KB50017 - How to create a Creating Keycloak Credentials in Zerto version 10.x

How to create a Creating Keycloak Credentials in Zerto version 10.x

 

Zerto made a shift in version 10.x, transitioning from the Windows-based ZVM to the Linux-based Zerto Virtual Manager Appliance (ZVMA), which integrates microservices for security and authentication. This transition influenced the development of a new iteration of EnsureDR, capitalizing on the enhanced capabilities introduced in Zerto v10.x

With the release of EnsureDR version 4.17, the only supported Zerto version is 10.x which works in conjunction with the Linux Appliance and utilizes the Keycloak authorization.

 

To create the Client for EnsureDR follow the steps below.

  1. Open Keycloak Administration

 

A screenshot of a computer

Description automatically generated

 

  1. Log with default credential that are created during the Zerto setup.

 

 

  1. When logged, select the Zerto realm from drop down list.

 

 

  1. Select the Clients option and click Create client.

 

 

  1. In the General Settings, leave default Client type “OpenID Connect”, enter a Client ID, the rest of the fields are optional. Click Next.

 

 

  1. Set the Capability config:
  • Client authentication - On
  • Authorization - On
  • Authentication flow – Select:
    • Standard flow
    • Implicit flow
    • Direct access grants

Click Next to continue.

 

A screenshot of a computer

Description automatically generated

 

  1. Click Save to create the client.

 

 

  1. After Keycloak has created the client, the Client details screen displays with different tabs to define settings for the client. Select the Credentials tab, and then copy the client secret.

 

 

The Client ID and Secret that you created in Keycloak you will need to enter in EnsureDR job setting page.

 

  1. If you're configuring the Zerto job for the first time, proceed to the next step. In case of an upgrade from EnsureDR version 4.16 to version 4.17, open a job and update the Zerto Client ID and Secret accordingly.
  • Click on the pencil icon (1)
  • Once the new form opens, enter the Client ID (2) and Secret (3).
  • Click on the Apply button (4)
  • Click on the Next button (5) to the last page and save the job.

 

 

  1. If you're configuring the Zerto job for the first time enter Zerto Source (1) and Target (2) IP or FQDN, then enter Client ID (3) and Secret (4) you created on Zerto DR site.