Skip to main content

Add intermediate trust anchors in OpenID Federation

Add an intermediate trust anchor when you are building a federation of federations in OpenID Federation. This how-to describes the two supported approaches in Raidiam Connect.

Prerequisites

  • You already have a federation created in Reference Data.

  • To add a sub-federation in Reference Data (option 1), you must have Super User access.

  • For the authority-based approach, you can administer the organisation that will become the intermediate trust anchor.

Choose how to add an intermediate trust anchor

You can add intermediate trust anchors in two ways:

  1. Create another federation in Reference Data and set the superior trust anchor in Remote Trust Anchor.

  2. Configure an organisation as an authority, which also makes it an intermediate trust anchor.

Option 1: Create another federation in Reference Data

Use this approach when you want an intermediate sub-federation with its own administration.

Follow Create an OpenID Federation in Reference Data.

Option 2: Make an organisation an authority (intermediate trust anchor)

  1. Navigate to the organisation you administer.

  2. Select Details > Authority > Add Authority.

  3. Fill in the required fields:


    FieldDescription
    Authority CodeUnique identifier assigned to the intermediate trust anchor for identification purposes
    Authority URIURL of the superior trust anchor; this value is also included in the authority_hints metadata parameter for this intermediate trust anchor. You can point to different superior trust anchors, including external trust anchors
  4. Save the authority.


The authority is now created and acts as an intermediate trust anchor.

info

Request your ecosystem administrator (a Super User) to map this authority to a domain in your federation (and to other domains if needed).

What's next

  1. Map authorities to domains.

  2. Onboard organizations.