Railnova supports OpenID Connect.
The activation/deactivation of those authentication methods is handled by the Railnova Customer Success Team. You can contact the team via chat through the Railnova platform, by clicking on "Contact us".
Pricing of the OpenID Connect Single Sign-On (SSO)
The OpenID Connect SSO is subject to a commercial support agreement to ensure that contact persons, service notifications, security upgrades, and migrations can be managed smoothly between the Client IT environment and the Railnova software platform.
If you desire a different SSO than OpenID Connect SSO, Railnova offers custom integration plans, subject to a specific commercial agreement. Please contact our Sales team for any questions related to custom integrations.
OpenID Connect
This authentication method delegates the Authentication and Authorization flow to an OpenID Connect implementation. Here is showcased an example with the Keycloak solution.
Authentication configuration
In order for the Azure Active Directory authentication method to be fully enabled, you will need to:
Go to the Railnova admin and select the Company section;
or navigate to the Company section and then click Company
Select Your Company in the list;
You should see a block for OpenID Connect SSO configuration, if not please contact Railnova Support Team, the OpenID Connect SSO authentication method has not been enabled for your company;
Register a new application with your OpenID Connect service.
For instance, using the Keycloak implementation, create a new client in a central realm, here one with railnova as id, and set its Valid redirect URIs to the one referenced in Railnova Admin under "Redirect URI".
On the same tab, make sure to enable Client authentication for that OpenID Connect client :
In the Credentials tab, set this Client Authenticator to Client Id and Secret, then copy the generated secret :
Finally, back in Railnova Admin on your company page, set the OpenID Connect OIDC URL, the Client Id and the Secret copied from the client setup above:
Users in the configured realm of your federation should now be able to sign on Railnova with your OpenID Connect service.
Note on the combination of multiple Authentication methods
It is allowed to have more than one authentication method activated at one time. This option is often necessary for granting access to third parties and can be deactivated.
When having multiple Authentication methods activated (such as a password method alongside an SSO method), removing a user from your SSO provider won’t necessarily mean that a user has no more access to Railnova if he or she had set up a password previously.
Support
Do you still have questions? Go to the Railnova platform and click "Contact us" for help!









