Thanks for the quick response! That's very helpful (ending some rabbit holes of searches).
OK, so here's another idea: I can maybe use privacyIDEA for OTP. It looks like I could maybe have privacyIDEA feed into FreeIPA via RADIUS (and Keycloak has its own privacyIDEA plugin). From what I understand, if I set the login type to RADIUS then FreeIPA will use that for SSSD/kinit but NOT for LDAP. That means that Keycloak and privacyIDEA should be able to validate passwords without any OTP requirements from FreeIPA (and those services can LDAP bind without issue). It does technically leave LDAP exposed without mandatory OTP (a user could use GSSAPI but it is not required), but maybe that's fine. It would be great if there was a way to allow system/service accounts only to authenticate to LDAP without GSSAPI. Thanks, Perry -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
