Hello everybody,
Update: (still no SSSD federation option in keycloak-17.0.0...
requesting further assistance)
I restarted my installation on the newer CentOS Stream 9, because the
jna package depends on java-11-headless witch works with
keycloak-17.0.0.tar.gz (in opposite of the situation in CentOS Stream 8)
I installed jna, libunix-dbus-java-0.8.0-1.fc24.x86_64.rpm and sssd-dbus
I used /opt/keycloak/keycloak-17.0.0/bin/federation-sssd-setup.sh from
keycloak-legacy-17.0.0.zip to make sure /etc/pam.d/keycloak and
/etc/sssd/sssd.conf are configured correctly.
The bellow commands are both working:
sudo dbus-send --print-reply --system
--dest=org.freedesktop.sssd.infopipe /org/freedesktop/sssd/infopipe
org.freedesktop.sssd.infopipe.GetUserGroups string:j.doe
sudo sssctl user-checks j.doe -s keycloak
I restarted the whole machine just to make sure the services/java
packages are reloaded correctly.
So this is as the steps here:
https://matthew-beliveau.github.io/Keycloak-SSSD-and-FreeIPA/ but this
was written in 2018.
I do not see any SSSD federation option in keycloak-17.0.0, what should
I do to integrate FreeIPA?
Am I missing a feature that I should build?
Mar 06 17:32:59 keycloak02.example.lan kc.sh[2132]: 2022-03-06
17:32:59,181 INFO [io.quarkus] (main) Installed features: [agroal, cdi,
hibernate-orm, infinispan-client, jdbc-h2, jdbc-mariadb, jdbc-mssql,
jdbc-mysql, jdbc-oracle, jdbc-postgresql, keycloak, narayana-jta,
reactive-routes, resteasy, resteasy-jackson,
smallrye-context-propagation, smallrye-health, smallrye-metrics, vault,
vertx]
Kind regards,
Jelle de Jong
> --
> You received this message because you are subscribed to the Google
> Groups "Keycloak User" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to
keycloak-use...@googlegroups.com
> <mailto:
keycloak-use...@googlegroups.com>.
> To view this discussion on the web visit
>
https://groups.google.com/d/msgid/keycloak-user/532ab9ee-1184-4081-8c42-da318d0870a5n%40googlegroups.com
> <
https://groups.google.com/d/msgid/keycloak-user/532ab9ee-1184-4081-8c42-da318d0870a5n%40googlegroups.com?utm_medium=email&utm_source=footer>.