| Both sides previous revision Previous revision Next revision | Previous revision |
| en:2.0:single_sign_on:saml_keycloak [2026/09/09 19:24] – [Quick Overview] kainhofer | en:2.0:single_sign_on:saml_keycloak [2026/09/09 20:28] (current) – [Profile Attributes from Admidio] kainhofer |
|---|
| |
| Keycloak also provides some more configuration settings that allow fine-tuning the SAML login behavior. The defaults should work fine, but changes can be made if other settings are prefered. | Keycloak also provides some more configuration settings that allow fine-tuning the SAML login behavior. The defaults should work fine, but changes can be made if other settings are prefered. |
| | |
| {{:en:2.0:sso:sso_saml_keycloak_04_config_keycloak.png?direct&400|}}{{:en:2.0:sso:sso_saml_keycloak_04b_config_keycloak.png?direct&400|}} | {{:en:2.0:sso:sso_saml_keycloak_04_config_keycloak.png?direct&400|}}{{:en:2.0:sso:sso_saml_keycloak_04b_config_keycloak.png?direct&400|}} |
| |
| {{ :en:2.0:sso:sso_saml_keycloak_04d_config_admidio_mapping.png?direct&400 |}} | {{ :en:2.0:sso:sso_saml_keycloak_04d_config_admidio_mapping.png?direct&400 |}} |
| |
| Unfortunately, there is no specification of the meaning of particular SAML attributes, so Keycloak by default does map those fields to its user's profile data. One can set up attribute mappers in Keycloak to use SAML attributes and assign them to the user's profile. | Unfortunately, there is no specification of the meaning of particular SAML attributes, so Keycloak by default does not map those fields to its user's profile data. One can set up attribute mappers in Keycloak to use SAML attributes and assign them to the user's profile. |
| Go to the "Mappers" tab of the SAML provider in Keycloak and add new mappers of type "Attribute Importer". It is a good idea to choose "Force", which will always update the keycloak user with the value from Admidio on every login. The "Attribute Name" is the SAML attribute, while the "User Attribute Name" is Keycloak's profile field name. | Go to the "Mappers" tab of the SAML provider in Keycloak and add new mappers of type "Attribute Importer". It is a good idea to choose "Force", which will always update the keycloak user with the value from Admidio on every login. The "Attribute Name" is the SAML attribute, while the "User Attribute Name" is Keycloak's profile field name. |
| {{ :en:2.0:sso:sso_saml_keycloak_04c_config_mappers.png?direct&600 |}} | {{ :en:2.0:sso:sso_saml_keycloak_04c_config_mappers.png?direct&600 |}} |