mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
[GH-ISSUE #2207] Netbird doesn't work with Keycloak with LDAPS for Account Delegation #4382
Open
opened 2026-08-05 00:57:26 -04:00 by saavagebueno
·
23 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#4382
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @michelangelo136 on GitHub (Jun 27, 2024).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/2207
Describe the problem
While running Netbird with Keycloak I can authenticate and connect while using the local accounts, but when I enable account federation with LDAPS on Keycloak, the authentication stops working and I can no longer login or use Netbird.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
The Netbird dashboard should load.
Are you using NetBird Cloud?
No, Netbird selfhosted
NetBird version
0.28.3
Screenshots
Additional context
Netbird works if Keycloak doesn't use LDAPS federated users, when adding the Federated users it stops working, I also get the following error some times:
ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Get "https://admin-keycloak.example.com:443/admin/realms/netbird/users?max=150": unexpected EOF@bcmmbaga commented on GitHub (Jun 27, 2024):
Hello @michelangelo136 , can you share the management logs?
@michelangelo136 commented on GitHub (Jun 27, 2024):
Hello @bcmmbaga, here are the logs.
management-1 | 2024-06-27T14:34:55Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Post "https://sso.example.com/realms/netbird/protocol/openid-connect/token": context deadline exceeded (Client.Timeout exceeded while awaiting headers) management-1 | 2024-06-27T14:34:55Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-27T14:34:55Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1008626266: GET /api/users status 401 management-1 | 2024-06-27T14:35:05Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Post "https://sso.example.com/realms/netbird/protocol/openid-connect/token": context deadline exceeded (Client.Timeout exceeded while awaiting headers) management-1 | 2024-06-27T14:35:05Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-27T14:35:05Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 3682479814: GET /api/users status 401 management-1 | 2024-06-27T14:35:15Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Post "https://sso.example.com/realms/netbird/protocol/openid-connect/token": context deadline exceeded (Client.Timeout exceeded while awaiting headers) management-1 | 2024-06-27T14:35:15Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-27T14:35:15Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 2881042402: GET /api/users status 401@bcmmbaga commented on GitHub (Jun 27, 2024):
There are missing initial logs when starting the management. Can you restart the management, and then share the logs afterwards?
@michelangelo136 commented on GitHub (Jun 28, 2024):
I restarted the management service, these is the log, the fqdn and the realm have been redacted replaced by redacted.
management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:455: loading OIDC configuration from the provided IDP configuration endpoint https://sso.example.com/realms/example/.well-known/openid-configuration management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:460: loaded OIDC configuration from the provided IDP configuration endpoint: https://sso.example.com/realms/example/.well-known/openid-configuration management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:462: overriding HttpConfig.AuthIssuer with a new value https://sso.example.com/realms/example, previously configured value: https://sso.example.com/realms/example management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:466: overriding HttpConfig.AuthKeysLocation (JWT certs) with a new value https://sso.example.com/realms/example/protocol/openid-connect/certs, previously configured value: https://sso.example.com/realms/example/protocol/openid-connect/certs management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:492: overriding PKCEAuthorizationFlow.TokenEndpoint with a new value: https://sso.example.com/realms/example/protocol/openid-connect/token, previously configured value: https://sso.example.com/realms/example/protocol/openid-connect/token management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:495: overriding PKCEAuthorizationFlow.AuthorizationEndpoint with a new value: https://sso.example.com/realms/example/protocol/openid-connect/auth, previously configured value: https://sso.example.com/realms/example/protocol/openid-connect/auth management-1 | 2024-06-28T12:13:23Z INFO management/server/telemetry/app_metrics.go:177: enabled application metrics and exposing on http://0.0.0.0:8081 management-1 | 2024-06-28T12:13:23Z INFO management/server/store.go:128: using SQLite store engine management-1 | 2024-06-28T12:13:23Z INFO management/server/migration/migration.go:130: No records in table peers, no migration needed management-1 | 2024-06-28T12:13:23Z INFO management/server/migration/migration.go:130: No records in table peers, no migration needed management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:173: geo location service has been initialized from /var/lib/netbird/ management-1 | 2024-06-28T12:13:23Z INFO management/server/account.go:902: single account mode enabled, accounts number 1 management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:292: running gRPC backward compatibility server: [::]:33073 management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:324: management server version 0.28.3 management-1 | 2024-06-28T12:13:23Z INFO management/cmd/management.go:325: running HTTP server and gRPC server on the same port: [::]:443 management-1 | 2024-06-28T12:13:33Z WARN management/server/account.go:942: failed warming up cache due to error: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:13:34Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: unexpected EOF management-1 | 2024-06-28T12:13:34Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:13:34Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 2969496814: GET /api/users status 401 management-1 | 2024-06-28T12:13:44Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:13:44Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:13:44Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1617532156: GET /api/groups status 401 management-1 | 2024-06-28T12:13:45Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Get "https://sso-admin.example.com:443/admin/realms/example/users?max=162": unexpected EOF management-1 | 2024-06-28T12:13:45Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:13:45Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 994037172: GET /api/peers status 401 management-1 | 2024-06-28T12:13:55Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:13:55Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:13:55Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1110047656: GET /api/users status 401 management-1 | 2024-06-28T12:14:20Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:14:20Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:14:20Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1610098238: GET /api/users status 401 management-1 | 2024-06-28T12:14:31Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:14:31Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:14:31Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1748801382: GET /api/users status 401 management-1 | 2024-06-28T12:14:41Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:14:41Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:14:41Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 884359798: GET /api/users status 401 management-1 | 2024-06-28T12:14:52Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:14:52Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:14:52Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1147169547: GET /api/users status 401 management-1 | 2024-06-28T12:15:08Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:15:08Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:08Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 2964505694: GET /api/users status 401 management-1 | 2024-06-28T12:15:18Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:15:18Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:18Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 2747264743: GET /api/users status 401 management-1 | 2024-06-28T12:15:19Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Get "https://sso-admin.example.com:443/admin/realms/example/users/count?": unexpected EOF management-1 | 2024-06-28T12:15:19Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:19Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 3841999307: GET /api/users status 401 management-1 | 2024-06-28T12:15:30Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:15:30Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:30Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 3284690800: GET /api/users status 401 management-1 | 2024-06-28T12:15:31Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: Get "https://sso-admin.example.com:443/admin/realms/example/users?max=162": unexpected EOF management-1 | 2024-06-28T12:15:31Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:31Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 620562561: GET /api/users status 401 management-1 | 2024-06-28T12:15:42Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:15:42Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:15:42Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 3594267140: GET /api/users status 401 management-1 | 2024-06-28T12:15:53Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:16:04Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:16:04Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:16:04Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 1882557009: GET /api/users status 401 management-1 | 2024-06-28T12:16:19Z ERRO management/server/http/middleware/auth_middleware.go:88: Error when validating JWT claims: context deadline exceeded (Client.Timeout or context cancellation while reading body) management-1 | 2024-06-28T12:16:19Z ERRO management/server/http/util/util.go:80: got a handler error: token invalid management-1 | 2024-06-28T12:16:19Z ERRO management/server/telemetry/http_api_metrics.go:181: HTTP response 701924560: GET /api/users status 401@michelangelo136 commented on GitHub (Jul 1, 2024):
Hello @bcmmbaga, will you need other logs from the system or something from the management file?
@bcmmbaga commented on GitHub (Jul 1, 2024):
@michelangelo136 There is an issue with the Keycloak LDAP federator becoming slow, causing timeouts when starting the management as we fetch the user list from Keycloak. Could you take a look at https://github.com/keycloak/keycloak/issues/10005? Also, please consider upgrading Keycloak and retesting to see if the issue has been resolved from their side.
@michelangelo136 commented on GitHub (Jul 2, 2024):
With the latest Keycloak version the problem still persists.
@relay2334 commented on GitHub (Jul 26, 2024):
Seeing the same issue still. Any recommendations?
@Marcus1Pierce commented on GitHub (Jul 26, 2024):
@relay2334 Try this comment https://github.com/netbirdio/netbird/issues/2142#issuecomment-2209552043
@relay2334 commented on GitHub (Jul 29, 2024):
Unfortunately, no luck. Looks like its the Keycloak LDAP Issue
@paulDashkevich commented on GitHub (Aug 11, 2024):
Clients > netbird backend (and 2nd netbird-client) > Client scopes > netbird-backend-dedicated (and 2nd netbird-client-dedicated) > Scope ON > switch to OFF@michelangelo136 commented on GitHub (Aug 11, 2024):
I followed a method mentioned above making an inter-realm authentication and having a separate netbird realm that authenticates on the primary one, I will try your method in the upcoming week, it will hopefully work nicely and won't cause an outage, hopefully this will help streamline the user authentication process.
Thanks for sharing!
@cmacheret commented on GitHub (Aug 16, 2024):
@michelangelo136 Thanks your sharing. How did you make the "inter-realm" authentication work?
Let's say you have Realm A with LDAP and Realm B (without LDAP) for Netbird ? Did you configure in Realm B an "identity provider" of type "Keycloak OpenID" that points to Realm A or did you use another way?
@michelangelo136 commented on GitHub (Aug 16, 2024):
@cmacheret yes that's how I did it, effectively the netbird realm authenticates using open id connect to the main realm.
I can look up the config on Monday and post it here as a lot of things are undocumented and you need to find how they work through trial and error.
@cmacheret commented on GitHub (Aug 17, 2024):
@michelangelo136 that would be great, thanks
@cmacheret commented on GitHub (Aug 21, 2024):
@michelangelo136 Hi, any chance you had time to check your config? It would be really great if you could share it. Thanks in advance!
@michelangelo136 commented on GitHub (Aug 28, 2024):
Hi @cmacheret, sorry for the delay, quite a lot of stuff lately, in the Netbird Realm you need to go to Identity Providers and create a new Keycloak OpenID provider
Alias = Your provider name (write anything you want here)
Under the OpenID Connection Settings populate the metadata URLs based on the https://keycloak.example.com/realms/example-realm/.well-known/openid-configuration contents (replace keycloak, example and example-realm with your own values)
Then set the following
Client authentication: Client secret sent as post
Client ID: "The client ID that you will create in your keycloak-example/prod realm"
Client Secret: "The secret taken from the client you created in your prod realm"
Client Assertion Signature Algorithm: "By default is ES256"
Send 'id_token_hint' in logout requests: On
Leave all of the other option to the "off" state.
Then, in your prod Realm create a new OpenID client and give it a name of your choice.
Client ID: Anything you would like
Root URL: Your keycloak - Netbird realm url, eg: https://keycloak.example.com/realms/netbird
Valid redirect URIs: You need to set the following values:
Web Origins: +
Client Authentication: On
Authentication Flow: Standard Flow, Direct Access grants
Then go to the Credentials Tab and set the Client Authenticator to "Client ID and Secret" and use generated secret to populate the Client Secret for the Identity Provider in the netbird Realm.
That should be what I did and it worked, hopefully, it work for you as well.
@cmacheret commented on GitHub (Aug 29, 2024):
Thanks a lot @michelangelo136
@nazarewk commented on GitHub (Apr 28, 2025):
Hello @michelangelo136,
We're currently reviewing our open issues and would like to verify if this problem still exists in the latest NetBird version.
Could you please confirm if the issue is still there?
We may close this issue temporarily if we don't hear back from you within 2 weeks, but feel free to reopen it with updated information.
Thanks for your contribution to improving the project!
@michelangelo136 commented on GitHub (Apr 28, 2025):
Hello @nazarewk,
Unfortunately I don't have a test Netbird environment available in order to test it.
@cmacheret I'm tagging you in the off chance that you have a test environment available and you can test it.
@cmacheret commented on GitHub (May 2, 2025):
Hi @michelangelo136 and @nazarewk
I don't have a test setup but should be able to get one running without too much effort. Will keep you posted.
@cmacheret commented on GitHub (May 5, 2025):
Hi @nazarewk and @michelangelo136
the issue seems to be solved.
Here the details from my test environment :
Keycloak (running on docker) :
version : 26.2 (image: quay.io/keycloak/keycloak:26.2)
user federation : Active Directory on prem (Windows Server 2022) using LDAPS (port 636)
Netbird version :
dashboard : v2.11.0
all other components (management,signal, ...) : 0.43.1
I'm able to login the dashboard with my "federated" user coming from the Active Directory.
The next step would be now to check how to limit the login to some users with a specific Active Directory group (or a specific role in Keyclaok).
Best regards
@Lirok228 commented on GitHub (Sep 11, 2025):
Subject: 401 Authentication Error and Timeout with LDAP Federation
I'm encountering a similar issue. I have configured LDAP federation in Keycloak, and I'm receiving a 401 error during authentication.
It appears that the authentication process is timing out, likely because we have a very large number of users in our Active Directory. It seems there is no option to configure this timeout.
I saw a suggestion in another issue to disable the "Full scope allowed" setting on the backend client, but this did not resolve the problem.
Netbird v0.56.1 (latest) (docker)
Keycloak v26.2.0 (on-prem)
Here is the full error log:
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: aef98b36-dddd-4f16-af09-6f36e9e9c607] management/server/http/middleware/auth_middleware.go:69: Error when validating JWT: context deadline exceeded (Client.Timeout or context cancellation while reading body)
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: aef98b36-dddd-4f16-af09-6f36e9e9c607] shared/management/http/util/util.go:85: got a handler error: token invalid
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: 8051026d-b7ff-4100-8bbf-6cce1a953c46] management/server/http/middleware/auth_middleware.go:69: Error when validating JWT: context deadline exceeded (Client.Timeout or context cancellation while reading body)
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: 8051026d-b7ff-4100-8bbf-6cce1a953c46] shared/management/http/util/util.go:85: got a handler error: token invalid
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: 8051026d-b7ff-4100-8bbf-6cce1a953c46] management/server/telemetry/http_api_metrics.go:189: HTTP response 8051026d-b7ff-4100-8bbf-6cce1a953c46: GET /api/users/current status 401
2025-09-10T10:25:11Z ERRO [context: HTTP, requestID: aef98b36-dddd-4f16-af09-6f36e9e9c607] management/server/telemetry/http_api_metrics.go:189: HTTP response aef98b36-dddd-4f16-af09-6f36e9e9c607: GET /api/users status 401