Okta

Configure OIDC for Progress Chef

This guide provides instructions on configuring OpenID Connect (OIDC) SSO for the Progress Chef integration.

Contents


Supported features

Progress Chef supports the following feature:

Prerequisites

Configure the app in Okta

  1. In the Admin Console, go to Applications and Resources > Applications (or Applications > Applications in Okta Classic Engine).
  2. Click Browse App Catalog.
  3. Search for and select the Progress Chef app.
  4. Click Add Integration.
  5. On the General Settings tab, enter an Application label, or use the default label.
  6. In the Redirect URL field, enter a placeholder value, for example https://platform.example.com/endpoint. Later, you can update this with the redirect URL that Progress Chef generates.
  7. Click Done.
  8. On the Authentication tab (or the Sign On tab in Okta Classic Engine), locate your Client ID and Client secret.
  9. Click the OpenID provider metadata link, and copy the Issuer, Authorization URL, Token URL, Logout URL, and User Info URL values. You need them to complete the manual configuration in Progress Chef.
  10. Go to the Assignments tab and click Assign > Assign to People.
  11. Select the users who need access.
  12. Click Save, and then click Go Back.

    The integration doesn't work for users until you assign them to the app in Okta.

Configure OIDC in Progress Chef

  1. On the SSO Configuration page, select + Provider, and then select OpenID Connect v1.0.
  2. On the Configuring OpenID Connect Provider screen, complete the following fields:
    • Unique name: Enter a name for the IdP. Only letters, numbers, dashes, and underscores are allowed.
    • Display name: Enter a display name, for example ACME Systems.
    • Display order: If you're using more than one IdP, set the sign-in display order.
  3. Leave the Import configuration from URL field blank, and select Show configuration details.
  4. Enter the following values from the Okta OpenID provider metadata you copied earlier:
    • Issuer, for example https://idp.example.com
    • Authorization URL, for example https://idp.example.com/oauth2/auth
    • Token URL, for example https://idp.example.com/oauth2/token
    • Logout URL (optional), for example https://idp.example.com/oauth2/v1/logout
    • User Info URL, for example https://idp.example.com/oauth2/userinfo
  5. Enter the Client ID and Client secret that you copied from Okta.
  6. Click Save.
  7. Click the vertical ellipsis next to the IdP to view its configuration details, and then copy the Redirect URL.
  8. Return to the Progress Chef app's General Settings tab in the Admin Console, and update the Redirect URL field with the value you copied.

Verify SP-initiated SSO

  1. Go to your Progress Chef tenant URL.
  2. Select your org from the Sign in with SSO list. You're directed to your Okta tenant.
  3. Enter your Okta credentials.
  4. Select your org and role, and then sign in. You're directed back to Progress Chef.