Keycloak authorization users from ldap without users import

Viewed 98

I am trying to authorize user from ldap without import users from ldap to keyclaok. The documentation says:

You can use LDAP with Keycloak without importing users into the Keycloak user database. The LDAP server backs up the common user model that the Keycloak runtime uses. If LDAP does not support data that a Keycloak feature requires, that feature will not work. The advantage of this approach is that you do not have the resource usage of importing and synchronizing copies of LDAP users into the Keycloak user database.

There is my spring security config:

   @Override
    protected void configure(HttpSecurity http) throws Exception {
        super.configure(http);
        
        http    
                    .csrf().disable()
                    .authorizeRequests()
                    .antMatchers("/vaadinServlet/UIDL/**").permitAll()
                    .antMatchers("/vaadinServlet/HEARTBEAT/**").permitAll()
                    .antMatchers("/api/gui**")
                    .permitAll()
                   .and().exceptionHandling().accessDeniedHandler(accessDeniedHandler())
                   .and().logout().logoutUrl("/api/logout").logoutSuccessUrl("/api/").deleteCookies("OAuth_Token_Request_State", "JSESSIONID").invalidateHttpSession(true);

    }

But keycloak cant find user from ldap when it trying to login. Is there any way to authorize user from ldap without importing it to keycloak users?

0 Answers
Related