blob: 2601089bd3ea7dfc2104b9b23b60971428a6b7d4 [file] [log] [blame]
Martin Polreich05c816b2019-01-24 10:48:03 +01001keycloak:
2 server:
3 enabled: true
4 realm:
5 ldap-realm:
6 enabled: true
7 id: ldap-realm
Ekaterina Chernovac5e52752019-05-15 16:02:25 +03008 additional_params:
9 registrationAllowed: false
10 registrationEmailAsUsername: false
11 resetPasswordAllowed: false
12 accessTokenLifespan: 60
13 ssoSessionIdleTimeout: 600
Martin Polreich05c816b2019-01-24 10:48:03 +010014 client:
15 ldap-app:
16 enabled: true
17 base_url: /ldap-portal
18 redirect_uris:
19 - /ldap-portal/*
20 web_origins:
21 - "*"
22 public_client: false
23 admin_url: /ldap-portal
24 secret: password
25 protocol_mapper:
26 oidc-usermodel-property-mapper:
27 username:
28 name: username
29 user_attribute: username
30 claim_name: preferred_username
31 given_name:
32 name: given name
33 user_attribute: firstName
34 claim_name: given_name
35 family_name:
36 name: family name
37 user_attribute: lastName
38 claim_name: family_name
39 email:
40 name: email
41 user_attribute: email
42 claim_name: email
43 oidc-full-name-mapper:
44 full_name:
45 name: full_name
46 federation_provider:
47 ldap:
48 display_name: ldap-server
49 users_dn: ou=people,dc=keycloak,dc=org
50 user_object_classes: inetOrgPerson, organizationalPerson
51 username_ldap_attribute: uid
52 bind_dn: cn=admin,dc=keycloak,dc=org
53 bind_credential: password
54 rdn_ldap_attribute: uid
55 edit_mode: READ_ONLY
56 uuid_ldap_attribute: entryUUID
57 connection_url: ldap://localhost:10389
58 sync_registrations: false
59 federation_mapper:
60 user-attribute-ldap-mapper:
61 username:
62 name: username
63 provider_display_name: ldap-server
64 ldap_attribute: uid
65 model_attribute: username
66 mandatory: true
67 read_only: false
68 always_read: false
69 first_name:
70 name: first name
71 provider_display_name: ldap-server
72 ldap_attribute: cn
73 model_attribute: firstName
74 mandatory: true
75 read_only: false
76 always_read: false
77 last_name:
78 name: last name
79 provider_display_name: ldap-server
80 ldap_attribute: sn
81 model_attribute: lastName
82 mandatory: true
83 read_only: false
84 always_read: false
85 email:
86 name: email
87 provider_display_name: ldap-server
88 ldap_attribute: mail
89 model_attribute: email
90 mandatory: false
91 read_only: false
92 always_read: false
93 role-ldap-mapper:
94 realm_roles:
95 name: realm roles
96 provider_display_name: ldap-server
97 roles_dn: ou=groups,dc=cicd,dc=local
98 membership_ldap_attribute: member
99 role_name_ldap_attribute: cn
100 role_object_classes: groupOfNames
101 mode: LDAP_ONLY
102 realm_roles_mapping: true