Supported Database

  • PostgresSQL, Oracle, and Db2 are the only database supported.

Supported version of IBM Verify Identity Access

  • IBM Verify Identity Access version 10.0.4.0_IF1 or later.

Supported mapping rule utilities

  • IBM Verify Identity Access OIDC Provider supports a subset of the existing IBM Verify Identity Access. Read more about the mapping rule utilities in the reference section.

Supported Point of contact

  • For IVIAOP, IBM Verify Identity Access version 10.0.4.0_IF1 or later Web Reverse Proxy is the only supported point of contact.
  • For IVIAOP, IVIA Web Reverse Proxy UI wizard is only available 10.0.6.0 or later.

Limitation on LDAP Server connection

  • In the storage.yml, we support one LDAP host for every server connection, unlike in IBM Verify Identity Access.

Limitation on AES-192-GCM

  • IBM Verify Identity Access OIDC Provider does not support AES-192-GCM as an encryption algorithm.

Limitation on LDAP bind, when password reset flag is set to true

  • IBM Verify Identity Access OIDC Provider support the communicating with the LDAP via the mapping rule, due to a library limitation, when the authenticate method in the mapping rule is invoked, the bind succeeds, despite the pwdMustChange password policy being set to true.

Support for B64 annotation for configuration

  • IBM Verify Identity Access OIDC Provider supports b64 and B64 annotation for base64 encoded content. We prefer that you use B64.

Exporting Oracle runtime database configuration from IVIA

  • When exporting oracle runtime database configuration with SSL, further modification is required to setup wallet configuration.