[keycloak-user] SAML attribute extraction and invalid_redirect_uri

Bill Burke bburke at redhat.com
Mon Nov 23 09:22:47 EST 2015



On 11/23/2015 5:26 AM, Joseph.George at finantix.com wrote:
> Dear All
>
> May I ask - how to get the user id and other SAML  additional attribute
> which server asserts.  Do you have any url for java program to extract
> these info from client/service provider program
>

Did you see the "Mappers" tab within Client configuration in the admin 
console?  Hopefully the tooltips ( the little "?" on the screen) make 
this self-describing.

>
> Secondly,
> am running keycloak server in a standalone mode and defined realm - demo
> with SAML and users/roles etc
> Now, once i access http://localhost:8280/sample/, it is getting redirect to
> IDP server ..but it is not challenging for user authentication..
> it just says "Invalid redirect uri"..
>

You need to configure a valid redirect URI for your application in the 
Client tab in the keycloak admin console.  You also need to specify the 
Master SAML Processing URL or the Single Signon/Logout Service URL and 
the binding you want to use.


-- 
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com


More information about the keycloak-user mailing list