Enabling OAuth Authentication in Vertica to Connect to Toad Data Point
Along with other methods of authentication, Vertica also supports OAuth authentication. This document provides an overview of the protocols and technologies used in connecting Toad Data Point to Vertica using OAuth authentication.
Open Authorization is an open standard protocol used for Authorization and Authentication. It allows you to grant access to the application without sharing user credentials.
Keycloak is an open-source identity and access management (IAM) solution that can act as an OAuth server. It provides the necessary infrastructure and functionality to implement OAuth-based authentication and authorization workflows. Keycloak handles the generation of access tokens, verifies user identities, and enforces access policies for protected resources. It acts as an OAuth server by managing client applications, user authentication, and authorization grants.
Toad Data Point is a data analysis and querying tool. It simplifies and enhances the process of accessing, querying, and analysing data from various sources.
Toad Data Point uses Vertica ODBC driver to connect to Vertica. For more details on connecting Toad Data Point with Vertica, see Vertica Integration with Toad Data Point: Connection Guide.
Test Environment
Vertica 23.3
Vertica ODBC 23.3
Toad Data Point 6.0.5
Keycloak 19.0.2
Connecting Toad Data Point to Vertica via OAuth Authentication
You can connect Toad Data Point to Vertica via OAuth Authentication. To do this, you can first authenticate to Vertica by generating an OAuth token using Keycloak. In this example, we use jwt as the validation type. After OAuth is enabled, you must create a DSN with additional steps that are specified in the following sections. You can use this DSN to connect to Toad Data Point.
Generating OAuth for Vertica in Keycloak
Following are steps to generate OAuth token in Keycloak:
-
Login into Keycloak.
-
Create a Realm.
-
Create a user and follow these steps for the user:
-
Enter details in all the required fields.
-
Enable the user from the Enabled switch.
-
Note down the password.
-
Map user with pseudosuperuser role.
-
-
Copy RS256 key from Realm Settings > Keys > Click Public Key > Copy RS256 key.
-
Copy EndpointName: Open Realm Settings > General tab > OpenID Endpoint Configuration link.
Enabling OAuth in Vertica
The following steps enable OAuth in Vertica. Run the following queries in Vertica database:
-
DROP AUTHENTICATION IF EXISTS oauthjwt CASCADE;
-
CREATE AUTHENTICATION oauthjwt METHOD 'oauth' HOST '0.0.0.0/0';
-
ALTER AUTHENTICATION oauthjwt SET validate_type = 'JWT';
-
ALTER AUTHENTICATION oauthjwt SET jwt_issuer = 'http://<keycloak_IP>:8080/realms/<Realm_Name>';
-
ALTER AUTHENTICATION oauthjwt SET jwt_rsa_public_key = '-----BEGIN PUBLIC KEY----- <PUBLIC_KEY Copied Above> -----END PUBLIC KEY-----';
-
ALTER AUTHENTICATION oauthjwt SET jwt_user_mapping = 'preferred_username';
-
ALTER AUTHENTICATION oauthjwt SET oauth2_jit_enabled = 'yes';
-
ALTER DATABASE default set OAuth2JITClient = '<ClientName>';
-
ALTER AUTHENTICATION oauthjwt SET client_id = '<ClientName>';
-
ALTER AUTHENTICATION oauthjwt SET discovery_url = 'http://<Keycloak_Server>:8080/realms/<Realm_Name>/.well-known/openid-configuration';
-
create user <Username>; (This user is same as created in Keycloak)
-
GRANT AUTHENTICATION oauthjwt TO <username>;
Creating Vertica ODBC DSN:
-
Install the Vertica ODBC driver.
-
Open 64-bit ODBC DSN.
-
Add Vertica DSN and provide the following details:
-
DSN Name
-
Database
-
Server
-
Port
-
User Name
-
-
Save the DSN.
-
Open regedit and navigate to HKEY_LOCAL_MACHINE\SOFTWARE\ODBC\ODBC.INI\<DSN_Name>
-
Right-click in the right pane where all the details of the DSN are specified and select option New > String Value.
-
Provide the name of the object as “OAuthJsonConfig” and its value should be “{"oauthtokenurl":"http://<Keycloak_IP>:8080/realms/<Realm_Name>/protocol/openid-connect/token","oauthauthurl":"http://<Keycloak_IP>:8080/realms/<Realm_Name>/protocol/openid-connect/auth","oauthclientid":"<Client_Name>", "oauthclientsecret": "<Client_Credentials>", "oauthscope": "offline_access openid", "oauthvalidatehostname": "false"}”
-
Client Credentials are available in keycloak > Clients > Credentials tab.
-
-
Now if you open Vertica DSN and save it, the registry entry made will be removed. You will need to add the key again.
Connecting OAuth Enabled Vertica to Toad Data Point
-
Open Toad Data Point.
-
Click Connect and select New Connection.
-
Select Vertica from the Group drop-down.
-
Select the recently created DSN.
-
Click Connect.
-
Keycloak page opens. Provide UserName and Password created in Keycloak.
A success notification appears.
-
Switch back to Toad Data Point. You should now be connected to Vertica.