{"id":891,"date":"2022-12-23T10:22:56","date_gmt":"2022-12-23T09:22:56","guid":{"rendered":"https:\/\/www.ume.li\/blog\/?p=891"},"modified":"2022-12-23T10:22:56","modified_gmt":"2022-12-23T09:22:56","slug":"keycloak-and-kerberos","status":"publish","type":"post","link":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/","title":{"rendered":"Keycloak and Kerberos"},"content":{"rendered":"<p>Goal:<br \/>\nLogin to your Windows Client and do not have to login to Connections<\/p>\n<p>My setup for this:<br \/>\n&#8211; Windows 2019 Server &#8211; AD for the domain &#8216;belsoft-lab.ch&#8217; &#8211; fresh install<br \/>\n&#8211; Windows 10 Client &#8211; Testing &#8211; already domain joined to &#8216;belsoft-lab.ch&#8217;<br \/>\n&#8211; Rocky Linux 8 &#8211; Keycloak 20.0.2 &#8211; already up and connected to AD through LDAP &#8211; url: login.belsoft-lab.ch \/ hostname login1.belsoft-lab.ch<br \/>\n&#8211; HCL Connections 8 already configured for OIDC against Keycloak (<a title=\"Configure OIDC\" href=\"https:\/\/opensource.hcltechsw.com\/connections-doc\/admin\/secure\/c_azure_oidc_container.html\" target=\"_blank\" rel=\"noopener\">configure OIDC in HCL Connections<\/a><\/p>\n<p>Motivation:<br \/>\nSure you can configure SPNEGO directly in WebSphere. But you might want to support OTP\/WebAuthn for external users which are not in your AD?<\/p>\n<p>Based on <a title=\"Keycloak Documentation\" href=\"https:\/\/www.keycloak.org\/docs\/latest\/server_admin\/index.html#_kerberos\" target=\"_blank\" rel=\"noopener\">keycloak documentation<\/a><\/p>\n<p><strong>Prepare the Keytab file<\/strong><br \/>\nCreate a user for the service account. For this example I use kk@belsoft-lab.ch. And add all the possible URL&#8217;s<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nktpass -out c:\\temp\\keycloak.keytab -princ HTTP\/login.belsoft-lab.ch@BELSOFT-LAB.CH -mapUser kk@belsoft-lab.ch  -kvno 0 -ptype KRB5_NT_PRINCIPAL -crypto AES256-SHA1 -pass *****\r\nsetspn -S HTTP\/login1.belsoft-lab.ch@BELSOFT-LAB.CH belsoft-lab\\kk\r\nsetspn -S HTTP\/login1.belsoft-lab.ch belsoft-lab\\kk\r\nsetspn -S HTTP\/login.belsoft-lab.ch belsoft-lab\\kk\r\nsetspn -l kk\r\n<\/pre>\n<p>The &#8216;setspn -l kk&#8217; displays the successfull registration and I&#8217;ve got the keycloak.keytab file in c:\\temp which I then have to copy to my keycloak server(s).<br \/>\n<a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_588\/\" rel=\"attachment wp-att-895\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-895\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_588-300x46.png\" alt=\"\" width=\"300\" height=\"46\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_588-300x46.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_588.png 717w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Prepare Keycloak<\/strong><\/p>\n<p>As I&#8217;ve already configured ldap against my AD server, I just need to activate Kerberos in the user federation.<br \/>\n<a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_589\/\" rel=\"attachment wp-att-896\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-896\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_589-300x177.png\" alt=\"\" width=\"300\" height=\"177\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_589-300x177.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_589-768x452.png 768w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_589-850x500.png 850w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_589.png 985w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Verify that the default authentication flow has set Kerberos to Alternative<br \/>\n<a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_590\/\" rel=\"attachment wp-att-897\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-897\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_590-300x155.png\" alt=\"\" width=\"300\" height=\"155\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_590-300x155.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_590-1024x530.png 1024w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_590-768x397.png 768w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_590.png 1210w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\ndnf install freeipa-client\r\n<\/pre>\n<p>Update the \/etc\/krb5.conf file on the keycloak server with my domain<br \/>\n<a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_591\/\" rel=\"attachment wp-att-898\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-898\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_591-300x123.png\" alt=\"\" width=\"300\" height=\"123\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_591-300x123.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_591.png 318w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Testing<\/strong><\/p>\n<p>And of course it did not work. I just got the default login window when I tried to go to keycloak&#8217;s account page.<\/p>\n<p><strong>Troubleshooting<\/strong><\/p>\n<p>Turning on the debug parameters in keycloak. For this I added this environment variable<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nJAVA_OPTS_APPEND=&quot;-Dsun.security.krb5.debug=true -Dsun.security.spnego.debug=true&quot;\r\n<\/pre>\n<p>and added these to my keycloak.conf file<\/p>\n<pre class=\"brush: plain; title: ; notranslate\" title=\"\">\r\nlog=file\r\nlog-file=\/opt\/keycloak\/log\/keycloak.log\r\nlog-level=info,org.keycloak.federation.kerberos:trace\r\n<\/pre>\n<p>the log file then showed this message:<br \/>\n<a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_592\/\" rel=\"attachment wp-att-900\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-900\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_592-300x61.png\" alt=\"\" width=\"300\" height=\"61\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_592-300x61.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_592-768x157.png 768w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_592.png 1020w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><em>java.security.PrivilegedActionException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Encryption type RC4 with HMAC is not supported\/enabled<\/em><br \/>\nwhich led me to this <a href=\"https:\/\/bugs.openjdk.org\/browse\/JDK-8262273\" target=\"_blank\" rel=\"noopener\">RC4 deprecated<\/a>. Further research led to numerous posts which proposed obscure tipps.<\/p>\n<p><strong>Solution<\/strong><\/p>\n<p>In the test users account I had to tick &#8216;this account supports Kerberos AES 256 bit&#8217;<\/p>\n<p><a href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/selection_593\/\" rel=\"attachment wp-att-901\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-901\" src=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_593-300x156.png\" alt=\"\" width=\"300\" height=\"156\" srcset=\"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_593-300x156.png 300w, https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_593.png 395w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Relogin to my test client. Finally managed to access the account console without entering username or password.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Goal: Login to your Windows Client and do not have to login to Connections My setup for this: &#8211; Windows<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,1],"tags":[85,84,83,82,86],"class_list":["post-891","post","type-post","status-publish","format-standard","hentry","category-connections","category-uncategorized","tag-active-directory","tag-ad","tag-kerberos","tag-keycloak","tag-windows"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain &#039;belsoft-lab.ch&#039; - fresh install - Windows 10 Client - Testing - already domain joined to &#039;belsoft-lab.ch&#039; - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"umeli\"\/>\n\t<meta name=\"keywords\" content=\"active-directory,ad,kerberos,keycloak,windows,connections,uncategorized\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Urs Meli&#039;s Blog\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Keycloak and Kerberos | Urs Meli&#039;s Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain &#039;belsoft-lab.ch&#039; - fresh install - Windows 10 Client - Testing - already domain joined to &#039;belsoft-lab.ch&#039; - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-23T09:22:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-23T09:22:56+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@umeli\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Keycloak and Kerberos | Urs Meli&#039;s Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain &#039;belsoft-lab.ch&#039; - fresh install - Windows 10 Client - Testing - already domain joined to &#039;belsoft-lab.ch&#039; - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@umeli\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#article\",\"name\":\"Keycloak and Kerberos | Urs Meli's Blog\",\"headline\":\"Keycloak and Kerberos\",\"author\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/author\\\/umeli\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Selection_588.png\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#articleImage\",\"width\":717,\"height\":110},\"datePublished\":\"2022-12-23T10:22:56+01:00\",\"dateModified\":\"2022-12-23T10:22:56+01:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#webpage\"},\"articleSection\":\"Connections, Uncategorized, active-directory, ad, kerberos, keycloak, windows\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#listItem\",\"name\":\"Keycloak and Kerberos\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#listItem\",\"position\":3,\"name\":\"Keycloak and Kerberos\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#person\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bba650dede6888bd44d79e656db7b6564b4a7e7ba51445cc1c062dd769729e59?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"admin\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/author\\\/umeli\\\/#author\",\"url\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/author\\\/umeli\\\/\",\"name\":\"umeli\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b722f3e7e78b4f1e2b994856370dd7327963f636c5b50078baa80c2c4e411165?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"umeli\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#webpage\",\"url\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/\",\"name\":\"Keycloak and Kerberos | Urs Meli's Blog\",\"description\":\"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain 'belsoft-lab.ch' - fresh install - Windows 10 Client - Testing - already domain joined to 'belsoft-lab.ch' - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/2022\\\/12\\\/23\\\/keycloak-and-kerberos\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/author\\\/umeli\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/author\\\/umeli\\\/#author\"},\"datePublished\":\"2022-12-23T10:22:56+01:00\",\"dateModified\":\"2022-12-23T10:22:56+01:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/\",\"name\":\"Urs Meli's Blog\",\"description\":\"Mostly harmless\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ume.li\\\/blog\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Keycloak and Kerberos | Urs Meli's Blog","description":"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain 'belsoft-lab.ch' - fresh install - Windows 10 Client - Testing - already domain joined to 'belsoft-lab.ch' - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected","canonical_url":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/","robots":"max-image-preview:large","keywords":"active-directory,ad,kerberos,keycloak,windows,connections,uncategorized","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#article","name":"Keycloak and Kerberos | Urs Meli's Blog","headline":"Keycloak and Kerberos","author":{"@id":"https:\/\/www.ume.li\/blog\/author\/umeli\/#author"},"publisher":{"@id":"https:\/\/www.ume.li\/blog\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/www.ume.li\/blog\/wp-content\/uploads\/2022\/12\/Selection_588.png","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#articleImage","width":717,"height":110},"datePublished":"2022-12-23T10:22:56+01:00","dateModified":"2022-12-23T10:22:56+01:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#webpage"},"isPartOf":{"@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#webpage"},"articleSection":"Connections, Uncategorized, active-directory, ad, kerberos, keycloak, windows"},{"@type":"BreadcrumbList","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/#listItem","position":1,"name":"Home","item":"https:\/\/www.ume.li\/blog\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/www.ume.li\/blog\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#listItem","name":"Keycloak and Kerberos"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#listItem","position":3,"name":"Keycloak and Kerberos","previousItem":{"@type":"ListItem","@id":"https:\/\/www.ume.li\/blog\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Person","@id":"https:\/\/www.ume.li\/blog\/#person","name":"admin","image":{"@type":"ImageObject","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/bba650dede6888bd44d79e656db7b6564b4a7e7ba51445cc1c062dd769729e59?s=96&d=mm&r=g","width":96,"height":96,"caption":"admin"}},{"@type":"Person","@id":"https:\/\/www.ume.li\/blog\/author\/umeli\/#author","url":"https:\/\/www.ume.li\/blog\/author\/umeli\/","name":"umeli","image":{"@type":"ImageObject","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/b722f3e7e78b4f1e2b994856370dd7327963f636c5b50078baa80c2c4e411165?s=96&d=mm&r=g","width":96,"height":96,"caption":"umeli"}},{"@type":"WebPage","@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#webpage","url":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/","name":"Keycloak and Kerberos | Urs Meli's Blog","description":"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain 'belsoft-lab.ch' - fresh install - Windows 10 Client - Testing - already domain joined to 'belsoft-lab.ch' - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.ume.li\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/#breadcrumblist"},"author":{"@id":"https:\/\/www.ume.li\/blog\/author\/umeli\/#author"},"creator":{"@id":"https:\/\/www.ume.li\/blog\/author\/umeli\/#author"},"datePublished":"2022-12-23T10:22:56+01:00","dateModified":"2022-12-23T10:22:56+01:00"},{"@type":"WebSite","@id":"https:\/\/www.ume.li\/blog\/#website","url":"https:\/\/www.ume.li\/blog\/","name":"Urs Meli's Blog","description":"Mostly harmless","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.ume.li\/blog\/#person"}}]},"og:locale":"en_US","og:site_name":"Urs Meli's Blog","og:type":"article","og:title":"Keycloak and Kerberos | Urs Meli's Blog","og:description":"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain 'belsoft-lab.ch' - fresh install - Windows 10 Client - Testing - already domain joined to 'belsoft-lab.ch' - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected","og:url":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/","article:published_time":"2022-12-23T09:22:56+00:00","article:modified_time":"2022-12-23T09:22:56+00:00","twitter:card":"summary","twitter:site":"@umeli","twitter:title":"Keycloak and Kerberos | Urs Meli's Blog","twitter:description":"Goal: Login to your Windows Client and do not have to login to Connections My setup for this: - Windows 2019 Server - AD for the domain 'belsoft-lab.ch' - fresh install - Windows 10 Client - Testing - already domain joined to 'belsoft-lab.ch' - Rocky Linux 8 - Keycloak 20.0.2 - already up and connected","twitter:creator":"@umeli"},"aioseo_meta_data":{"post_id":"891","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","location":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2022-12-23 08:11:57","updated":"2025-07-09 09:54:36","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.ume.li\/blog\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.ume.li\/blog\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tKeycloak and Kerberos\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.ume.li\/blog\/"},{"label":"Uncategorized","link":"https:\/\/www.ume.li\/blog\/category\/uncategorized\/"},{"label":"Keycloak and Kerberos","link":"https:\/\/www.ume.li\/blog\/2022\/12\/23\/keycloak-and-kerberos\/"}],"_links":{"self":[{"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/posts\/891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/comments?post=891"}],"version-history":[{"count":7,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/posts\/891\/revisions"}],"predecessor-version":[{"id":904,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/posts\/891\/revisions\/904"}],"wp:attachment":[{"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/media?parent=891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/categories?post=891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ume.li\/blog\/wp-json\/wp\/v2\/tags?post=891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}