FAQs
Frequently asked questions about BMC Helix Single Sign-On
Frequently asked questions about the idle timeout
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*
Here are some answers to the most frequently asked questions about the BMC Helix Single Sign-On product.
Related topics
Identity providers do not automatically notify BMC Helix SSO about the password change. Hence, an end user's BMC Helix SSO session remains active until it expires, and is not revoked after password change on IdP. To force the logoff, and receive the request for entering a new password, an end user needs to ask a BMC Helix SSO administrator to delete all active sessions/OAuth of this end user.
You can change your password in the BMC Helix SSO Admin Console, in the Admin User Management. To change your password, select your user account name, and then edit your password as required. See Setting-up-BMC-Helix-SSO-administrator-accounts for more details about how to change the password of an administrator.
You can obtain the BMC Helix SSO server version information through the <RSSO Server>/config/server-status URL. You must be authenticated as a BMC Helix SSO administrator before that.
Yes, you can do this.
If the OpenID Issuer URL is configured for the OAuth 2.0, developers of third-party applications can retrieve the OAuth metadata from the BMC Helix SSO server by using the following autodiscovery URL: RSSO_host:RSSO_port/rsso/.well-known/openid-configuration.
Running this request in the browser window returns details about the OpenID Connect provider's configuration, including the URIs of the authorization, token, revocation, userinfo, and public-keys endpoints.
Multi-factor authentication is not implemented on the BMC Helix SSO side. BMC Helix SSO only supports scenarios where the Identity Provider that is configured in BMC Helix SSO for authentication has configured multi-factor authentication.
For example, if your application is integrated with the BMC Helix SSO server that is configured to use the SAML protocol to authenticate users accessing an application, then for the end users to pass the authentication flow, multi-factor authentication must be enabled and configured on the SAML Identity Provider.
Yes.
You can enable audit records for end-user events in the BMC Helix SSO Admin Console > General > Advanced > select the End-user events check box.
If the idle timeout value is reached, logout happens anyways.
If the UI idle timeout BMC Helix SSO script does not work for at least one of the applications, the idle timeout does not work for all of the applications.
In version 22.4, the UI idle timeout feature can be enabled only for BMC applications that communicate with BMC Helix SSO through Auth Proxy (external server). Starting from version 22.4.01, UI idle timeout is also supported for the BMC Helix SSO agent (embedded into the application).
A warning message is shown for an application with the least UI idle timeout value first.
Idle timeout is not applied.
A user is not logged out from all the applications, but only from the applications that reached the idle timeout value.