You can configure Standard, OAuth, and OAuth - JWT connection types to connect to Salesforce. Use an OAuth or OAuth - JWT connection to connect more securely to Salesforce.
Before you configure the connection properties, keep the authentication details handy based on the connection type that you want to use.
Standard
To use a standard connection, you need the Salesforce account user name, password, and service URL. You also need your Salesforce security token to connect to Salesforce. If you do not want to use the security token, you need to add the Data Integration IP addresses to the trusted IP ranges in your Salesforce account.
For more information about the list of IP address ranges used by the Secure Agent and your service, see POD Availability and Networking. For information about setting the IP address in your Salesforce account, see the Salesforce documentation.
OAuth
Create an OAuth connection that uses the OAuth 2.0 protocol to access Salesforce through the Salesforce API. OAuth is a standard protocol that allows for secure API authorization.
To create an OAuth connection, you need an OAuth refresh token. Informatica provides the SFDC OAuth 2.0 tool to generate the OAuth refresh token.
You also need the consumer key and consumer secret from your Salesforce account to generate the OAuth refresh token.
3Go to the oauth\conf folder, open the server.xml file, and update the mystore.jks file path to the one on your system. Save and close the file.
4Go to \oauth\bin and run the command catalina.bat start.
5Open http://localhost:8090/salesforce from the browser.
6Enter your Salesforce user name and password to log in.
7Enter the client ID and client secret, and click Submit.
The client ID is the consumer key in Salesforce and the client secret is the consumer secret in Salesforce.
The OAuth refresh token is generated.
OAuth - JWT
Create an OAuth - JWT connection to connect to Salesforce without a password or a stored OAuth token.
An OAuth - JWT connection uses a server-to-server flow that doesn't use an interactive login. You sign a JSON Web Token (JWT) with a private key to establish identity, and you upload the self-signed certificate to the external client app in Salesforce. An administrator pre-authorizes consent instead of a user granting approval through a browser.
To create an OAuth - JWT connection, the Salesforce administrator needs to complete prerequisite tasks in Salesforce and gather the configuration details that the JWT requires.
The JWT includes the following claims that you enter in the OAuth JWT Payload property of the Salesforce connection in JSON format:
{ "iss":"<client ID>", "sub":"<user name>", "aud":"https://login.salesforce.com", "exp":"<expiry time in seconds>" }
For more information about the aud value for the Salesforce production and sandbox environments, see the Salesforce documentation.
1Download and install OpenSSL on the Secure Agent machine.
2Generate an RSA private key named server.key and a self-signed certificate named server.crt.
The RSA private key signs the JWT and the self-signed certificate verifies the signature.
4Get the consumer key from the OAuth settings of the external client app.
The consumer key is the client ID of the app and becomes the iss claim of the JWT. The OAuth - JWT connection requires only the consumer key, not the consumer secret.
5Authorize a one-time consent for the external client app.
After a one-time consent, the JWT-based flow authorizes subsequent logins automatically.