PI Nexus+ / Reference
OpenID Connect Settings
This reference lists the OpenID Connect client settings, the registration values for AVEVA Identity Manager, and the commands for the secret certificate.
Overview
This reference lists the OpenID Connect client settings, the registration values for AVEVA Identity Manager, and the commands for the secret certificate.
Client settings
| Setting | Default | Notes |
|---|---|---|
| Client ID | PINexus_App_<web server name> | Up to 512 characters. Shared by every OpenID Connect target |
| Client Secret | 48 random bytes, Base64 | Up to 1,024 characters. Shown in clear text on the page; treat the page as sensitive |
| Regenerate Secret | Replaces the secret at once; the old registration stops working | |
| Page visibility | OpenID Connect is listed in the Admin navigation once a PI Data Archive or AF server uses it; /admin/openid-connect always opens it |
If the page says the client settings are not available yet, the database schema is not current: apply it under Admin > SQL Server.
Identity Manager registration
| Parameter | Value |
|---|---|
-HostBase | https://<identity_manager_fqdn>:<port>: 443, or the port the identity server publishes. The command PI Nexus+ shows uses 444, which AVEVA Identity Manager commonly uses; change it if yours differs |
-Id | The Client ID |
-AllowedGrantTypes | ClientCredentials |
-ScopeRestrictions | openid, system, profile |
-Secret | The Client Secret |
Map the client to a PI identity (PI Data Archive) or AF identity (AF server) with the read rights in Service Account Rights.
What OpenID Connect supports
| Feature | Windows | OpenID Connect |
|---|---|---|
| PI Point inventory and health | Yes | Yes |
| AF inventory and health | Yes | Yes |
| PI Interface tracking and runtime monitoring | Yes | No; disable Interface Tracking before switching |
| Test Module DB | Yes | Not offered |
Secret protection
| Situation | Protection | Readable by |
|---|---|---|
| No certificate configured | Windows DPAPI | Only the server that saved the secret |
| Certificate configured | The certificate's key | Every server with the certificate and its private key |
| Certificate configured later | Converted once, when PI Nexus+ starts on the server that saved the secret | |
| Thumbprint removed later | Not converted back | Keep the certificate installed |
| Deployment | Certificate |
|---|---|
| Split installation with an OpenID Connect target | Required, on both servers |
| Single server | Optional; recommended if the database may be restored to another server |
Certificate requirements: RSA 2048-bit, exportable private key, Microsoft Software Key Storage Provider, in Local Computer > Personal. Self-signed is fine and expiry does not matter. No + in the subject, or New-SelfSignedCertificate fails with CRYPT_E_INVALID_X500_STRING.
Certificate commands
Export on the server that has the certificate, import on the other:
Export-PfxCertificate -Cert Cert:\LocalMachine\My\<thumbprint> -FilePath C:\Temp\PINexus-Secrets.pfx -Password (Read-Host -AsSecureString "PFX password")
Import-PfxCertificate -FilePath C:\Temp\PINexus-Secrets.pfx -CertStoreLocation Cert:\LocalMachine\My -Exportable -Password (Read-Host -AsSecureString "PFX password")
Grant the service accounts read access to the private key, instead of certlm.msc:
$cert = Get-Item Cert:\LocalMachine\My\<thumbprint>
$key = [System.Security.Cryptography.X509Certificates.RSACertificateExtensions]::GetRSAPrivateKey($cert)
$keyFile = Join-Path $env:ProgramData ("Microsoft\Crypto\Keys\" + $key.Key.UniqueName)
icacls $keyFile /grant "DOMAIN\svc-pinexus-web:R"
icacls $keyFile /grant "DOMAIN\svc-pinexus-scan:R"
On a split installation with two accounts, grant both accounts on both servers. Delete the copied .pfx after the import.
| Where to enter the thumbprint | Value |
|---|---|
| Installer | Secret certificate field |
| Silent installation | SECRETCERTIFICATETHUMBPRINT="<thumbprint>" |
| Existing installation | "secretCertificateThumbprint": "<thumbprint>" in C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json |
Then recycle PINexusAppPool and restart PI Nexus+ Scanner on every server. Admin > Support > Readiness reports per server whether the certificate is configured, found and usable.
