[keycloak-user] Overriding AssertionConsumerServiceURL in

Bill Burke bburke at redhat.com
Wed Apr 5 10:00:22 EDT 2017


The SP can send ACS URL, this URL will only be used if it is validated 
against the Redirect URI patterns that are registered in the 
configuration of the client.  Does that answer your question?


On 4/4/17 6:07 PM, Jacobs, Michael wrote:
> For our application we created a SAML Identity Provider to proxy authentication to an outside source.  However we need their response to be sent back to a load-balanced URL on our F5.  The value that I believe controls this is "Redirect URI" in our SAML Provider config, looks like that goes to populate the AssertionConsumerServiceURL in the SAML request.  Redirect URI is not editable in the UI.  Is there a way we can control what gets populated there, so our partner will be directed to send to the load-balanced URL.
>
> We'd also like to control password reset emails links to contain that load-balanced URL, but it does not look like the templating system allows us to manipulate that that level.
>
> MJ
> _______________________________________________
> keycloak-user mailing list
> keycloak-user at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-user



More information about the keycloak-user mailing list