<font face="arial" size="2"><p style="margin:0;padding:0;font-family: arial; font-size: 10pt; word-wrap: break-word;">Thanks</p>
<p style="margin:0;padding:0;font-family: arial; font-size: 10pt; word-wrap: break-word;">Kalinga.<br style="font-family: arial; font-size: 10pt; word-wrap: break-word;" /><br />-----Original Message-----<br />From: "Raghu Prabhala" <prabhalar@yahoo.com><br />Sent: Monday, March 16, 2015 4:09pm<br />To: "Kalinga Dissanayake" <kalinga@leapset.com>, "Stian Thorgersen" <stian@redhat.com><br />Cc: "keycloak-user@lists.jboss.org" <keycloak-user@lists.jboss.org><br />Subject: Re: [keycloak-user] Customization of authentication mechanism and +<br /><br /></p>
<div id="SafeStyles1426502684">
<div style="color: #000; background-color: #fff; font-family: HelveticaNeue-Light, Helvetica Neue Light, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;">
<div id="yui_3_16_0_1_1426499522055_5852">Kalinga - The latest published version is 1.1 and you can find the documentation at the below link.</div>
<div id="yui_3_16_0_1_1426499522055_5850"><a id="yui_3_16_0_1_1426499522055_5849" href="http://keycloak.jboss.org/docs">http://keycloak.jboss.org/docs</a></div>
<div id="yui_3_16_0_1_1426499522055_5870" dir="ltr">Raghu<br /> </div>
<div id="yui_3_16_0_1_1426499522055_5830" style="font-family: HelveticaNeue-Light, Helvetica Neue Light, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;">
<div id="yui_3_16_0_1_1426499522055_5829" style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;">
<div id="yui_3_16_0_1_1426499522055_5828" dir="ltr"><hr size="1" /><span id="yui_3_16_0_1_1426499522055_5827" style="font-family: Arial; font-size: small;"> <strong><span style="font-weight: bold;">From:</span></strong> Kalinga Dissanayake <kalinga@leapset.com><br /><strong><span style="font-weight: bold;">To:</span></strong> Stian Thorgersen <stian@redhat.com> <br /><strong><span style="font-weight: bold;">Cc:</span></strong> keycloak-user@lists.jboss.org <br /><strong><span style="font-weight: bold;">Sent:</span></strong> Monday, March 16, 2015 6:32 AM<br /><strong><span style="font-weight: bold;">Subject:</span></strong> Re: [keycloak-user] Customization of authentication mechanism and +<br /></span></div>
<div id="yui_3_16_0_1_1426499522055_5873" class="y_msg_container"><br />
<div id="yiv2518617105">
<div id="yui_3_16_0_1_1426499522055_5872">
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">Stian,</div>
<div id="yui_3_16_0_1_1426499522055_5871" style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">Thanks for responding in a matter of few minutes.</div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;"> </div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">I will then look to see if i can manage my doing changes on the Authentication Manager class for now.</div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">Further, I will have a look at the user provider and get back to u.</div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">btw, Is the content on this link outdated;</div>
<div id="yui_3_16_0_1_1426499522055_5877" style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;"><span id="yui_3_16_0_1_1426499522055_5876" style="font-family: monospace;"><span id="yui_3_16_0_1_1426499522055_5875" style="color: #800000;"> <a id="yui_3_16_0_1_1426499522055_5874" rel="nofollow"></a>http://docs.jboss.org/keycloak/docs/1.0-beta-3/userguide/html/authentication-spi.html</span></span></div>
<div id="yui_3_16_0_1_1426499522055_5878" style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;"> </div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;"><span style="font-family: monospace;"><span style="color: #800000;">Kalinga.</span></span></div>
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;"> </div>
<div class="qtdSeparateBR"><br /><br /></div>
<div id="yiv2518617105yqtfd23764" class="yiv2518617105yqt0239841417">
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">-----Original Message-----<br />From: "Stian Thorgersen" <stian@redhat.com><br />Sent: Monday, March 16, 2015 3:31pm<br />To: "Kalinga Dissanayake" <kalinga@leapset.com><br />Cc: keycloak-user@lists.jboss.org<br />Subject: Re: [keycloak-user] Customization of authentication mechanism and +<br /><br /></div>
<div id="yiv2518617105SafeStyles1426501772">
<div style="margin: 0px; padding: 0px; font-family: arial; font-size: 10pt; -ms-word-wrap: break-word;">We don't currently have a way to plugin your own authentication mechanism, but this is something we'll be adding.<br /><br />You have two choices when it comes to users, you can either use our user federation provider mechanism to sync between Keycloak and your current db. Or you can migrate the users fully to the Keycloak db. In either case you have an option on overriding how passwords are verified (either UserFederationProvider or by extending an existing UserProvider). With the above authentication mechanism we'll most likely also make the verification of passwords pluggable which would support different hash algorithms.<br /><br />----- Original Message -----<br />> From: "Kalinga Dissanayake" <kalinga@leapset.com><br />> To: keycloak-user@lists.jboss.org<br />> Sent: Monday, March 16, 2015 10:48:55 AM<br />> Subject: [keycloak-user] Customization of authentication mechanism and +<br />> <br />> <br />> <br />> Guys,<br />> <br />> I need to understand the capability of keycloak with my requirement and to<br />> ensure that keycloak is scalable to meet my needs. My main requirement is to<br />> integrate keycloak to our system to support SSO hence I need to migrate my<br />> existing users. My main concerns;<br />> <br />> <br />> <br />> 1/ Customize authentication method.<br />> <br />> I need to authenticate users similar to what we currently use in our<br />> production system. In our system, users are identified by username, password<br />> and the pin.<br />> <br />> For instance;<br />> <br />> User -> jack, password -> pwd, pin -> 50000<br />> <br />> User should enter all three to login to the system.<br />> <br />> I went through the codebase and I saw that the Authentication Manager (which<br />> is a concrete class) does all the work inside keycloak. I managed to<br />> customize the frontend with ease, however, in order to support the pin in<br />> the backend seems like I have to customize the AuthenticationManager class<br />> (no direct SPIs).<br />> <br />> Although there is a link here;<br />> <br />> http://docs.jboss.org/keycloak/docs/1.0-beta-3/userguide/html/authentication-spi.html<br />> <br />> I cant seem to find anything here which matches the current code base (to via<br />> a new authentication method via spis) and the example has been removed.<br />> <br />> <br />> <br />> 2/ Customize password hashes.<br />> <br />> We have our own algorithm used to store password hashes. What should I do to<br />> add this to keycloak?<br />> <br />> I do not know the current passwords of the users already in our system, so<br />> when doing the migration i need keyclock to support the current algorithm we<br />> use. Can we plugin new hashing algorithms to meet my needs?<br />> <br />> <br />> <br />> Any other issues I might face?<br />> <br />> I feel key cloak is the right choice if the above two questions are answered.<br />> Please let me know.<br />> <br />> _______________________________________________<br />> keycloak-user mailing list<br />> keycloak-user@lists.jboss.org<br />> https://lists.jboss.org/mailman/listinfo/keycloak-user</div>
</div>
</div>
</div>
</div>
<br />
<div id="yqtfd48690" class="yqt0239841417">_______________________________________________<br />keycloak-user mailing list<br /><a href="mailto:keycloak-user@lists.jboss.org">keycloak-user@lists.jboss.org</a><br /><a href="https://lists.jboss.org/mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/mailman/listinfo/keycloak-user</a></div>
<br /><br /></div>
</div>
</div>
</div>
</div></font>