This guide describes how to configure Keycloak as a SAML 2.0 Identity Provider (IdP) for ClouDNS.
Log in to the Keycloak Administration Console and create a new realm, or use an existing realm for the ClouDNS integration.
| Setting | Value |
|---|---|
| Realm name | cloudns |
It is recommended to use a public HTTPS address for your Keycloak installation.
https://sso.example.comSelect the appropriate realm and navigate to:
Clients > Create client
Configure the new client as follows:
| Setting | Value |
|---|---|
| Client type | SAML |
| Client ID | https://www.cloudns.net |
| Name | ClouDNS |
Click Save.
Open the newly created ClouDNS client and configure the following initial values:
| Setting | Value |
|---|---|
| Master SAML Processing URL | https://www.cloudns.net |
| Valid Redirect URIs | https://www.cloudns.net/* |
| Setting | Value |
|---|---|
| Name ID Format | email |
| Force Name ID Format | On |
| Force POST Binding | On |
| Include AuthnStatement | On |
| Setting | Value |
|---|---|
| Sign Documents | On |
| Sign Assertions | Off |
| Signature Algorithm | RSA_SHA256 |
Open the Keys tab and configure:
| Setting | Value |
|---|---|
| Client Signature Required | Off |
| Encrypt Assertions | Off |
Keycloak provides the SAML Identity Provider metadata through the following endpoint:
https://sso.example.com/realms/cloudns/protocol/saml/descriptorReplace sso.example.com and cloudns with your actual Keycloak hostname and realm name.
We recommend downloading the metadata XML directly with curl instead of using the browser's Save Page function.
This ensures that the downloaded file contains the original XML response without any browser-generated HTML or additional content.
curl -fsS \
"https://sso.example.com/realms/cloudns/protocol/saml/descriptor" \
-o keycloak-metadata.xml
You can optionally validate the downloaded XML before uploading it:
xmllint --noout keycloak-metadata.xml
If the XML file is valid, the command will complete without displaying an error.
Log in to your ClouDNS account and navigate to:
Profile > SSO Authentication
Click Add new provider and enter a name for the provider.
| Setting | Value |
|---|---|
| Provider name | Keycloak |
| Metadata XML | keycloak-metadata.xml |
After adding the provider, ClouDNS will generate an ACS URL similar to:
https://www.cloudns.net/saml/user/XXXXXCopy this URL. It will be required in the next step.
Return to:
Clients > ClouDNS > Settings
Replace the temporary values configured earlier with the ACS URL generated by ClouDNS.
| Setting | Value |
|---|---|
| Master SAML Processing URL | https://www.cloudns.net/saml/user/XXXXX |
| Valid Redirect URIs | https://www.cloudns.net/saml/user/XXXXX |
Replace XXXXX with the value generated for your ClouDNS account.
You can also explicitly configure the ACS endpoint under:
Advanced > Fine Grain SAML Endpoint Configuration
| Setting | Value |
|---|---|
| Assertion Consumer Service POST Binding URL | https://www.cloudns.net/saml/user/XXXXX |
Click Save.
Create or configure the users who should be able to access ClouDNS through SAML.
Each user must have a valid email address configured in Keycloak. The email address should correspond to the user account allowed to access ClouDNS.
| Setting | Example |
|---|---|
| Username | user |
user@example.com |
|
| Email verified | Yes |
Open the ClouDNS login page and select the configured SAML provider.
You should be redirected to Keycloak for authentication. After successful authentication, Keycloak will send the signed SAML response to the ClouDNS ACS URL and you will be logged in to your ClouDNS account.
If you want ClouDNS to appear in the Keycloak Account Console under Applications, open the ClouDNS client settings and enable:
| Setting | Value |
|---|---|
| Always Display in Console | On |
The Keycloak Account Console is available at:
https://sso.example.com/realms/cloudns/account/