Hi,

I have FreeIPA + Keycloak set up in Podman on one machine. Because they are in 
Podman, I connected Keycloak to FreeIPA via LDAP + Kerberos instead of SSSD. 
Keycloak has a service account in FreeIPA to do this.

Is there a way to enforce Keycloak's LDAP/Kerberos authentication checks to use 
password only and not password + OTP? Can the user authentication types be 
configured per-service account or otherwise? I still want password + OTP when a 
user uses kinit or SSH's into a server. Keycloak's own OTP system makes more 
sense for users primarily using web applications, so I want to keep those parts 
separate.

Thanks!
Perry
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to