About This Guide

This guide describes how to integrate Utimaco Enterprise Secure Key Manager (ESKM) with an OpenID Connect (OIDC) identity provider using Microsoft Entra ID. The integration enables users to authenticate to ESKM through the OIDC protocol, providing centralized authentication and Single Sign-On (SSO) capabilities.

Target Audience

This guide is intended for Microsoft Entra ID administrators and Utimaco ESKM administrators responsible for configuring, deploying, and managing OpenID Connect (OIDC)-based authentication integration between the two systems.

Purpose of the Integration

The integration of Utimaco Enterprise Secure Key Manager (ESKM) with an OIDC identity provider enables centralized user authentication for ESKM. By leveraging OIDC authentication, organizations can provide users with a secure and streamlined sign-in experience while reducing the need for local credential management within ESKM.

In this integration, Microsoft Entra ID acts as the OIDC Identity Provider (IdP), authenticating users and providing identity information to ESKM.

Benefits of the integration include:

  • Centralized authentication using organizational credentials.

  • Single Sign-On (SSO) access to the ESKM Management UI.

  • Simplified user identity management through a centralized identity provider.

  • Reduced administrative overhead associated with local account management.

  • Enhanced security through centralized authentication policies and Multi-Factor Authentication (MFA), where configured.

  • Improved user experience by allowing users to authenticate using their existing organizational accounts.

Scope of the Integration

This guide covers the configuration required to integrate Utimaco Enterprise Secure Key Manager (ESKM) with Microsoft Entra ID using OIDC authentication. The guide describes the creation and configuration of an application registration in Microsoft Entra ID, the configuration of OIDC settings in ESKM, and the validation of user authentication through the identity provider.

Abbreviations

Abbreviation

Meaning

ESKM

Enterprise Secure Key Manager

OIDC

OpenID Connect

IdP

Identity Provider

SSO

Single Sign-On

MFA

Multi-Factor Authentication

GUI

Graphical User Interface

UI

User Interface

URL

Uniform Resource Locator

KMIP

Key Management Interoperability Protocol

NTP

Network Time Protocol

DNS

Domain Name System

ID

Identifier

Abbreviations

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Under Client secrets, click New client secret.

Monospaced

Code that is given for explanation or as an example, file paths

chsm-create

Italic

References and important terms

ESKM listed in Tested Versions.

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message indicates the expected result after the successful execution of an instruction.