Keycloak IdP SAML 2 Export of XML metdata to an SP

后端 未结 3 1392
你的背包
你的背包 2021-02-08 06:55

I\'m using Keycloak version 1.6.1, newly installed as a standalone application.

Keycloak should act as an IdP (Identity provider) for an SP (Service Provider) called Tab

相关标签:
3条回答
  • 2021-02-08 06:55

    Since Keycloak 3.x, IdP XML descriptor needs /auth/ after keycloak-url

    https://{KEYCLOAK-URL}/auth/realms/{REALM-NAME}/protocol/saml/descriptor
    
    0 讨论(0)
  • 2021-02-08 07:00

    The original poster is correct that the option SAML Metadata IDPSSODescriptor is no longer available on Keycloak 6.0.1

    One change to make is when you use the URL https://{KEYCLOAK-URL}/auth/realms/{REALM-NAME}/protocol/saml/descriptor, Rancher expects the root element to be EntityDescriptor so you need to remove EntitiesDescriptor and copy the namespaces from the root element.

    i.e.

    <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" entityID="https://{KEYCLOAK-URL}/auth/realms/{REALM-NAME}">
      ....
    
    </EntityDescriptor>
    
    0 讨论(0)
  • 2021-02-08 07:20

    Sometimes it's a good thing to specify in writing what you need - which I did here on Stack Overflow.

    I found the URL to where on Keycloak one can export the IdP XML

    https://keycloak-url/realms/{REALM-NAME}/protocol/saml/descriptor
    

    That gave me the IDPSSODescriptor.

    I'll leave this thread here, so people can benefit from my mistakes.

    0 讨论(0)
提交回复
热议问题