Thanks for the quick response! That's very helpful (ending some rabbit holes of 
searches).

OK, so here's another idea: I can maybe use privacyIDEA for OTP. It looks like 
I could maybe have privacyIDEA feed into FreeIPA via RADIUS (and Keycloak has 
its own privacyIDEA plugin). From what I understand, if I set the login type to 
RADIUS then FreeIPA will use that for SSSD/kinit but NOT for LDAP. That means 
that Keycloak and privacyIDEA should be able to validate passwords without any 
OTP requirements from FreeIPA (and those services can LDAP bind without issue).

It does technically leave LDAP exposed without mandatory OTP (a user could use 
GSSAPI but it is not required), but maybe that's fine. It would be great if 
there was a way to allow system/service accounts only to authenticate to LDAP 
without GSSAPI.

Thanks,
Perry
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to