Using PingFederate Service
You can configure the connector to authenticate your connection through IAM authentication using the credentials stored in the PingFederate service.
To configure IAM authentication using PingFederate service:
- Set the
UIDproperty to the user name associated with your Ping account. - Set the
PWDproperty to the password associated with your Ping user name. - Set the
IAMproperty to1. - Set the
plugin_nameproperty toping. - If the ID and region of the Redshift server cluster are not already provided through the
Serverproperty, then do the following:- Set the
ClusterIDproperty to the ID for the Redshift server cluster. - Set the
Regionproperty to the region for the Redshift server cluster.
- Set the
- Set the
DbUserproperty to the ID that you want to designate to the Redshift user. - If the ID you specified for the
DbUserproperty does not already exist in your Redshift account, you must create it:- Set the
AutoCreateproperty to1. - Set the
DbGroupsproperty to the names of any user groups that you want the new DbUser to be added to, separated by commas. - Optionally, to lowercase all
DbGroupsthat are received from the identity provider, select theForce Lowercasecheck box.
- Set the
- Optionally, set the
EndpointUrlproperty to the endpoint used to retrieve the Redshift cluster's credentials. - Optionally, set the
StsEndpointUrlproperty to the endpoint used to communicate with the AWS Security Token Service (AWS STS). - Optionally, set the
VPCEndpointUrlproperty to the endpoint used to communicate with the Redshift cluster. - Optionally, set the
AuthProfileproperty to the authentication profile you want to use to manage the connection settings, then do the following:- Set the
AccessKeyIDproperty to your Redshift access key ID. - Set the
SecretAccessKeyproperty to your Redshift secret key.
- Set the
- Set the
IdP_Hostproperty to the address of the service host. - Set the
IdP_Portproperty to the port number that the service listens at. - Set the
Preferred_Roleproperty to the name or ID for the IAM Role that you want the user to assume when logged in to Redshift. - To skip verification of the SSL certificate of the IDP server, set the
SSL_Insecureproperty to1. - Optionally, set the
partner_spidproperty to a partner SPID (service provider ID) value.