Migrating from LDAP to OpenID Connect
This topic provides guidance for moving users from Lightweight Directory Access Protocol (LDAP) authentication to OpenID Connect (OIDC).
OIDC authentication is supported in Nexus Repository Cloud and Nexus Repository Pro version 3.86 or later. Before starting this migration, configure OIDC for Nexus Repository. For more information, see OpenID Connect.
Existing LDAP user accounts are not automatically migrated to OIDC identities. OIDC users are created in Nexus Repository after they successfully authenticate through the configured OpenID Provider (OP).
Before making authentication changes, take a database backup.
Migration approach
To move from LDAP to OIDC:
Configure OIDC while keeping your existing LDAP configuration available.
Add the OAuth2 Realm to Active Realms and place it above the Local Authenticating Realm.
Validate OIDC login with a small set of users.
Configure external role mappings so OIDC group claims map to the appropriate Nexus Repository roles.
Confirm that authenticated OIDC users appear in Nexus Repository with the expected roles.
After OIDC authentication and authorization are validated, remove the LDAP realm from Active Realms if you no longer want users to authenticate through LDAP.
User records and role mappings
When a user authenticates through OIDC, Nexus Repository creates the local user record from the OIDC login flow. Authorization is based on the claims returned by the OpenID Provider and the external role mappings configured in Nexus Repository.
Configure role access by mapping OIDC group claims to Nexus Repository roles.
User tokens
LDAP-to-OIDC user token migration is not supported through the LDAP-to-SAML migration task or script.
Users who need user tokens should authenticate through OIDC first. After the OIDC user record exists, the user can create a user token, or an administrator can create one for that user through the user token API.