I\'m using Keycloak version 1.6.1, newly installed as a standalone application.
Keycloak should act as an IdP (Identity provider) for an SP (Service Provider) called Tab
The original poster is correct that the option SAML Metadata IDPSSODescriptor
is no longer available on Keycloak 6.0.1
One change to make is when you use the URL https://{KEYCLOAK-URL}/auth/realms/{REALM-NAME}/protocol/saml/descriptor
, Rancher expects the root element to be EntityDescriptor
so you need to remove EntitiesDescriptor
and copy the namespaces from the root element.
i.e.
....