See below for creating an external named credential in SFDC.
CSP Vault must have a publicly routable address and a publicly signed certificate in order to communicate with Salesforce.
Creating an external named credential in SFDC
- In Salesforce, navigate to Named Credentials.
In the External Credentials tab, click New.
In the New External Credential window, enter the Label and the Name, and select JWT for the Authentication Protocol.
Complete the following:
Click Save.
In the Principals section, click New.
In the Create Principal window, complete the following:
- Parameter Name—Enter a name for the principal.
- Identity Type—Select Named Principal.
- Click Save.
Return to Named Credentials.
Click the Named Credentials tab, and click New.
In the Named Credentials window, enter the Label and the Name.
Enter the URL that you want to use for the callouts in the following format:
https://<vault>/v5/sfdcUnder Authentication, select the External Credential that you created.
Click Save.
Navigate to Users > Permission Sets.
Create a permission set that gives the user permission to access external credentials.
Return to the named credential that you created and copy the ID from the URL.
The ID is located after
/NamedCredential/
Issuer (iss)
Enter the Salesforce Organization ID.
You can find this value on the Company Information page in Salesforce.
Subject (sub)
Enter the Client ID that you used when you created the Cloud Service Provider Account for SFDC.
This value was referred to as "Customer Key" in Salesforce.
Audience (aud)
Enter the name of the Cloud Service Provider Account that you created.
JWT Expiration (in seconds)
Set to 600 seconds (10 minutes).
Signing Certificate
Enter the name of the wrapping certificate that you used when you created the Cloud Service Provider Account for SFDC.
Signing Algorithm
Select RS256.