Investigate migration from Ipsilon to Keycloak #13188

Open
opened 2026-03-09 14:51:28 +00:00 by abompard · 1 comment
Member

Description of request

This ticket will be used to track our migration efforts from Ipsilon as the OIDC and SAML2 identity provider to something else, most likely Keycloak, maybe with IPA-tuura.

### Description of request This ticket will be used to track our migration efforts from Ipsilon as the OIDC and SAML2 identity provider to something else, most likely Keycloak, maybe with IPA-tuura.
Author
Member

I had a call with the IPA-tuura team on 2026-03-02. Right now the main thing we need is attribute mapping (from IPA to the OIDC profile). It's not supported by IPA-tuura's Keycloak plugin yet, but it is supported by the LDAP plugin so it should not be too hard to port.
Things we still need to check:

  • check that groups are properly propagated from IPA-tuura to keycloak, they expected the groups to be managed in Keycloak and not IPA.
  • check that IPA-tuura works with SAML2
  • check GSSAPI auth support
  • check performance, we have way more users than what they're used to
I had a call with the IPA-tuura team on 2026-03-02. Right now the main thing we need is attribute mapping (from IPA to the OIDC profile). It's not supported by IPA-tuura's Keycloak plugin yet, but it is supported by the LDAP plugin so it should not be too hard to port. Things we still need to check: - check that groups are properly propagated from IPA-tuura to keycloak, they expected the groups to be managed in Keycloak and not IPA. - check that IPA-tuura works with SAML2 - check GSSAPI auth support - check performance, we have way more users than what they're used to
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13188
No description provided.