Dear
Hannah and Thomas,
We are exploring the possibility of implementing a KeyCloak to connect to eduGAIN. I am new as far as KeyCloak is concerned, in addition to KeyCloak we are also testing a GLUU server. (
https://www.gluu.org/)
Hannah certainly has more experience,
it would be GREAT if KeyCloak can upgrade with all the modules needed for eduGAIN. (
https://edugain.org/)
Hannah, I would be very grateful if you could help us with the implementation of KeyClaok for eduGAIN, and do you know any reliable solution for WAYF? Or do you recommend Discovery Service?
Note: We are a decentralized system, and we cannot have one central SSO / IDP.
I was able to connect KeyCloak as an IDP with Google services as a SP. When logging in to Google services, our users are redirected to our KeyCloak server, and after authentication to KeyCloak, they get access to Google. (Note: Google is not an IDP).
QUESTION: Can KeyCloak do "Provisioning" users from KeyCloak to Google? Only users with a Google Account can sign in. We are currently working on Sync between LDAP / AD and Google, but that solution is extra work.
Best Regards,
Salko