Page History
...
It is possible to link Keycloak to an Active Directory with the Kerberos protocol using User Federation. This will allow users to sign in using their AD credentials. To set this up:
- Select User Federation from the navigation panel
...
- and then select "Add Kerberos providers".
- Choose a UI display name
...
- Enter the Kerberos Realm
...
- Enter the principal for the serverÂ
...
- Enter the location of the keytab file containing credentials of the given principal
...
...
- Set Allow Password Authentication to On:
...
- Set Edit Mode to READ_ONLY
...
- In order to test it, a AD user can try to sign in to the Account console for the Studio realm at
http://<domain:port>/Keycloak/realms/<realm>/account
Overview
Content Tools