Documentation PI Nexus+ Documentation

PI Nexus+ / Administration Guide

OpenID Connect

This chapter connects PI Nexus+ to PI Data Archives and AF servers through AVEVA Identity Manager instead of the Windows service account, and protects the client secret.

Overview

This chapter connects PI Nexus+ to PI Data Archives and AF servers through AVEVA Identity Manager instead of the Windows service account, and protects the client secret.

Use it where a server does not accept the service account, for example across domains. All OpenID Connect targets share one client. PI Interface tracking still needs Windows authentication: on an OpenID Connect archive, PI Points are scanned but interfaces are not.

Register the client

Admin > OpenID Connect with the client ID, the client secret and the registration command
  1. Under Admin > PI Data Archives or Admin > AF Servers, choose Edit for the target and set Authentication mode to OpenID Connect. OpenID Connect now appears in the Admin navigation.
  2. Open Admin > OpenID Connect. PI Nexus+ created a Client ID and a random Client Secret; to use your own, enter them and choose Save Client Settings.
  3. Choose Copy Command and run it in an elevated PowerShell on the AVEVA Identity Manager server, with its host name filled in.
  4. Map the client to a PI identity on the PI Data Archive, or an AF identity on the AF server, with read rights.
  5. In PI Nexus+, choose Test for the target, then Enable.

Regenerate Secret replaces the secret at once; update the registration in Identity Manager straight away.

Protect the client secret with a certificate

The secret is encrypted with Windows DPAPI of the server that saved it, so only that server can read it. A secret certificate lets every server holding it read the secret. It is required on a split installation with an OpenID Connect target, and recommended on a single server whose database may be restored elsewhere.

  1. In an elevated PowerShell, create an RSA 2048-bit certificate with an exportable key. Self-signed is fine and expiry does not matter; do not put a + in the subject.
   $cert = New-SelfSignedCertificate -Subject "CN=PI Nexus Secret Protection" `
     -CertStoreLocation Cert:\LocalMachine\My -KeyAlgorithm RSA -KeyLength 2048 `
     -KeyExportPolicy Exportable -KeyUsage KeyEncipherment,DataEncipherment `
     -Provider "Microsoft Software Key Storage Provider" -NotAfter (Get-Date).AddYears(10)
   $cert.Thumbprint
  1. For a second server, export it to a password-protected .pfx and import it there into Local Computer > Personal. Keep the .pfx with your recovery documentation.
  2. On every server with the certificate, give each PI Nexus+ service account Read on its private key (certlm.msc, All Tasks > Manage Private Keys), even if the account is a local administrator.
  3. Enter the thumbprint on every server: in the installer's Secret certificate field, or as secretCertificateThumbprint in C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json.
  4. Recycle PINexusAppPool and restart the PI Nexus+ Scanner service on every server.

An existing secret is converted when PI Nexus+ next starts on the server that saved it; keep the certificate installed. Readiness shows whether each server can use it. The export and key-access commands are in Certificate commands in the Reference.

Troubleshooting

SymptomCauseFix
Test fails with an authentication errorClient not registered, or the secrets differCopy the command again and update the registration
Test passes but scans find nothingThe client has no PI or AF identity with read rightsMap it as in step 4
The secret cannot be read after a restore or on a second serverDPAPI of another server protects itSet up the certificate, or regenerate the secret and update the registration

Reference: OpenID Connect Settings