This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |
| en:2.0:single_sign_on:saml_keycloak [2026/09/09 20:25] – [Setting up the Client (SP) in Admidio] kainhofer | en:2.0:single_sign_on:saml_keycloak [2026/09/09 20:28] (current) – [Profile Attributes from Admidio] kainhofer |
|---|
| {{ :en:2.0:sso:sso_saml_keycloak_04d_config_admidio_mapping.png?direct&400 |}} | {{ :en:2.0:sso:sso_saml_keycloak_04d_config_admidio_mapping.png?direct&400 |}} |
| |
| Unfortunately, there is no specification of the meaning of particular SAML attributes, so Keycloak by default does map those fields to its user's profile data. One can set up attribute mappers in Keycloak to use SAML attributes and assign them to the user's profile. | Unfortunately, there is no specification of the meaning of particular SAML attributes, so Keycloak by default does not map those fields to its user's profile data. One can set up attribute mappers in Keycloak to use SAML attributes and assign them to the user's profile. |
| Go to the "Mappers" tab of the SAML provider in Keycloak and add new mappers of type "Attribute Importer". It is a good idea to choose "Force", which will always update the keycloak user with the value from Admidio on every login. The "Attribute Name" is the SAML attribute, while the "User Attribute Name" is Keycloak's profile field name. | Go to the "Mappers" tab of the SAML provider in Keycloak and add new mappers of type "Attribute Importer". It is a good idea to choose "Force", which will always update the keycloak user with the value from Admidio on every login. The "Attribute Name" is the SAML attribute, while the "User Attribute Name" is Keycloak's profile field name. |
| {{ :en:2.0:sso:sso_saml_keycloak_04c_config_mappers.png?direct&600 |}} | {{ :en:2.0:sso:sso_saml_keycloak_04c_config_mappers.png?direct&600 |}} |