Bug 57806 - Adjust keycloak-migration-status to check keycloak settings relevant for UCS 5.2
Summary: Adjust keycloak-migration-status to check keycloak settings relevant for UCS 5.2
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Keycloak
Version: UCS 5.0
Hardware: Other Linux
: P5 normal
Target Milestone: UCS 5.0-9-errata
Assignee: Julia Bremer
QA Contact: Felix Botner
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-12-13 16:22 CET by Julia Bremer
Modified: 2024-12-18 14:48 CET (History)
1 user (show)

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Julia Bremer univentionstaff 2024-12-13 16:22:25 CET
keycloak/server/sso/fqdn/path is originally an app setting, but is evaluated by other components, so it's also used an an UCRv. This leads to problems in setting, syncing and evaluting the value.
On a broader picture this shows the inconsistencies between UCRv, app settings and additional configurational objects.
Comment 1 Felix Botner univentionstaff 2024-12-16 13:10:45 CET
product: ucs
release: "5.0"
version: [9]
scope: ucs_5.0-0-errata5.0-9
src: univention-keycloak
fix: 1.0.13-4
desc: |
 This update addresses the following issues:
 * The script `univention-keycloak-migration-status` has been adjusted to
   check the setting ucs/server/sso/uri, which will be used
   from UCS 5.2 onwards.
bug: [57806]
Comment 2 Felix Botner univentionstaff 2024-12-16 13:35:01 CET
OK - old sso objects only on primary
OK - uri setting check on all machines
  OK - if no keycloak
  OK - creates policy on primary/local setting
OK - yaml