Administration
Single sign-on
Keycloak
5min
- In the Keycloak admin console, head to Clients and click Create
- Select SAML as Client Protocol and complete the ClientID and Client SAML Endpoint with the Echoes SP information that can be found on the configuration page.
- Click Save.
data:image/s3,"s3://crabby-images/3d29a/3d29ada8c218fb741798d9625d2257f31d4086d6" alt="Create SAML client Create SAML client"
Create SAML client
You will then be redirected to the Keycloak configuration page of the client for further configuration.
On this page, you should have the following configuration
- Client Signature Required should be turned OFF
- Sign Documents & Sign Assertions should be turned ON
data:image/s3,"s3://crabby-images/3e2e6/3e2e6cb1718e9df4ae94f40ff115a0c4a5f2be22" alt="SAML client full configuration SAML client full configuration"
SAML client full configuration
In the Mappers section, configure the SAML attributes mapping required by Echoes.
data:image/s3,"s3://crabby-images/9efeb/9efeb7bf86d14d57baa97428df28606a8289bcff" alt="Attributes mapping Attributes mapping"
Attributes mapping
All attribute's NameFormat should be Basic.
data:image/s3,"s3://crabby-images/6181c/6181c4ab1f3ceaae48181d8e136cbdb93385bcf6" alt="Email attribute Email attribute"
Email attribute
data:image/s3,"s3://crabby-images/0c17d/0c17db620e575e018beede4929f67a9b86b75c44" alt="LastName attribute LastName attribute"
LastName attribute
data:image/s3,"s3://crabby-images/13575/135757475ccdf8e9eb2ebe7f9da5c468d5edea14" alt="Firstname attribute Firstname attribute"
Firstname attribute
Should have the form of: https://<your-keycloak-domain>/auth/realms/<your-realm>/protocol/saml
Can be found in the Keycloak realm's Keys -> Certificate.
Updated 03 Mar 2023
Did this page help you?