PI Nexus+ / Administration Guide
OpenID Connect
This chapter connects PI Nexus+ to PI Data Archives and AF servers through AVEVA Identity Manager instead of the Windows service account, and protects the client secret.
Overview
This chapter connects PI Nexus+ to PI Data Archives and AF servers through AVEVA Identity Manager instead of the Windows service account, and protects the client secret.
Use it where a server does not accept the service account, for example across domains. All OpenID Connect targets share one client. PI Interface tracking still needs Windows authentication: on an OpenID Connect archive, PI Points are scanned but interfaces are not.
Register the client

- Under Admin > PI Data Archives or Admin > AF Servers, choose Edit for the target and set Authentication mode to OpenID Connect. OpenID Connect now appears in the Admin navigation.
- Open Admin > OpenID Connect. PI Nexus+ created a Client ID and a random Client Secret; to use your own, enter them and choose Save Client Settings.
- Choose Copy Command and run it in an elevated PowerShell on the AVEVA Identity Manager server, with its host name filled in.
- Map the client to a PI identity on the PI Data Archive, or an AF identity on the AF server, with read rights.
- In PI Nexus+, choose Test for the target, then Enable.
Regenerate Secret replaces the secret at once; update the registration in Identity Manager straight away.
Protect the client secret with a certificate
The secret is encrypted with Windows DPAPI of the server that saved it, so only that server can read it. A secret certificate lets every server holding it read the secret. It is required on a split installation with an OpenID Connect target, and recommended on a single server whose database may be restored elsewhere.
- In an elevated PowerShell, create an RSA 2048-bit certificate with an exportable key. Self-signed is fine and expiry does not matter; do not put a
+in the subject.
$cert = New-SelfSignedCertificate -Subject "CN=PI Nexus Secret Protection" `
-CertStoreLocation Cert:\LocalMachine\My -KeyAlgorithm RSA -KeyLength 2048 `
-KeyExportPolicy Exportable -KeyUsage KeyEncipherment,DataEncipherment `
-Provider "Microsoft Software Key Storage Provider" -NotAfter (Get-Date).AddYears(10)
$cert.Thumbprint
- For a second server, export it to a password-protected
.pfxand import it there into Local Computer > Personal. Keep the.pfxwith your recovery documentation. - On every server with the certificate, give each PI Nexus+ service account Read on its private key (
certlm.msc, All Tasks > Manage Private Keys), even if the account is a local administrator. - Enter the thumbprint on every server: in the installer's Secret certificate field, or as
secretCertificateThumbprintinC:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json. - Recycle
PINexusAppPooland restart thePI Nexus+ Scannerservice on every server.
An existing secret is converted when PI Nexus+ next starts on the server that saved it; keep the certificate installed. Readiness shows whether each server can use it. The export and key-access commands are in Certificate commands in the Reference.
Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| Test fails with an authentication error | Client not registered, or the secrets differ | Copy the command again and update the registration |
| Test passes but scans find nothing | The client has no PI or AF identity with read rights | Map it as in step 4 |
| The secret cannot be read after a restore or on a second server | DPAPI of another server protects it | Set up the certificate, or regenerate the secret and update the registration |
Reference: OpenID Connect Settings
