Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-3641

Once KEYCLOAK-8316 is included in a GA release of RH-SSO update the instructions to include instructions

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 2.13.0 GA, 2.14.0 GA
    • Documentation
    • 5
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • -

      The sentence "you can either configure the User Federation mapping to set the Email Verified attribute to true" is not currently possible:
      https://access.redhat.com/documentation/en-us/red_hat_3scale_api_management/2.5/html/creating_the_developer_portal/authentication#rhsso

      However, there is https://issues.jboss.org/browse/KEYCLOAK-8316 which once available in a GA released of Red Hat Single Sign-On will allow the same function but with a different configuration. Once this is available please update 3scale documentation with correct instructions to setup RH-SSO LDAP for this change. In the unreleased version this is done by setting "Trust Email" in the LDAP User Federation configuration, but maybe there will be changes before it's GAed.

      Additionally, althought "in the client created previously for 3scale SSO integration configure a hardcoded claim, with the token name email_verified and the claim value set to true." technically works, it's not the correct way to do it. Unfortunately until KEYCLOAK-8316 is released it's the only option. So probably a good idea to suggest against this approach in the 3scale documentation once the LDAP provider "Trust Email" setting exists.

            Unassigned Unassigned
            rhn-support-cdolphy Chris Dolphy
            Lluis Cavalle Lluis Cavalle
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: