Skip to content
Discussion options

You must be logged in to vote

Looks like if you configure LDAP User Storage Provider with "Import users"=OFF, then you get User IDs of the form: f:<Provider-Component-ID>:<LDAP-User-Identifier>, which can be stable across Keycloak rebuilds. This means you must trade off performance to get a stable User ID across rebuilds though.

In my use case Keycloak upgrades are built from scratch and configuration is simply scripted with admin CLI. This works great except for the changing UUID problem.

Surprised there is no way to pull in Red Hat Identity Manager (FreeIPA) ipaUniqueId field to be sub claim.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by slominskir
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant