> We do have ability to enforce OTPs on LDAP for all but specific services
Ah, I should have specified: I do have that set up for Keycloak itself, but I also would want to turn off OTP for users authenticating via Keycloak (and rely on its own OTP for users). What I have settled on for now: sssd-idp + External IdP auth. This seems to work pretty well. Users run kinit and get a URL to login with Keycloak, which completes its own OTP. The caveat here are offline clients since the user is never prompted for a password that could be cached, but I have not actually tried this yet. Now what I'm running into: I can set the "Default user authentication type" to External Identity Provider, but there doesn't seem to be a way to template or set a default External IdP configuration/External IdP user identifier for new users. If I leave user identifier blank, I would assume it would use the uid, but that does not seem to be the case. I also can't leave the IdP configuration line blank per user. Is there a way to set defaults for these? Thanks, Perry -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
