sbose/sssd-idp

Project ID: 136413

Description

This repository contains the current state of the development of the direct integration of SSSD with an external IdP. Currently Keycloak and Entra ID are supported.

You can find a short video with a demo at https://sbose.fedorapeople.org/sssd-idp-demo/sssd-idp-demo.mp4.

The code is based on the git trees:

Feel free to leave comments, questions and suggestions on github.

Installation Instructions

After installing the packages form this repository, especially the sssd-idp package, create a sssd.conf file like e.g.:

[sssd] config_file_version = 2 services = nss, pam domains = YOU.onmicrosoft.com, keycloak [domain/YOU.onmicrosoft.com] id_provider = idp auto_private_groups = true use_fully_qualified_names = true debug_level = 9 idp_client_id = UUID_of_YOUR_Entra_ID_client idp_client_id = Password_of_YOUR_Entra_ID_client idp_token_endpoint = https://login.microsoftonline.com/YOUR_Entra_ID_tennant_UUID/oauth2/v2.0/token idp_device_auth_endpoint = https://login.microsoftonline.com/YOUR_Entra_ID_tennant_UUID/oauth2/v2.0/devicecode idp_userinfo_endpoint = https://graph.microsoft.com/v1.0/me idp_id_scope = https%3A%2F%2Fgraph.microsoft.com%2F.default idp_auth_scope = openid profile email [domain/keycloak] idp_type = keycloak:https://master.keycloak.test:8443/auth/admin/realms/master/ id_provider = idp auto_private_groups = true use_fully_qualified_names = true debug_level = 9 idp_client_id = YourKeycloakClient idp_client_secret = YourKeycloakClientPassword idp_token_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/token idp_userinfo_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/userinfo idp_device_auth_endpoint = https://master.keycloak.test:8443/auth/realms/master/protocol/openid-connect/auth/device idp_id_scope = profile idp_auth_scope = openid profile email [nss] debug_level = 9 default_shell = /bin/bash fallback_homedir = /home/%f

Please note that the IdP clients must have the permission to read user and group attributes.

Active Releases

The following unofficial repositories are provided as-is by owner of this project. Contact the owner directly for bugs or issues (IE: not bugzilla).

Release Architectures Repo Download
Centos-stream 10 x86_64 (562)* Centos-stream 10 (11 downloads)
Centos-stream 8 x86_64 (9)* Centos-stream 8 (11 downloads)
Centos-stream 9 x86_64 (585)* Centos-stream 9 (9 downloads)
EPEL 8 x86_64 (9)* EPEL 8 (10 downloads)
EPEL 9 x86_64 (639)* EPEL 9 (20 downloads)
Fedora 39 aarch64 (550)*, s390x (549)*, x86_64 (549)* Fedora 39 (10 downloads)
Fedora 40 aarch64 (549)*, ppc64le (552)*, s390x (549)*, x86_64 (739)* Fedora 40 (21 downloads)
Fedora 41 aarch64 (0)*, ppc64le (0)*, s390x (0)*, x86_64 (0)* Fedora 41 (3 downloads)
Fedora eln x86_64 (9)* Fedora eln (10 downloads)
Fedora rawhide aarch64 (561)*, ppc64le (559)*, s390x (580)*, x86_64 (637)* Fedora rawhide (16 downloads)

* Total number of downloaded packages.