IBM Security Verify
BlokSec can be configured as an inbound federation identity provider (also known as a social provider) for your IBM Security Verify tenant, and can also be configured to enable user mapping within the IBM admin console.
The BlokSec ↔ IBM Security Verify integration enables authentication via the SAML protocol. Configuration involves steps on both the BlokSec admin console and the IBM Security Verify console.
Prerequisites
Section titled “Prerequisites”- A BlokSec admin account with permission to create applications
- An IBM Security Verify tenant with admin access
1. Create the IBM Security Verify application in BlokSec
Section titled “1. Create the IBM Security Verify application in BlokSec”- Sign in to the BlokSec admin console as a user with admin privileges
- From the dashboard, click + Add Application and select Create From Template
- Select the IBM Security Verify template
- Complete the application details and click Submit:
| Field | Value |
|---|---|
| Name | IBM Verify (or your preferred name) |
| SSO Type | OpenID Connect |
| Redirect URIs | Leave blank for now |
| Post Logout Redirect URIs | Leave blank for now |
- Click back into the newly created application to open its configuration
- Click Generate App Secret, then note the Application ID and Application Secret — these are required when registering the application with IBM Verify
2. Configure BlokSec as an identity source in IBM Security Verify
Section titled “2. Configure BlokSec as an identity source in IBM Security Verify”- Sign in to the IBM Security Verify admin console as a user with admin privileges
- Navigate to Configuration → Identity Sources
- Click Add Identity Source and select SAML Enterprise from the dropdown
- Complete the identity provider configuration with the following values:
General Settings
| Field | Value |
|---|---|
| Name | BlokSec yuID Passwordless (or your preferred name) |
| Realm | bloksec |
From Identity Provider
| Field | Value |
|---|---|
| SAML Single Sign-On flow initiated by | Service Provider |
| XML Metadata | Upload the metadata XML exported from the BlokSec admin console |
To Identity Provider
- Click the Download link to save the IBM Security Verify metadata file
- From that metadata file, copy:
- The Entity ID URI
- The Assertion Consumer Service URI
- Click Save
3. Complete the BlokSec application configuration
Section titled “3. Complete the BlokSec application configuration”- Return to the IBM Security Verify application in the BlokSec admin console, click the gear icon in the upper right, and select Edit Application
- Enter the Entity ID copied from the IBM Security Verify metadata in the previous step
- Enter the Assertion Consumer Service URL copied from the IBM Security Verify metadata
- Check Request Signed
- Paste the X.509 Certificate value from the IBM Security Verify metadata XML into the certificate field
- Click Submit to save the changes
Verifying the integration
Section titled “Verifying the integration”- Open a private/incognito browser window
- Navigate to your IBM Security Verify tenant login page
- Select BlokSec (or your configured identity source name) as the sign-in method
- Approve the sign-in on the BlokSec mobile app
- Confirm you are successfully authenticated into IBM Security Verify