I have entityID = https://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/metadata in trytond.conf and also set my keycloak saml client’s clientId to the same value. I just can’t overcome “invalid request” message in browser with keycloak log showing “Cannot_match_source_hash”. My keycloak xml is gotten from curl -k -L -o /etc/tryton/keycloak-metadata.xml “https://keycloak.mydomain.com/realms/mydomain.com/protocol/saml/descriptor”. I just cannot figure out what I am doing wrong. Meanwhile, regular password login to tryton works for the same service.
Not sure what you mean but authentication_saml configuration accept only local file for metadata and config keys.
I am referring to the use of authentication_saml module ( Authentication SAML Module — SAML authentication for Tryton) for SSO with keycloak
I understood that but not the sentence I quoted.
I am referring to the part of trytond.conf file, viz:
[authentication_saml]
keycloak = Keycloak Single Sign On
[authentication_saml keycloak]
entityID = https://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/metadata
Location = https://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/acs
metadata = /etc/tryton/keycloak-metadata.xml
login = username
Any issue with the above configuration?
Those are not part of the standard configuration.
And you are missing the config key.
I am not using config key which is specified as optional in the documentation at Configuration — SAML authentication for Tryton.
Well, maybe the default configuration of PySAML does not work with your service.
I have taken a closer look by decoding the SAML Request sent. E.g.
The https is unexpectedly replaced by http as shown in the decoded equivalent below …
<ns0:AuthnRequest xmlns:ns0="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion" ID="id-rXbSAO9HEtDTP6tJ6" Version="2.0" IssueInstant="2026-09-18T16:26:33Z" Destination="``https://keycloak.peakharmony.com/realms/mydomain.com/protocol/saml``" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="``http://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/acs``" > <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">``http://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/metadata``</ns1:Issuer> </ns0:AuthnRequest>
If I then set the clientId in the keycloak saml service to
http://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/metadata
and set redirect uri to
http://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/acs
keycloak login appears correctly. Unfortunately after login, it will redirect to the http and not https. The real issue is thus why https is replaced by http in the SAML Request, that leads to the mismatch. I am yet to experiment with the optional config key involving PySAML.
It is because you did not set the tryton configuration [ssl] certificate.
Adding the following to trytond.conf fixed the https issue. Thank you.
[ssl]
certificate = /usr/local/share/ca-certificates/ca.mydomain.com.crt
privatekey = true
The following are not required in trytond.conf.
entityID = https://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/metadata
Location = https://erp.mydomain.com/tryton_db_yeqqcrtbickz/authentication/saml/keycloak/acs
You do not need to set to any path, just true or unset it (only one of certificate or privatekey needs to be true).
I first set only certificate = true and the problem was not solved.
What made you believe that those keys exists in trytond.conf ?
I think that if people want to customize this (I don’t know why they would but I am not very knowledgeable about SAML) they need to use a specific configuration file specified in config as it allows to override the settings used by the SAML client.