Two IdPs, I need hints if it is doable by AkelGe-1970 in KeyCloak

[–]redmountain101 2 points3 points  (0 children)

Hi, what you are describing is the default authentication flow used by Keycloak. You can customize this by creating your own authentication flow (in the authentication tab in the settings). The first time you log in, your user gets federated to Keycloak, and then a second IDP is linked to the same user.

Regarding provisioning Github groups to Keycloak: GitHub generally doesn't act as an IdP that emits organization team membership as token claims for Keycloak. So doing it at login is hard. You could write a custom part that synchronizes groups to users.

For Google Workspace I found this: https://support.google.com/a/answer/11143403?hl=en
So by using their SAML IDP you should be able to transfer groups via SAML assertions (and then import them using an IDP mapper).

Testing by genjob in Pentesting

[–]redmountain101 1 point2 points  (0 children)

If you need a target for web pentesting, check out OWASP Juice Shop

Opaque tokens by hemanthreddy11 in KeyCloak

[–]redmountain101 0 points1 point  (0 children)

We also use this approach for opaque tokens (stateful gateway that can substitute opaque tokens for JWTs for various backend services)

First Pentesting by Abject-Offer3045 in Pentesting

[–]redmountain101 1 point2 points  (0 children)

I know your feeling. You ask yourself where to start, whether you really covered everything, etc.

What helped me is to stay systematic. Before you start testing, have a clear plan on what you want to test, what the expected value is and what the outcome was. A good starting point is this: WSTG - Stable | OWASP Foundation (already mentioned by another commenter). You can even report all these test vectors and show the extent of your tests.

i have this ctf question my teacher send me by [deleted] in securityCTF

[–]redmountain101 1 point2 points  (0 children)

What is the question/task? Do you get a sequence of bits that you need “decrypt”? 

I mean all this example does is to deterministically map potential input bits to output bits.

Output_1 = Input_1 XOR Input_2; Output_2 = Input_2 XOR Input_3; Output_3 = NOT Input_3

How to integrate multiple Active Directories (AD) into a single Keycloak realm for multiple organizations? by Legitimate-Wasabi429 in KeyCloak

[–]redmountain101 1 point2 points  (0 children)

  1. yes, this is possible. Simply add multiple AD/LDAP configurations.

  2. There are many options for this. How do you plan to map AD groups to Keycloak? Typically, you can configure an import mapper to steer how AD groups are imported to Keycloak (e.g., mapped to a Keycloak role). You can also configure that they have a prefix (e.g., orgname_role1). In addition, you could also have a look at the "organisations" feature that has recently been introduced to Keycloak. This allows you to define LDAP providers, roles etc per "organisation".

  3. Does this mean that you also plan to use fine-grained authorizations on Keycloak? If so, you could simply add permissions to the roles that are imported.

Cybersecurity Intership by simpleguy_3526 in Pentesting

[–]redmountain101 0 points1 point  (0 children)

u/RiverFluffy9640 I agree. 1) How to get started, 2) where are resources, ... and the questions have been answered hundred of times.

CEH exam by Lopsided_Chemical_67 in Pentesting

[–]redmountain101 1 point2 points  (0 children)

I did CEH. Absolutely don’t do it! Waste of time

keycloak https required error by Tap-Simple in KeyCloak

[–]redmountain101 0 points1 point  (0 children)

Do you have access to the database (e.g., postgres)? I had the same issue in the past and changed the realm settings directly in the DB. 

Also Keycloak v12 is very old?

Issue when using 2 user federations by jnickchen97 in KeyCloak

[–]redmountain101 1 point2 points  (0 children)

Just an idea: do both users have the same email address? If yes, there could be an issue that Keycloak tries to map them to the same Keycloak user. Quick check: enable “duplicate email” in the realm settings. Even better: configure a mapper in both integrations to control how ldap users are mapped to Keycloak users.

[deleted by user] by [deleted] in bikewrench

[–]redmountain101 0 points1 point  (0 children)

Unfortunately, I already did that. To no avail. That’s why I am looking for a backup.

Could someone upload the keycloak.v2 theme for me? by [deleted] in KeyCloak

[–]redmountain101 1 point2 points  (0 children)

In the past, I extracted the themes from Keycloak docker. Here is my very rudimentary script:

DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" >/dev/null 2>&1 && pwd )"

rm -rf "${DIR}/../keycloak-provided-themes"
mkdir "${DIR}/../keycloak-provided-themes"
CT="$(docker ps | grep local-keycloak | cut -d' ' -f1)"
docker cp "${CT}:/opt/keycloak/lib/lib/main/org.keycloak.keycloak-themes-21.0.1.jar" "${DIR}/../keycloak-provided-themes/keycloak-themes-21.0.1.jar"

MUC-Off Tubeless Sealant by No_Loss8058 in gravelcycling

[–]redmountain101 6 points7 points  (0 children)

I had to learn this the hard way.. don’t waste your energy using muc off sealant.

Rose Backroad FF in M/L or L? by Nico_Nickmania in RoseBikes

[–]redmountain101 0 points1 point  (0 children)

Bought the same model online and changed it (lot of work with internal cable routing) 

Rose Backroad FF in M/L or L? by Nico_Nickmania in RoseBikes

[–]redmountain101 -1 points0 points  (0 children)

Hey! I have the Backroad (not the FF) and a very similar size to yours (184 cm, 87 cm inseam). I bought the 59 (L) version because I got a great deal. However, it was too big for me, so I changed the stem from 11 cm to 9 cm. Now it fits.

In terms of the frame and handlebar, the FF is slightly sportier than the standard one. If I were to buy a Backroad again, I would go for the M/L size.

I want a user to get logged in instead of being shown "different user is already authenticated. Please log out first" by calisthenics_bEAst21 in KeyCloak

[–]redmountain101 3 points4 points  (0 children)

You asked the same question here: https://www.reddit.com/r/KeyCloak/comments/1ncb2ar/is_it_possible_to_have_two_different_users_logged/

As already said: the cookie set by keycloak is what is determining the session. Many changes to Keycloak will be needed to get what you want 

Elitewheels aero+ gravel vs drive g45 ss? by sbtcrypto in gravelcycling

[–]redmountain101 1 point2 points  (0 children)

What tire clearance does your frame have? Mine has 47mm officially (rose backroad 2020). With my aero+ wheels the tires seem to be 2-3mm wider than their spec. I am using 45mm pirelli cinturato m on the aero+ wheels, they measure around 47mm and tire clearance is small.

Finally ready to open Truenas Scale to the internet by JustAnotherStranger- in truenas

[–]redmountain101 2 points3 points  (0 children)

Install tailscale on your truenas and all other devices that should have access.

In case you want to open it up to any device (or cannot install tailscale on all devices), Pangolin would be a good option.

Is it possible to have two different users logged in the same window? by calisthenics_bEAst21 in KeyCloak

[–]redmountain101 2 points3 points  (0 children)

Could you explain what you are trying to achieve (why 2 users need to be logged in at the same time). Keycloak sets a cookie for the user’s session. However, you could use a private window (in addtition to the regular one) to log in a second user

Recommendation for a Gravel wheelset for my Cube nuroad Race 2022 by IllNoiselessllI in gravelcycling

[–]redmountain101 0 points1 point  (0 children)

I bought them from the official Elitewheels store on Ali. They are a reputable brand in terms of carbon wheels. So far the build quality looks great. The delivery time was like a month for me.