Salesforce Connector > Connections for Salesforce > Prepare for authentication
  

Prepare for authentication

You can configure Standard, OAuth, and OAuth - JWT connection types to connect to Salesforce. Use an OAuth or OAuth - JWT connection to connect more securely to Salesforce.
Before you configure the connection properties, keep the authentication details handy based on the connection type that you want to use.

Standard

To use a standard connection, you need the Salesforce account user name, password, and service URL. You also need your Salesforce security token to connect to Salesforce. If you do not want to use the security token, you need to add the Data Integration IP addresses to the trusted IP ranges in your Salesforce account.
For more information about the list of IP address ranges used by the Secure Agent and your service, see POD Availability and Networking. For information about setting the IP address in your Salesforce account, see the Salesforce documentation.

OAuth

Create an OAuth connection that uses the OAuth 2.0 protocol to access Salesforce through the Salesforce API. OAuth is a standard protocol that allows for secure API authorization.
To create an OAuth connection, you need an OAuth refresh token. Informatica provides the SFDC OAuth 2.0 tool to generate the OAuth refresh token.
You also need the consumer key and consumer secret from your Salesforce account to generate the OAuth refresh token.
  1. 1Download the SFDC OAuth tool from Informatica Marketplace.
  2. 2Extract the OAuth.zip file.
  3. 3Go to the oauth\conf folder, open the server.xml file, and update the mystore.jks file path to the one on your system. Save and close the file.
  4. 4Go to \oauth\bin and run the command catalina.bat start.
  5. 5Open http://localhost:8090/salesforce from the browser.
  6. 6Enter your Salesforce user name and password to log in.
  7. 7Enter the client ID and client secret, and click Submit.
  8. The client ID is the consumer key in Salesforce and the client secret is the consumer secret in Salesforce.
    The OAuth refresh token is generated.

OAuth - JWT

Create an OAuth - JWT connection to connect to Salesforce without a password or a stored OAuth token.
An OAuth - JWT connection uses a server-to-server flow that doesn't use an interactive login. You sign a JSON Web Token (JWT) with a private key to establish identity, and you upload the self-signed certificate to the external client app in Salesforce. An administrator pre-authorizes consent instead of a user granting approval through a browser.
To create an OAuth - JWT connection, the Salesforce administrator needs to complete prerequisite tasks in Salesforce and gather the configuration details that the JWT requires.
The JWT includes the following claims that you enter in the OAuth JWT Payload property of the Salesforce connection in JSON format:
{
"iss":"<client ID>",
"sub":"<user name>",
"aud":"https://login.salesforce.com",
"exp":"<expiry time in seconds>"
}
For more information about the aud value for the Salesforce production and sandbox environments, see the Salesforce documentation.
  1. 1Download and install OpenSSL on the Secure Agent machine.
  2. 2Generate an RSA private key named server.key and a self-signed certificate named server.crt.
  3. The RSA private key signs the JWT and the self-signed certificate verifies the signature.
    For more information about creating an RSA private key and self-signed certificate, see Create a private key and self-signed digital certificate.
  4. 3Create an external client app in your Salesforce organization with the following configuration:
    1. aEnable OAuth settings.
    2. bSelect the required OAuth scopes.
    3. cSelect Enable JWT Bearer Flow to enable the JWT bearer flow.
    4. dUpload the server.crt self-signed certificate.
    5. eConfigure the required OAuth policies.
    6. fSet an expiry time for the token.
    For more information, see Create an external client app.
  5. 4Get the consumer key from the OAuth settings of the external client app.
  6. The consumer key is the client ID of the app and becomes the iss claim of the JWT. The OAuth - JWT connection requires only the consumer key, not the consumer secret.
  7. 5Authorize a one-time consent for the external client app.
  8. After a one-time consent, the JWT-based flow authorizes subsequent logins automatically.
    For more information about getting the client ID and authorizing consent, see Get and use the consumer key.
  9. 6From the command line, run the following command to create a PKCS12 keystore file bundled with the RSA private key and self-signed certificate:
  10. openssl pkcs12 -export -in <self-signed certificate> -inkey <RSA private key> -out <name of the keystore with a p12 extension>
    For example, to create a PKCS12 keystore file named samplekeystore.p12, run the following command:
    openssl pkcs12 -export -in server.crt -inkey server.key -out samplekeystore.p12
  11. 7Run the following command to convert the PKCS12 keystore file to a Java keystore file:
  12. keytool -importkeystore -srckeystore <PKCS12 keystore file> -srcstoretype pkcs12 -destkeystore <name of the Java keystore> -deststoretype JKS
    For example, to create a Java keystore file using the samplekeystore.p12 file, run the following command:
    keytool -importkeystore -srckeystore samplekeystore.p12 -srcstoretype pkcs12 -destkeystore servercert.jks -deststoretype JKS
  13. 8Run the following command to rename the imported alias to the alias you use in the Salesforce connection:
  14. keytool -keystore servercert.jks -changealias -alias 1 -destalias <alias>