如何通过Terraform Keycloak Provider设置Keycloak中SAML IDP的身份提供商实体ID
问题
在Keycloak 21.1.1版本中,尝试通过Terraform的keycloak_saml_identity_provider资源配置SAML IDP时,找不到用于设置颁发者验证的身份提供商实体ID的方法,且该字段在UI中无法填写。当前配置如下:
resource "keycloak_saml_identity_provider" "google_saml" { realm = keycloak_realm.realm.id alias = "test_google_saml" display_name = "TEST" entity_id = var.google_SAML_SP_entity_id single_sign_on_service_url = var.google_SAML_IDP_SSO_service_url trust_email = true sync_mode = "FORCE" name_id_policy_format = "Email" principal_type = "SUBJECT" post_binding_response = true post_binding_authn_request = true store_token = false force_authn = false validate_signature = false extra_config = { "allowCreate" : true "identityProviderEntityID" : var.google_SAML_IDP_entity_id } }
请问对应的参数或extraConfig键是什么?
解决方案
要配置颁发者验证的身份提供商实体ID,需在extraConfig中添加两个关键配置:
validateIssuer: 设置为true,开启颁发者验证功能issuer: 设置为你的身份提供商实体ID(即var.google_SAML_IDP_entity_id)
修改后的完整配置如下:
resource "keycloak_saml_identity_provider" "google_saml" { realm = keycloak_realm.realm.id alias = "test_google_saml" display_name = "TEST" entity_id = var.google_SAML_SP_entity_id single_sign_on_service_url = var.google_SAML_IDP_SSO_service_url trust_email = true sync_mode = "FORCE" name_id_policy_format = "Email" principal_type = "SUBJECT" post_binding_response = true post_binding_authn_request = true store_token = false force_authn = false validate_signature = false extra_config = { "allowCreate" = true "validateIssuer" = true "issuer" = var.google_SAML_IDP_entity_id } }
说明:
validateIssuer默认可能为false,需显式设为true才能触发颁发者验证逻辑issuer字段用于指定需要验证的IDP实体ID,Keycloak会用它来校验SAML响应中的颁发者值是否匹配
内容的提问来源于stack exchange,提问作者b.fiss
相关产品推荐
相关产品推荐

