diff --git a/docker-compose.yml b/docker-compose.yml index 7d78326..eff92fb 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1107,6 +1107,7 @@ services: KC_BOOTSTRAP_ADMIN_PASSWORD: admin KEYCLOAK_PROXY_ADDRESS_FORWARDING: "true" KEYCLOAK_FRONTEND_URL: "${PROTOCOL:-http}://keycloak${DOMAIN_SUFFIX}" + KC_SPI_CONNECTIONS_HTTP_CLIENT_DEFAULT_DISABLE_TRUST_MANAGER: "true" KC_PROXY: edge av: diff --git a/docs/services/sso.md b/docs/services/sso.md index 2e1863b..f82c9da 100644 --- a/docs/services/sso.md +++ b/docs/services/sso.md @@ -3,12 +3,16 @@ ## [Keycloak](https://www.keycloak.org/) -- Keycloak is using LDAP as a user backend (make sure the LDAP container is also running) -- If you have ssl enabled please modify the example realm config accordingly in `docker/configs/keycloak/Example-realm.json` -- `occ user_oidc:provider Keycloak -c nextcloud -s 09e3c268-d8bc-42f1-b7c6-74d307ef5fde -d http://keycloak.local/auth/realms/Example/.well-known/openid-configuration` -- -- nextcloud -- 09e3c268-d8bc-42f1-b7c6-74d307ef5fde +``` +docker compose up -d ldap +docker compose up -d nextcloud keycloak +``` + +# Keycloak is using LDAP as a user backend. Make sure the LDAP container is also running. +- If you have ssl enabled, replace `http://nextcloud.local` with `https://nextcloud.local` in the example realm config at `docker/keycloak/Example-realm.json` +- Configure Keycloak as provider: `occ user_oidc:provider Keycloak -c nextcloud -s 09e3c268-d8bc-42f1-b7c6-74d307ef5fde -d http://keycloak.local/realms/Example/.well-known/openid-configuration` +- Keycloak admin interface: (admin:admin) +- Nextcloud client credentials: user: nextcloud // password: 09e3c268-d8bc-42f1-b7c6-74d307ef5fde ## Authentik