SSO with Keycloak

esk February 17, 2020

Anyone with experience getting SSO on Atlassian Datacenter products to work with Keycloak

I've added a new client with Keycloak, however the AuthnRequest keeps failing.

<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="ONELOGIN_fa70f13e-5058-411b-9b57-787ac254cbfb" Version="2.0" IssueInstant="2020-02-17T17:51:16Z" Destination="https://URL/realms/corp/protocol/saml" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="https://URL/bitbucket/plugins/servlet/samlconsumer">

The error l see in the Keycloak logs is 

error=invalid_authn_request, reason=invalid_destination


2 answers

Suggest an answer

Log in or Sign up to answer
0 votes
Tadas Apulskis March 22, 2021

Please share your keycloak client config and the SSO config. 

0 votes
Richard Lapwood -TechTime-
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
February 17, 2020

I would suggest try changing your destination URL to match your POST binding URL (i.e. the Atlassian product URL, not the Keycloak Realms URL)

esk February 20, 2020

Hi Richard,

Thank you for your quick response and my apologies for not replying sooner. I've tried setting both the Assertion Consumer Service POST Binding URL and Assertion Consumer Service Redirect Binding URL in keycloak. It still wouldn't work.  

Like kiryl.kruhlik likes this
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 4, 2022

Hey, @esk , have you managed to resolve the issue? If yes, could you please share the solution?

AUG Leaders

Atlassian Community Events