On Sun, 26 Jul 2026, Perry Naseck via FreeIPA-users wrote:
We do have ability to enforce OTPs on LDAP for all but specific services

Ah, I should have specified: I do have that set up for Keycloak itself,
but I also would want to turn off OTP for users authenticating via
Keycloak (and rely on its own OTP for users).

What I have settled on for now: sssd-idp + External IdP auth. This
seems to work pretty well. Users run kinit and get a URL to login with
Keycloak, which completes its own OTP. The caveat here are offline
clients since the user is never prompted for a password that could be
cached, but I have not actually tried this yet.

Now what I'm running into: I can set the "Default user authentication
type" to External Identity Provider, but there doesn't seem to be a way
to template or set a default External IdP configuration/External IdP
user identifier for new users. If I leave user identifier blank, I
would assume it would use the uid, but that does not seem to be the
case. I also can't leave the IdP configuration line blank per user. Is
there a way to set defaults for these?

No, there is no templating. Configuration is explicit for each user.


--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland

--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to