---
title: "EasySSO SAML with Keycloak"
canonical: "https://www.techtime-initiative.com/space/EasySSO/5341244/EasySSO%20SAML%20with%20Keycloak"
format: markdown
---
Configuration of EasySSO with signed POST requests, using Keycloak version 19 as an Identity Provider (IdP)

> Macro (toc)

## Configure the EasySSO side

Fill in the IdP Metadata URL, and then click `Load Certificate`.

![image-20240829-015756.png](media://27dbabcc-0f8d-4ff2-b37f-8509384fbfc8)

Click `Regenerate Certificate` to generate certificate

![image-20240829-020051.png](media://eb9d780b-d37d-4ae1-8c34-625f6a06f3c4)

Set both login and logout binding type to POST

![image-20240829-020343.png](media://07f08d7b-4af9-4a5f-acd0-c918400d2d6d)

Set to sign and verify signatures

![EasySSO SAML-Signed Requests-4.png](media://90b895a5-bb61-41fb-b7a6-8027101c48a9)

Save the settings

![EasySSO SAML-Signed Requests-5.png](media://1a5dbe4f-e8d6-453f-a1b6-39ddd56db343)

Open the metadata.xml and save to desktop

![EasySSO SAML-Signed Requests-6.png](media://38ea6fdd-778e-485c-88ec-87687d39d10c)

## Configure the Keycloak Side

### Keycloak Client Scope

In KeyCloak Administration console, navigate to Client Scopes, click `Create client scope`. Set the name to EASY_SSO and protocol to SAML.

Click `Save`.

![image-20240829-044845.png](media://39a268cb-93f2-4334-ac9c-e90ac503710e)

You should now be in the EASY_SSO client scope details. Select the mappers tab, then click `Configure a new mapper`.

![image-20240829-044959.png](media://90c03d31-eb6a-4fa3-affe-69458bbc21ce)

Select User Property

![image-20240829-045131.png](media://14263365-8de1-4778-a7d4-e1eafe123814)

Configure username user property

1. Name: username
2. Mapper Type: User Property
3. Property: username
4. Friendly Name: username
5. SAML Attribute Name: urn:oid:0.9.2342.19200300.100.1.1

Click `Save`

![image-20240829-045154.png](media://7bd28058-e2a8-41e8-8686-6ea4d7518a13)

Configure Email user property

1. Name: email
2. Mapper Type: User Property
3. Property: email
4. Friendly Name: email
5. SAML Attribute Name: urn:oid:0.9.2342.19200300.100.1.3

Click `Save`

![image-20240829-045305.png](media://c0a72581-945c-4210-a4cc-15f313f6c665)

Configure first name user property

1. Name: firstName
2. Mapper Type: User Property
3. Property: firstName
4. Friendly Name: firstName
5. SAML Attribute Name: urn:oid:2.5.4.42

Click `Save`.

![image-20240829-045329.png](media://3a28a311-5bf0-4277-a221-c526b8d94fcf)

Configure last name user property

1. Name: lastName
2. Mapper Type: User Property
3. Property: lastName
4. Friendly Name: lastName
5. SAML Attribute Name: urn:oid:2.5.4.4

Click `Save`

![image-20240829-045410.png](media://735662b6-c431-40d0-9b19-0cdba4d13d48)


(Optional) Configure Groups group list property

1. Name: groups
2. Mapper Type: Group list
3. Group attribute name: urn:oid:2.5.4.31
4. Friendly Name: groups
5. Full group path: off

Click `Save`

![image-20240829-045430.png](media://ec7da269-65d9-4b0b-8b31-190abe70eaae)

The final EASY_SSO Client scope should look something like this:

![image-20240829-045458.png](media://fcf2df00-c5f2-4481-88dc-05f9842464a5)

### KeyCloak Client

In KeyCloak Administration console, navigate to clients, click the "Import client" button

![image-20240829-050533.png](media://f154a090-a1f2-44fc-ac7b-589698c40def)

Click browse and upload the metadata.xml file exported from EasySSO earlier

![image-20240829-050555.png](media://e7a245ef-e885-4a8d-b14f-f19e65e8df45)

Ensure the Encrypt assertions is turned off, and that client signature required is turned on. Click `Save`.

![image-20240829-050614.png](media://4184be2d-5b70-45dd-b756-2c0fa2a8b1f9)

In the client that has just been imported, open Client scopes.

![image-20240829-050730.png](media://ee23d2d0-4c98-4c19-b96c-819c5c14b8a9)

Click to add the EASY_SSO client scope configured earlier

![image-20240829-050738.png](media://ba7e663f-df34-4c18-9c98-dcf23c7e81cc)

On the client configuration general configuration page ensure the following settings

1. Sign documents is enabled
2. Sign assertions is enabled

![image-20240829-050825.png](media://70799e79-af1d-4581-ac98-713c1b67da37)

## Configuring Users

For users to successfully log in, they must also have permission to access the application. See [EasySSO SAML JIT User Provisioning](https://techtime-website.atlassian.net/wiki/spaces/EasySSO/pages/5046870) for more details.