On Fri, 24 Jul 2026, Perry Naseck via FreeIPA-users wrote:
Thanks for the quick response! That's very helpful (ending some rabbit holes of
searches).
OK, so here's another idea: I can maybe use privacyIDEA for OTP. It
looks like I could maybe have privacyIDEA feed into FreeIPA via RADIUS
(and Keycloak has its own privacyIDEA plugin). From what I understand,
if I set the login type to RADIUS then FreeIPA will use that for
SSSD/kinit but NOT for LDAP. That means that Keycloak and privacyIDEA
should be able to validate passwords without any OTP requirements from
FreeIPA (and those services can LDAP bind without issue).
It does technically leave LDAP exposed without mandatory OTP (a user
could use GSSAPI but it is not required), but maybe that's fine. It
would be great if there was a way to allow system/service accounts only
to authenticate to LDAP without GSSAPI.
We do have ability to enforce OTPs on LDAP for all but specific services
that perform bind validation. See
https://freeipa.readthedocs.io/en/latest/designs/sysaccounts.html for
details.
--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new