You must configure {Keycloak} settings for authentication with {PIV} cards.
-
In the {Keycloak} web UI, navigate to the Authentication tab.
-
From the Flows list, select Browser.
-
Click Copy to copy this flow.
-
In the Copy Authentication Flow window, enter a new name for the flow and click OK.
-
In the copied flow, delete Username Password Form and OTP Form entries.
-
Click Add execution.
-
From the Provider list, select X509/Validate Username Form.
-
Click Save.
-
In the X509/Validate Username Form raw, select ALTERNATIVE.
-
In the X509/Validate Username Form raw, click Actions > Config.
-
In the Alias field, enter a name for this configuration.
-
From the User Identity Source list, select Subject’s Common Name,
-
From the User mapping method list, select Username or Email.
-
Click Save.
-
Navigate to Authentication > Bindings.
-
From the Browser Flow list, select the created flow.