User Federation Not Synchronizing LDAP Users to RH-SSO

Solution Verified - Updated -

Issue

  • We successfully synchronized ldap user federation users with object class testperson where attribute uuid is mandatory. We later added another object class testid where attribute uuid is optional. We observe that when a new user is created under objectclass testperson, we can successfully sync the user into RH SSO. However, any user with object class testid is showing duplicate ID and sync issue.

  • When we create a user in redhat directory and try synchronizing changed users in redhatSSO we get the following in the RH-SSO server.log

WARN [org.keycloak.storage.ldap.LDAPStorageProviderFactory] (default task-7) User with ID 'ccccccc-faffffff-9a3333ddd' is not updated during sync as he already exists in Keycloak database but is not linked to federation provider '

Environment

  • Red Hat Single Sign-On (RH-SSO)
    • 7
  • LDAP
  • User Federation

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content