Bug 55635 - Keycloak - Improve Documentation - missing UCRVs
Keycloak - Improve Documentation - missing UCRVs
Status: NEW
Product: UCS
Classification: Unclassified
Component: Keycloak
UCS 5.0
Other All
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-02-01 12:01 CET by Ingo Jürgensmann
Modified: 2023-05-26 10:31 CEST (History)
3 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ingo Jürgensmann univentionstaff 2023-02-01 12:01:40 CET
When testing out Keycloak from the App Center, some missing parts in the current Keycloak documentation got my attention: 

1) "ucs/server/sso/virtualhost" is undocumented
Although "ucs/server/sso/virtualhost" is important for generating the Apache2 config in /etc/apache2/sites-availbe/univention-keycloak.conf it is not listed under Configuration -> 2.9 Settings. If this UCRV is set to "false" an empty Apache config will be generated and Keycloak won't work. 

2) Keycloaks Apache UCRVs are not documented
When using e.g. LetsEncrypt (or other) SSL certs for Apache, you'll need to set some more variables: 
- keycloak/apache2/ssl/certificate 
- keycloak/apache2/ssl/key
- keycloak/apache2/ssl/ca (maybe not always needed)
- keycloak/url/prefix (is being set via UMC, I guess)
- keycloak/server/sso/certificate/generation

No UCRV seems to have a description set in UMC as well, so the more important is a comprehensive documentation.