Documentation PI Nexus+ Documentation

PI Nexus+ / Reference

OpenID Connect Settings

This reference lists the OpenID Connect client settings, the registration values for AVEVA Identity Manager, and the commands for the secret certificate.

Overview

This reference lists the OpenID Connect client settings, the registration values for AVEVA Identity Manager, and the commands for the secret certificate.

Client settings

SettingDefaultNotes
Client IDPINexus_App_<web server name>Up to 512 characters. Shared by every OpenID Connect target
Client Secret48 random bytes, Base64Up to 1,024 characters. Shown in clear text on the page; treat the page as sensitive
Regenerate SecretReplaces the secret at once; the old registration stops working
Page visibilityOpenID Connect is listed in the Admin navigation once a PI Data Archive or AF server uses it; /admin/openid-connect always opens it

If the page says the client settings are not available yet, the database schema is not current: apply it under Admin > SQL Server.

Identity Manager registration

ParameterValue
-HostBasehttps://<identity_manager_fqdn>:<port>: 443, or the port the identity server publishes. The command PI Nexus+ shows uses 444, which AVEVA Identity Manager commonly uses; change it if yours differs
-IdThe Client ID
-AllowedGrantTypesClientCredentials
-ScopeRestrictionsopenid, system, profile
-SecretThe Client Secret

Map the client to a PI identity (PI Data Archive) or AF identity (AF server) with the read rights in Service Account Rights.

What OpenID Connect supports

FeatureWindowsOpenID Connect
PI Point inventory and healthYesYes
AF inventory and healthYesYes
PI Interface tracking and runtime monitoringYesNo; disable Interface Tracking before switching
Test Module DBYesNot offered

Secret protection

SituationProtectionReadable by
No certificate configuredWindows DPAPIOnly the server that saved the secret
Certificate configuredThe certificate's keyEvery server with the certificate and its private key
Certificate configured laterConverted once, when PI Nexus+ starts on the server that saved the secret
Thumbprint removed laterNot converted backKeep the certificate installed
DeploymentCertificate
Split installation with an OpenID Connect targetRequired, on both servers
Single serverOptional; recommended if the database may be restored to another server

Certificate requirements: RSA 2048-bit, exportable private key, Microsoft Software Key Storage Provider, in Local Computer > Personal. Self-signed is fine and expiry does not matter. No + in the subject, or New-SelfSignedCertificate fails with CRYPT_E_INVALID_X500_STRING.

Certificate commands

Export on the server that has the certificate, import on the other:

Export-PfxCertificate -Cert Cert:\LocalMachine\My\<thumbprint> -FilePath C:\Temp\PINexus-Secrets.pfx -Password (Read-Host -AsSecureString "PFX password")
Import-PfxCertificate -FilePath C:\Temp\PINexus-Secrets.pfx -CertStoreLocation Cert:\LocalMachine\My -Exportable -Password (Read-Host -AsSecureString "PFX password")

Grant the service accounts read access to the private key, instead of certlm.msc:

$cert = Get-Item Cert:\LocalMachine\My\<thumbprint>
$key = [System.Security.Cryptography.X509Certificates.RSACertificateExtensions]::GetRSAPrivateKey($cert)
$keyFile = Join-Path $env:ProgramData ("Microsoft\Crypto\Keys\" + $key.Key.UniqueName)
icacls $keyFile /grant "DOMAIN\svc-pinexus-web:R"
icacls $keyFile /grant "DOMAIN\svc-pinexus-scan:R"

On a split installation with two accounts, grant both accounts on both servers. Delete the copied .pfx after the import.

Where to enter the thumbprintValue
InstallerSecret certificate field
Silent installationSECRETCERTIFICATETHUMBPRINT="<thumbprint>"
Existing installation"secretCertificateThumbprint": "<thumbprint>" in C:\ProgramData\Software Athlete\PI Nexus+\bootstrap.json

Then recycle PINexusAppPool and restart PI Nexus+ Scanner on every server. Admin > Support > Readiness reports per server whether the certificate is configured, found and usable.