users might not be able to log in to Cloud Pak for Data.
Procedure
What to do next
- Determine whether you need to update name of the default administrative user that is created by the Identity Management Service.
- Connect to your LDAP servers. For more information, see Configuring an LDAP connection in the IBM Cloud Pak foundational services documentation.