blob: c1e354902af68318e664250c958962085a8fec72 [file] [log] [blame]
Martin Polreich05c816b2019-01-24 10:48:03 +01001keycloak:
2 server:
3 enabled: true
4 realm:
5 ldap-realm:
6 enabled: true
7 id: ldap-realm
8 client:
9 ldap-app:
10 enabled: true
11 base_url: /ldap-portal
12 redirect_uris:
13 - /ldap-portal/*
14 web_origins:
15 - "*"
16 public_client: false
17 admin_url: /ldap-portal
18 secret: password
19 protocol_mapper:
20 oidc-usermodel-property-mapper:
21 username:
22 name: username
23 user_attribute: username
24 claim_name: preferred_username
25 given_name:
26 name: given name
27 user_attribute: firstName
28 claim_name: given_name
29 family_name:
30 name: family name
31 user_attribute: lastName
32 claim_name: family_name
33 email:
34 name: email
35 user_attribute: email
36 claim_name: email
37 oidc-full-name-mapper:
38 full_name:
39 name: full_name
40 federation_provider:
41 ldap:
42 display_name: ldap-server
43 users_dn: ou=people,dc=keycloak,dc=org
44 user_object_classes: inetOrgPerson, organizationalPerson
45 username_ldap_attribute: uid
46 bind_dn: cn=admin,dc=keycloak,dc=org
47 bind_credential: password
48 rdn_ldap_attribute: uid
49 edit_mode: READ_ONLY
50 uuid_ldap_attribute: entryUUID
51 connection_url: ldap://localhost:10389
52 sync_registrations: false
53 federation_mapper:
54 user-attribute-ldap-mapper:
55 username:
56 name: username
57 provider_display_name: ldap-server
58 ldap_attribute: uid
59 model_attribute: username
60 mandatory: true
61 read_only: false
62 always_read: false
63 first_name:
64 name: first name
65 provider_display_name: ldap-server
66 ldap_attribute: cn
67 model_attribute: firstName
68 mandatory: true
69 read_only: false
70 always_read: false
71 last_name:
72 name: last name
73 provider_display_name: ldap-server
74 ldap_attribute: sn
75 model_attribute: lastName
76 mandatory: true
77 read_only: false
78 always_read: false
79 email:
80 name: email
81 provider_display_name: ldap-server
82 ldap_attribute: mail
83 model_attribute: email
84 mandatory: false
85 read_only: false
86 always_read: false
87 role-ldap-mapper:
88 realm_roles:
89 name: realm roles
90 provider_display_name: ldap-server
91 roles_dn: ou=groups,dc=cicd,dc=local
92 membership_ldap_attribute: member
93 role_name_ldap_attribute: cn
94 role_object_classes: groupOfNames
95 mode: LDAP_ONLY
96 realm_roles_mapping: true