Integrating BMC Helix SSO with TrueSight Orchestration
Embedded BMC Helix SSO
In this option, BMC Helix SSO is installed with the TrueSight Orchestration upgrade when you install the TrueSight Orchestration repository, CDP, and HA-CDP and you do not need to install BMC Helix SSO separately.
If you install the embedded BMC Helix SSO during the TrueSight Orchestration installation, a realm named BAOLocal is automatically created during the installation of the repository, CDP, and HA-CDP if it is installed.
External BMC Helix SSO
In this option, you need to install a supported version of BMC Helix SSO on a separate server before installing TrueSight Orchestration components.
Install an external BMC Helix SSO only if you are not installing the embedded BMC Helix SSO with the TrueSight Orchestration installation. Install BMC Helix SSO before you install TrueSight Orchestration components.
To install BMC Helix SSO, use the instructions in Installing. During the external BMC Helix SSO installation, the system prompts you for a database type. To use BMC Helix SSO with TrueSight Orchestration, choose embedded database or Oracle database.
After installing BMC Helix SSO, perform the following steps:
- Create a realm. For information on creating a realm, see To create a realm for Local user authentication below.
- Create a user called aoadmin. For information on creating a user, see Configuring-Local-authentication.
- Create a role called AoAdmin. For information on creating a role, see Configuring-Local-authentication.
- Assign the aoadmin user to the AoAdmin role. For information on assigning a role to a user, see Configuring-Local-authentication.
To create a realm for Local user authentication
- Log in to the BMC Helix SSO Admin Console of BMC Helix SSO.
- Click the Realm tab.
- Click Add Realm.
- On the General tab, enter the realm details. For information about the realm parameters, see Configuring-general-settings-for-a-realm.
- Click the Authentication tab.
- In the Authentication Type field, click Local.
- (Optional) Click Enable Chaining Mode and perform the following steps to enable authentication chaining. For information about the authentications that you can chain with LDAP, see Authentication-fallback.
- Click Add Authentication.
- Select the required authentication type and enter the authentication details.
- Repeat steps a and b to add more authentications for the realm.
- Click Add.