3 ms·
I love keycloak but I was always disappointed it cannot be used as an LDAP server. As many open source products and SaaS support LDAP as authentication/authori
by TedLePoireau 6y ago
I love keycloak but I was always disappointed it cannot be used as an LDAP server. As many open source products and SaaS support LDAP as authentication/authorization, it would have been perfecy for an internal SSO.
Instead of keycloak, I had to rely on GSuite Identity Premium: hood product but gets expensive quickly...
- snuxoll 6y agoSetting up OpenLDAP or 389ds and integrating Keycloak with it is hardly rocket science - no need to reinvent the wheel.
- vetinari 6y agoSetting it up with FreeIPA (which contains 389ds) is a matter of filling up a single form in Keycloak admin. That includes SPNEGO (passwordless auth in browser) for those, who are enrolled into domain or have Kerberos tickets.
- kiney 6y agoFreeIPA has it's own set of problems. One being basically unrunnable in containers because of weird systemd stuff
- vetinari 6y agoFreeIPA is not supported in containers, because it is integration of a bunch of services that need to be on the same machine and each of them has its own idea where to keep state. It has nothing to do with systemd, despite what systemd-phobes think.
- doublerabbit 6y agoAnd is somewhat broken and bodged with FreeBSD.