XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    OpenId Login via Keycloak

    Scheduled Pinned Locked Moved Xen Orchestra
    16 Posts 4 Posters 1.3k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mandrav @olivierlambert
      last edited by

      @olivierlambert yes, there was a user in XO with the same name from LDAP.
      I deleted both the un-named user and the existing LDAP user.
      I then tried to login again with OIDC and the user had no username again...

      1 Reply Last reply Reply Quote 0
      • olivierlambertO Offline
        olivierlambert Vates 🪐 Co-Founder CEO
        last edited by

        Okay try this:

        1. Login with the LDAP thing first. You should have the correct login name
        2. Login with the same creds with OIDC and check if you have a user name

        What's weird: I tested on 2 XOAs here (lab and prob) and it worked well, I still got my username, so I'm not sure to get what's going on 🤔

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          mandrav @olivierlambert
          last edited by

          @olivierlambert said in OpenId Login via Keycloak:

          Okay try this:

          1. Login with the LDAP thing first. You should have the correct login name
          2. Login with the same creds with OIDC and check if you have a user name

          What's weird: I tested on 2 XOAs here (lab and prob) and it worked well, I still got my username, so I'm not sure to get what's going on 🤔

          Well, that's what I was doing at first and ended up with a correct LDAP user and an un-named OIDC user 🙂 .
          If it helps, Authelia reads its users from LDAP so no matter if use LDAP or OIDC, the final user being used is the same.

          1 Reply Last reply Reply Quote 0
          • olivierlambertO Offline
            olivierlambert Vates 🪐 Co-Founder CEO
            last edited by

            Is this unnamed user is the same as the "named" one or a completely different one?

            M 1 Reply Last reply Reply Quote 0
            • M Offline
              mandrav @olivierlambert
              last edited by

              @olivierlambert the same user

              1 Reply Last reply Reply Quote 0
              • olivierlambertO Offline
                olivierlambert Vates 🪐 Co-Founder CEO
                last edited by

                Okay so hopefully it's a display issue or something. Let me ping @julien-f about this 🙂

                M 1 Reply Last reply Reply Quote 0
                • M Offline
                  mandrav @olivierlambert
                  last edited by

                  @olivierlambert well, thanks for taking the time to look into this 🙂

                  It's not a show-stopper for me because I can still log into XO but it 'd be nice to use the nice features of OIDC like single sign-on etc.

                  julien-fJ 1 Reply Last reply Reply Quote 0
                  • olivierlambertO Offline
                    olivierlambert Vates 🪐 Co-Founder CEO
                    last edited by

                    Yes, maybe it's just a cosmetic issue without any other impact, but worth checking 🙂

                    1 Reply Last reply Reply Quote 0
                    • julien-fJ Offline
                      julien-f Vates 🪐 Co-Founder XO Team @mandrav
                      last edited by

                      @mandrav I've just pushed a fix to prevent XO from creating users with an empty name.

                      Most likely your problem is that the plugin does not work with the setting username field set to email.

                      Please test the branch fix-oidc-email for a fix. Re-signing in the problematic user (if it has been created via OpenId Connect signin and has not been linked to another auth provider) should update the user name.

                      julien-fJ 1 Reply Last reply Reply Quote 1
                      • julien-fJ Offline
                        julien-f Vates 🪐 Co-Founder XO Team @julien-f
                        last edited by

                        @prononext @mandrav The problem of empty username has been fixed in master.

                        The support of email for username field is currently in review in the PR linked in my previous message and will be available soon 🙂

                        Thanks for your help!

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post