Red Hat signs users in through Red Hat SSO, the OpenID Connect realm at sso.redhat.com.
Copy the redirect URI
In the Authdog console, select the project and environment, open Authentication > Providers, find Red Hat, and click Enable. Copy the redirect URI shown in the form:
https://identity.authdog.com/api/v1/callback/<connectionId>Create the application
- Register an OAuth client for the Red Hat SSO realm
redhat-external. - Set the redirect URI to the value copied from Authdog.
- Request the scopes
openid,email, andprofile. - Copy the client ID and client secret.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | The Red Hat client ID |
| Client Secret | The Red Hat client secret |
Save, then toggle the connection active.
What Red Hat returns
Authdog uses the authorization-code flow against https://sso.redhat.com/auth/realms/redhat-external/protocol/openid-connect/auth and reads the profile from the realm userinfo endpoint.
The userinfo response includes the subject and, when the email scope is granted, an email address.
Test it
- Open your environment's hosted sign-in page, or link to
https://identity.authdog.com/api/v1/signin/<connectionId>. - Select the Red Hat button and complete the flow.
- Confirm the user appears under Users in the console with a Red Hat identity linked.
Troubleshooting
| Symptom | Cause |
|---|---|
redirect_uri_mismatch |
The callback registered on the client differs from Authdog's redirect URI |
| No email on the user | The client was not granted the email scope |
| Works in one environment only | Each environment has its own connectionId, and so its own redirect URI |
Related
| Read | To learn how to |
|---|---|
| Connectors | Set up any other social provider |
| Enterprise SSO | Connect a SAML or OpenID Connect workforce IdP |