> We do have ability to enforce OTPs on LDAP for all but specific services

Ah, I should have specified: I do have that set up for Keycloak itself, but I 
also would want to turn off OTP for users authenticating via Keycloak (and rely 
on its own OTP for users).

What I have settled on for now: sssd-idp + External IdP auth. This seems to 
work pretty well. Users run kinit and get a URL to login with Keycloak, which 
completes its own OTP. The caveat here are offline clients since the user is 
never prompted for a password that could be cached, but I have not actually 
tried this yet.

Now what I'm running into: I can set the "Default user authentication type" to 
External Identity Provider, but there doesn't seem to be a way to template or 
set a default External IdP configuration/External IdP user identifier for new 
users. If I leave user identifier blank, I would assume it would use the uid, 
but that does not seem to be the case. I also can't leave the IdP configuration 
line blank per user. Is there a way to set defaults for these?

Thanks,
Perry
-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to