Keycloak SSO integration

Hello, I've successfully added my AD LDAP service in Keycloak. My connection works and I am able to search for users from Keycloak. How do I map an LDAP group 'adminusers' into the Ovirt web interface and map it to the internal administration group? I just seem to see the ovirt-internal Keycloak authentication source in the base of my Ovirt URL. Thank You!

People must not be using Keycloak (Redhat SSO). Anyone have experience integrating LDAP users in Ovirt? The documentation on the Ovirt site is very scant on the subject. For the moment I'm only able to use admin@ovirt.

Le samedi 06 avril 2024 à 11:34 +0000, luc.lalonde@polymtl.ca<mailto:luc.lalonde@polymtl.ca> a écrit : People must not be using Keycloak (Redhat SSO). Anyone have experience integrating LDAP users in Ovirt? sure, please install the ovirt-engine-extension-aaa-ldap-setup-1.4.6-1.el9.noarch and execute ovirt-engine-extension-aaa-ldap-setup. If you already used to authenticate with aaa on el8 engine, you can simply rsync these directories to the new el9 engine: rsync -av /etc/ovirt-engine/extensions.d/<profile>-auth* new_engine_fqdn:/etc/ovirt-engine/extensions.d/ rsync -av /etc/ovirt-engine/aaa/<profile>.properties new_engine_fqdn:/etc/ovirt-engine/aaa/ The documentation on the Ovirt site is very scant on the subject. For the moment I'm only able to use admin@ovirt<mailto:admin@ovirt>. _______________________________________________ Users mailing list -- users@ovirt.org<mailto:users@ovirt.org> To unsubscribe send an email to users-leave@ovirt.org<mailto:users-leave@ovirt.org> Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/RBS664Q6VQB7IR... -- Nathanaël Blanchet Administrateur Systèmes et Réseaux Service Informatique et REseau (SIRE) Département des systèmes d'information 227 avenue Professeur-Jean-Louis-Viala 34193 MONTPELLIER CEDEX 5 Tél. 33 (0)4 67 54 84 55 Fax 33 (0)4 67 54 84 14 blanchet@abes.fr

Unfortunately, I chose the 'Keycloak' option during the setup instead. So using using ovirt-engine-extension-aaa-ldap-setup is not an option. In the documentation, they say that 'ovirt-engine-extension-aaa-ldap-setup' is being deprecated... I regret not using it anyway. Documentation is missing on how to configure Keycloak (RedHat SSO). Thank You.

While I haven't configured it myself (someone else in my Team did the integration and we are using another Keycloak instance, not LDAP) and therefore don't know all details, I think you should be able to configure another IdP in the Keycloak administration interface (https://<OVIRT_ENGINE>/ovirt-engine-auth/admin). LDAP should be available under "User Federation". On 06.04.24 14:23, luc.lalonde@polymtl.ca wrote:
Unfortunately, I chose the 'Keycloak' option during the setup instead. So using using ovirt-engine-extension-aaa-ldap-setup is not an option.
In the documentation, they say that 'ovirt-engine-extension-aaa-ldap-setup' is being deprecated... I regret not using it anyway. Documentation is missing on how to configure Keycloak (RedHat SSO).
Thank You. _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/5XU43ZJ3Y2F3NR...

I followed the instructions in this guide: https://blogs.ovirt.org/2019/01/federate-ovirt-engine-authentication-to-open... I can see the users and groups imported in Keycloak... But the Apache configuration cause errors. There are references to manually disable Keycloak and go back to ovirt-engine-extension-aaa-ldap-setup manually. Anyone have instructions on how to do this? The only link that I could find was paywalled on Oracle's support site.

Unfortunately, Keycloak is not fully integrated into oVirt, other than the main authentication will not work. Scripts from the ovirt-sdk4, virt-v2v commands, API access, and others still rely on the AAA authentication mechanism. Marcos -----Original Message----- From: luc.lalonde@polymtl.ca <luc.lalonde@polymtl.ca> Sent: Saturday, April 6, 2024 9:23 AM To: users@ovirt.org Subject: [External] : [ovirt-users] Re: Keycloak SSO integration Unfortunately, I chose the 'Keycloak' option during the setup instead. So using using ovirt-engine-extension-aaa-ldap-setup is not an option. In the documentation, they say that 'ovirt-engine-extension-aaa-ldap-setup' is being deprecated... I regret not using it anyway. Documentation is missing on how to configure Keycloak (RedHat SSO). Thank You. _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://urldefense.com/v3/__https://www.ovirt.org/privacy-policy.html__;!!AC... oVirt Code of Conduct: https://urldefense.com/v3/__https://www.ovirt.org/community/about/community-... List Archives: https://urldefense.com/v3/__https://lists.ovirt.org/archives/list/users@ovir...

You can try this https://blogs.ovirt.org/wp-content/uploads/2021/09/04-Prerequisites-and-Trou... Marcos -----Original Message----- From: luc.lalonde@polymtl.ca <luc.lalonde@polymtl.ca> Sent: Saturday, April 6, 2024 8:34 AM To: users@ovirt.org Subject: [External] : [ovirt-users] Re: Keycloak SSO integration People must not be using Keycloak (Redhat SSO). Anyone have experience integrating LDAP users in Ovirt? The documentation on the Ovirt site is very scant on the subject. For the moment I'm only able to use admin@ovirt. _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://urldefense.com/v3/__https://www.ovirt.org/privacy-policy.html__;!!AC... oVirt Code of Conduct: https://urldefense.com/v3/__https://www.ovirt.org/community/about/community-... List Archives: https://urldefense.com/v3/__https://lists.ovirt.org/archives/list/users@ovir...
participants (4)
-
Jonas
-
luc.lalonde@polymtl.ca
-
Marcos Sungaila
-
Nathanaël Blanchet