SOT
    • Introduction
    • User manual
      • Getting started
        • Device registration overview
          • Registering a device
          • Self-registration of devices
        • Device claiming
          • Adding a ctrlX Core device
          • Adding a Rexroth connectivity unit device
      • Device overview
        • Setting the filter for the search
        • Device details
        • Edit device properties
        • Roll out artifacts on one or more devices
        • Rolling out a distribution
      • Device groups
        • Creating a device group
      • Machine overview
        • Create, edit and delete machines
        • Adding machines and devices via CSV file import
        • Structure of the CSV import file
      • Activity overview
      • Distribution overview
        • Managing distributions
        • Managing commands in a distribution
    • Operations manual
      • Overview
      • System architecture and interfaces
        • Element descriptions
        • Network connections overview
      • System requirements
        • General system requirements
        • Ingress controller
        • idm/idm-device-administration-app
        • idm/idm-software-management-app
        • idm/idm-device-monitoring-app
        • idm/idm-device-master-data-mgmt-app
        • idm/idm-device-app
        • idm/idm-solution-app
        • idm/idm-webapp-backend
        • idm/idm-device-tunnel-app
        • idm/idm-artifact-repository
        • bci-app/opensearch
        • bci-app/opensearch-dashboards
        • bci-app/valkey
        • bci-app/nginx
        • bci-kube/nexeed-ansible-operator
      • Migration from previous versions
      • Setup and configuration
        • Installation guide
          • How to initialize OpenSearch
          • How to create MACMA tenants with basic authentication
          • How to configure tenants for artifact-related use cases
        • Configuration
          • Detailed configuration parameters
          • Recommendations for service meshes
      • Start and shutdown
      • Regular operations
        • Whitelist new certificate
      • Failure handling
        • Device Portal data is out of sync
        • How to synchronize devices and machines to OpenSearch
        • Synchronize communication id mapping to key-value store (Redis/Valkey)
      • Backup and Restore
      • Logging and monitoring
      • Known limitations
    • Developer guide
      • Communication ID
      • Adding diagnostic functionality to devices
      • Add command processing to devices
      • Add the backup/restore functionality to devices
      • Reducing data consumption of device communication
      • Access through a custom application
    • Artifact Repository guide
      • Introduction
      • Providing artifacts for roll-out
        • Establishing a connection to the Device Portal
        • Uploading and managing artifacts in the repository
      • Downloading artifacts
      • Sending commands
    • API documentation
    • Glossary
Device Portal
  • Smart Operations Toolkit
    • Deviation Processor
    • Multitenant Access Control
    • Notification Service
    • Ticket Management
    • Web Portal
  • Shopfloor Management
    • Andon Live
    • KPI Reporting
    • Operational Routines
    • Shift Book
    • Shopfloor Management Administration
  • Product & Quality
    • Process Quality
    • AI Services
  • Machine & Equipment
    • Condition Monitoring
    • Device Portal
  • Enterprise & Shopfloor Integration
    • Information Router
    • Master Data Management

SOT Learning Portal

  • Device Portal
  • Operations manual
  • Setup and configuration
  • Installation guide
  • How to create MACMA tenants with basic authentication

How to create MACMA tenants with basic authentication

For the MACMA tenant configuration, it is necessary to manually create organizations and configure them. Organization and tenant refer to the same concept.

This guide is derived from here: NEXOPS: How to create a new Tenant.

Password requirements

During the MACMA tenant creation, it is required to create users and assign them an initial password. This password will be replaced after the first login attempt but it still needs to fulfill the requirements. Keep them in mind while setting the password:

  • must contain at least 1 upper case characters.

  • must contain at least 1 lower case characters.

  • must contain at least 1 numerical digits.

  • minimum length 12.

Create organization

  1. Login to default tenant with admin credentials from custom-values (variables macmaPortalAdminUser and macmaPortalAdminPassword)

  2. Go to Access Management → Organizations

  3. Create an organization with admin username "tenant_admin" and any valid password (see password-requirements)

  4. Document the tenant id

Create contracts

Follow these steps for each organization.

  1. Create 2 new contracts:

    1. Create 1 contract for Portal and MACMA called "Foundation" (description: "provide Roles: Access-Manager, User-reader, and Portal-user, Portal-Admin, Portal Operator, Portal Registration") & Type Provision (Note: There could exist a UI wrong description of the types as the type we really need is access/consumer, see MACMA provider and consumer scope naming in the UI )

      1. During the second step "Contractual Partner", activate the checkbox "Assign all roles of the contract to the following user:" and insert the "tenant_admin" username defined in the previous steps

    2. Create 1 contract for Device portal called "Device Portal" with all Device Portal roles except DP_CAN_MANAGE_DEVICE_GROUPS (description: "Provide Device Portal Roles to Device Portal") & Type Provision

      1. During the second step "Contractual Partner", activate the checkbox "Assign all roles of the contract to the following user:" and insert the "tenant_admin" username defined in the previous steps

Configure tenants

For each created tenant, follow these steps:

  1. Login to the tenant

    1. On first login with the previously created admin user a new password needs to be specified. Save this password.

  2. Create a new user for operations tasks

    1. Assign this user any valid password (see password-requirements).

  3. Create Group "Web-application User"

    1. Assign the role Web Portal User and all Device Portal roles except DP_CAN_MANAGE_REPOSITORY_SOFTWARE, DP_CAN_MANAGE_SOFTWARE_ON_DEVICE, DP_DEVICE_DELETE and roles starting with "DP_API"

    2. Assign the created user to this group

  4. Create Group "Artifact Repository Manager".

    1. Assign Device Portal roles DP_CAN_MANAGE_REPOSITORY_SOFTWARE, DP_CAN_MANAGE_SOFTWARE_ON_DEVICE

    2. Assign the created user to this group

  5. Create a Group called "Tenant Owner" with the roles: Access Manager, Web Portal Admin, Web Portal User and User Reader

  6. Assign role User Reader to the module called "Nexeed Device Portal"

  7. Create a Module called "DP_Solution_API"

    1. Provide a secure password

    2. In the next tab, deactivate user login and finish the dialog

    3. Switch to the tab "Assigned Roles" and assign all Device Portal roles starting with "DP_API"

    4. Save the client id and client secret

  8. Log out and login with the created user. Change the password as prompted and save the credentials.

Contents

© Robert Bosch Manufacturing Solutions GmbH 2023-2026, all rights reserved

Changelog Corporate information Legal notice Data protection notice Third party licenses