mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 22:49:17 +00:00
Address feedback. Also fix table formatting
This commit is contained in:
@@ -61,7 +61,19 @@ If your organization uses Keycloak Identity Provider (IdP) for user authenticati
|
|||||||
|
|
||||||
1. Select **Keycloak**.
|
1. Select **Keycloak**.
|
||||||
|
|
||||||
1. Complete the **Configure Keycloak Account** form.
|
1. Complete the **Configure Keycloak Account** form. For help with filling the form, see the [configuration reference](#configuration-reference).
|
||||||
|
|
||||||
|
1. After you complete the **Configure Keycloak Account** form, click **Authenticate with Keycloak**, which is at the bottom of the page.
|
||||||
|
|
||||||
|
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
||||||
|
|
||||||
|
>**Note:** You may have to disable your popup blocker to see the IdP login page.
|
||||||
|
|
||||||
|
**Result:** Rancher is configured to work with Keycloak. Your users can now sign into Rancher using their Keycloak logins.
|
||||||
|
|
||||||
|
{{< saml_caveats >}}
|
||||||
|
|
||||||
|
## Configuration Reference
|
||||||
|
|
||||||
|
|
||||||
| Field | Description |
|
| Field | Description |
|
||||||
@@ -80,23 +92,13 @@ If your organization uses Keycloak Identity Provider (IdP) for user authenticati
|
|||||||
> openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout myservice.key -out myservice.cert
|
> openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout myservice.key -out myservice.cert
|
||||||
|
|
||||||
|
|
||||||
1. After you complete the **Configure Keycloak Account** form, click **Authenticate with Keycloak**, which is at the bottom of the page.
|
|
||||||
|
|
||||||
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
|
||||||
|
|
||||||
>**Note:** You may have to disable your popup blocker to see the IdP login page.
|
|
||||||
|
|
||||||
**Result:** Rancher is configured to work with Keycloak. Your users can now sign into Rancher using their Keycloak logins.
|
|
||||||
|
|
||||||
{{< saml_caveats >}}
|
|
||||||
|
|
||||||
## Annex: Troubleshooting
|
## Annex: Troubleshooting
|
||||||
|
|
||||||
If you are experiencing issues while testing the connection to the Keycloak server, first double-check the configuration option of your SAML client. You may also inspect the Rancher logs to help pinpointing the problem cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging]({{<baseurl>}}/rancher/v2.5/en/faq/technical/#how-can-i-enable-debug-logging) in this documentation.
|
If you are experiencing issues while testing the connection to the Keycloak server, first double-check the configuration option of your SAML client. You may also inspect the Rancher logs to help pinpointing the problem cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging]({{<baseurl>}}/rancher/v2.5/en/faq/technical/#how-can-i-enable-debug-logging) in this documentation.
|
||||||
|
|
||||||
### You are not redirected to Keycloak
|
### You are not redirected to Keycloak
|
||||||
|
|
||||||
When you click on **Authenticate with Keycloak**, your are not redirected to your IdP.
|
When you click on **Authenticate with Keycloak**, you are not redirected to your IdP.
|
||||||
|
|
||||||
* Verify your Keycloak client configuration.
|
* Verify your Keycloak client configuration.
|
||||||
* Make sure `Force Post Binding` set to `OFF`.
|
* Make sure `Force Post Binding` set to `OFF`.
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
`Access Type` | `confidential`
|
`Access Type` | `confidential`
|
||||||
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
|
`Valid Redirect URI` | `https://yourRancherHostURL/verify-auth`
|
||||||
|
|
||||||
- In the new OIDC client, create [Mappers](https://www.keycloak.org/docs/latest/server_admin/#_protocol-mappers) to expose the users fields
|
- In the new OIDC client, create [Mappers](https://www.keycloak.org/docs/latest/server_admin/#_protocol-mappers) to expose the users fields.
|
||||||
- Create a new "Groups Mapper" with the settings below.
|
- Create a new "Groups Mapper" with the settings below.
|
||||||
|
|
||||||
Setting | Value
|
Setting | Value
|
||||||
@@ -43,8 +43,17 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
|
|
||||||
1. Select **Keycloak (OIDC)**.
|
1. Select **Keycloak (OIDC)**.
|
||||||
|
|
||||||
1. Complete the **Configure a Keycloak OIDC account** form.
|
1. Complete the **Configure a Keycloak OIDC account** form. For help with filling the form, see the [configuration reference](#configuration-reference).
|
||||||
|
|
||||||
|
1. After you complete the **Configure a Keycloak OIDC account** form, click **Enable**.
|
||||||
|
|
||||||
|
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
||||||
|
|
||||||
|
>**Note:** You may need to disable your popup blocker to see the IdP login page.
|
||||||
|
|
||||||
|
**Result:** Rancher is configured to work with Keycloak using the OIDC protocol. Your users can now sign into Rancher using their Keycloak logins.
|
||||||
|
|
||||||
|
## Configuration Reference
|
||||||
|
|
||||||
| Field | Description |
|
| Field | Description |
|
||||||
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
@@ -55,23 +64,14 @@ If you have an existing configuration using the SAML protocol and want to switch
|
|||||||
| Keycloak URL | The URL for your Keycloak server. |
|
| Keycloak URL | The URL for your Keycloak server. |
|
||||||
| Keycloak Realm | The name of the realm in which the Keycloak client was created in. |
|
| Keycloak Realm | The name of the realm in which the Keycloak client was created in. |
|
||||||
| Rancher URL | The URL for your Rancher Server. |
|
| Rancher URL | The URL for your Rancher Server. |
|
||||||
| Issuer | The URL of your IdP.
|
| Issuer | The URL of your IdP. |
|
||||||
| Auth Endpoint | The URL where users are redirected to authenticate.
|
| Auth Endpoint | The URL where users are redirected to authenticate. |
|
||||||
|
|
||||||
|
|
||||||
1. After you complete the **Configure a Keycloak OIDC account** form, click **Enable**.
|
|
||||||
|
|
||||||
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
|
||||||
|
|
||||||
>**Note:** You may need to disable your popup blocker to see the IdP login page.
|
|
||||||
|
|
||||||
**Result:** Rancher is configured to work with Keycloak using the OIDC protocol. Your users can now sign into Rancher using their Keycloak logins.
|
|
||||||
|
|
||||||
## Migrating from SAML to OIDC
|
## Migrating from SAML to OIDC
|
||||||
|
|
||||||
This section describes the process to transition from using Rancher with Keycloak (SAML) to Keycloak (OIDC).
|
This section describes the process to transition from using Rancher with Keycloak (SAML) to Keycloak (OIDC).
|
||||||
|
|
||||||
### Changes to Keycloak
|
### Reconfigure Keycloak
|
||||||
|
|
||||||
1. Change the existing client to use the OIDC protocol. In the Keycloak console, select **Clients**, select the SAML client to migrate, select the **Settings** tab, change `Client Protocol` from `saml` to `openid-connect`, and click **Save**
|
1. Change the existing client to use the OIDC protocol. In the Keycloak console, select **Clients**, select the SAML client to migrate, select the **Settings** tab, change `Client Protocol` from `saml` to `openid-connect`, and click **Save**
|
||||||
|
|
||||||
@@ -88,7 +88,7 @@ This section describes the process to transition from using Rancher with Keycloa
|
|||||||
`Add to access token` | `ON`
|
`Add to access token` | `ON`
|
||||||
`Add to user info` | `ON`
|
`Add to user info` | `ON`
|
||||||
|
|
||||||
### Changes to Rancher
|
### Reconfigure Rancher
|
||||||
|
|
||||||
Before configuring Rancher to use Keycloak (OIDC), Keycloak (SAML) must be first disabled.
|
Before configuring Rancher to use Keycloak (OIDC), Keycloak (SAML) must be first disabled.
|
||||||
|
|
||||||
@@ -110,7 +110,7 @@ All Keycloak related log entries will be prepended with either `[generic oidc]`
|
|||||||
|
|
||||||
### You are not redirected to Keycloak
|
### You are not redirected to Keycloak
|
||||||
|
|
||||||
When you fill the **Configure a Keycloak OIDC account** form and click on **Enable**, your are not redirected to your IdP.
|
When you fill the **Configure a Keycloak OIDC account** form and click on **Enable**, you are not redirected to your IdP.
|
||||||
|
|
||||||
* Verify your Keycloak client configuration.
|
* Verify your Keycloak client configuration.
|
||||||
|
|
||||||
|
|||||||
@@ -61,8 +61,19 @@ If your organization uses Keycloak Identity Provider (IdP) for user authenticati
|
|||||||
|
|
||||||
1. Select **Keycloak**.
|
1. Select **Keycloak**.
|
||||||
|
|
||||||
1. Complete the **Configure Keycloak Account** form.
|
1. Complete the **Configure Keycloak Account** form. For help with filling the form, see the [configuration reference](#configuration-reference).
|
||||||
|
|
||||||
|
1. After you complete the **Configure Keycloak Account** form, click **Authenticate with Keycloak**, which is at the bottom of the page.
|
||||||
|
|
||||||
|
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
||||||
|
|
||||||
|
>**Note:** You may have to disable your popup blocker to see the IdP login page.
|
||||||
|
|
||||||
|
**Result:** Rancher is configured to work with Keycloak. Your users can now sign into Rancher using their Keycloak logins.
|
||||||
|
|
||||||
|
{{< saml_caveats >}}
|
||||||
|
|
||||||
|
## Configuration Reference
|
||||||
|
|
||||||
| Field | Description |
|
| Field | Description |
|
||||||
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
@@ -79,24 +90,13 @@ If your organization uses Keycloak Identity Provider (IdP) for user authenticati
|
|||||||
>
|
>
|
||||||
> openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout myservice.key -out myservice.cert
|
> openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout myservice.key -out myservice.cert
|
||||||
|
|
||||||
|
|
||||||
1. After you complete the **Configure Keycloak Account** form, click **Authenticate with Keycloak**, which is at the bottom of the page.
|
|
||||||
|
|
||||||
Rancher redirects you to the IdP login page. Enter credentials that authenticate with Keycloak IdP to validate your Rancher Keycloak configuration.
|
|
||||||
|
|
||||||
>**Note:** You may have to disable your popup blocker to see the IdP login page.
|
|
||||||
|
|
||||||
**Result:** Rancher is configured to work with Keycloak. Your users can now sign into Rancher using their Keycloak logins.
|
|
||||||
|
|
||||||
{{< saml_caveats >}}
|
|
||||||
|
|
||||||
## Annex: Troubleshooting
|
## Annex: Troubleshooting
|
||||||
|
|
||||||
If you are experiencing issues while testing the connection to the Keycloak server, first double-check the configuration option of your SAML client. You may also inspect the Rancher logs to help pinpointing the problem cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging]({{<baseurl>}}/rancher/v2.6/en/faq/technical/#how-can-i-enable-debug-logging) in this documentation.
|
If you are experiencing issues while testing the connection to the Keycloak server, first double-check the configuration option of your SAML client. You may also inspect the Rancher logs to help pinpointing the problem cause. Debug logs may contain more detailed information about the error. Please refer to [How can I enable debug logging]({{<baseurl>}}/rancher/v2.6/en/faq/technical/#how-can-i-enable-debug-logging) in this documentation.
|
||||||
|
|
||||||
### You are not redirected to Keycloak
|
### You are not redirected to Keycloak
|
||||||
|
|
||||||
When you click on **Authenticate with Keycloak**, your are not redirected to your IdP.
|
When you click on **Authenticate with Keycloak**, you are not redirected to your IdP.
|
||||||
|
|
||||||
* Verify your Keycloak client configuration.
|
* Verify your Keycloak client configuration.
|
||||||
* Make sure `Force Post Binding` set to `OFF`.
|
* Make sure `Force Post Binding` set to `OFF`.
|
||||||
|
|||||||
Reference in New Issue
Block a user