# New installation on Rocky Linux 9.6 using keycloak for auth

**URL:** <https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450>\
**Category:** Get Help\
**Created:** [August 14, 2025, 9:57pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450 "2025-08-14T21:57:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 14, 2025, 9:57pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/1 "2025-08-14T21:57:11Z")

</div>

I am standing up OOD to talk to our on prem HPC. i would like to get everything running on one host.

OS: RockyLinux 9.6

I am looking to use keycloak 26.3.2 for auth.

I have installed the ood RPM and its responding on http. i have installed “Keycloak” and setup a new “Realm” and also setup the “User federation”.  
These directions talk about adding an OIDC Client Template but i don’t see where to do that

> **[2. Configure Keycloak — Open OnDemand 1.4.9 documentation](https://osc.github.io/ood-documentation/release-1.4/authentication/tutorial-oidc-keycloak-rhel7/configure-keycloak-webui.html)**

I did add OnDemand as a client so that part is done. don’t know how to move forward. please help.

---

<div class="post-metadata">

**Author:** ![maflister](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/maflister/32/139_2.png) [@maflister](https://discourse.openondemand.org/u/maflister)\
**Post date:** [August 15, 2025, 1:26pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/2 "2025-08-15T13:26:57Z")

</div>

I just completed an install using those same versions. Try the latest version of the docs and it should work. Feel free to reach out with more questions.

> **[2. Configure Keycloak — Open OnDemand 4.0.0 documentation](https://osc.github.io/ood-documentation/latest/authentication/tutorial-oidc-keycloak-rhel7/configure-keycloak-webui.html)**

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 15, 2025, 1:30pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/3 "2025-08-15T13:30:35Z")

</div>

Hi and welcome @alfredkwentua!

Thank you @maflister! I may not have noticed the link to the documentation is very old. Not sure why/how you got release docs for 1.4, but yea `latest` is your best bet.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 15, 2025, 2:17pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/4 "2025-08-15T14:17:03Z")

</div>

looking and following the latest documentation now.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 15, 2025, 2:22pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/5 "2025-08-15T14:22:49Z")

</div>

Matthew, i am glad to know you have the same setup and got it working.

i would follow the documentation and would gladly reach out if and when stuck.

actually first question is on the “Authentication”

do i have to complete the

{ \*OpenID Connect } step or should i just jump to the

{\* OpenID Connect with KeyCloak on RHEL7 } and just do this part when getting authentication working.

Also did you use the same host for OOD and KeyCloak?

@maflister

---

<div class="post-metadata">

**Author:** ![maflister](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/maflister/32/139_2.png) [@maflister](https://discourse.openondemand.org/u/maflister)\
**Post date:** [August 15, 2025, 5:14pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/6 "2025-08-15T17:14:56Z")

</div>

You should use the “OpenID Connect with KeyCloak on RHEL7” guide for this purpose. Not sure why the OpenID Connect page still exists as its probably redundant now.

We deploy KeyCloak on its own VM since we have several OOD instances and other applications authenticating to the same instance. But our first deployment many years ago had KC and OOD on the same host. If this is the only app that uses KC it is a good solution. Only difference is the hostname and port in the different config files.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 15, 2025, 7:37pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/7 "2025-08-15T19:37:55Z")

</div>

thanks for the feedback, this is the only application that will use KC for us. going to try the guide now.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 19, 2025, 3:21am UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/8 "2025-08-19T03:21:36Z")

</div>

@maflister

I completed everything on this page and restarted httpd and still getting the default page is this normal?

[3. Configure OnDemand to authenticate with Keycloak — Open OnDemand 4.0.0 documentation](https://osc.github.io/ood-documentation/latest/authentication/tutorial-oidc-keycloak-rhel7/install_mod_auth_openidc.html#re-generate-main-configuration-using-ood-portal-generator)

also this page seems out of date as i am using keycloak latest version 26.3.2. can i skip this step?  
[4. Add Custom Theme — Open OnDemand 4.0.0 documentation](https://osc.github.io/ood-documentation/latest/authentication/tutorial-oidc-keycloak-rhel7/add-custom-theme.html)

did you complete this step as well?

[5. Configure Keycloak with CILogon — Open OnDemand 4.0.0 documentation](https://osc.github.io/ood-documentation/latest/authentication/tutorial-oidc-keycloak-rhel7/configure-cilogon.html)

---

<div class="post-metadata">

**Author:** ![maflister](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/maflister/32/139_2.png) [@maflister](https://discourse.openondemand.org/u/maflister)\
**Post date:** [August 19, 2025, 6:07pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/9 "2025-08-19T18:07:40Z")

</div>

You can skip the CILogon page unless that is your type of authentication. We use LDAP. You can skip the theme step until everything is working.

I’m not sure what “default page” means. Send a screenshot if possible. If you’re not being prompted for authentication, there is probably a missed step like firewall ports not open, ood-portal-generator not run after change, etc. I am happy to look at config files if you’d like to share those but probably best to confirm if you’re even prompted for authentication.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 19, 2025, 6:36pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/10 "2025-08-19T18:36:34Z")

</div>

not even prompted to authenticate.

this is the default screen i am talking about

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/3/3962b332eb3ad91a5e68050d58368c6fb3bbea48.png)

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 19, 2025, 8:47pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/11 "2025-08-19T20:47:46Z")

</div>

tried to get it talking over https but this is not working. here is the content of my “/etc/ood/config/ood\_portal.yml”

–End of FILE—  
servername: [ausondprd.corp.signaturescience.com](http://ausondprd.corp.signaturescience.com)  
ssl:

- ‘SSLCertificateFile “/etc/pki/tls/certs/ausondprd.corp.signaturescience.com.crt”’
- ‘SSLCertificateKeyFile “/etc/pki/tls/private/ausondprd.corp.signaturescience.com.key”’
- ‘SSLCertificateChainFile “/etc/pki/tls/certs/ausondprd.corp.signaturescience.com.crt”’

but still no https after rebooting Apache

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 20, 2025, 1:36pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/12 "2025-08-20T13:36:22Z")

</div>

@alfredkwentua your issue is not with https, but with authentication. You need to supply the `auth` section of the `ood_portal.yml` file to move forward.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 20, 2025, 2:20pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/13 "2025-08-20T14:20:45Z")

</div>

in following the direction this is what i have in my “ood\_portal.yml”

auth:

- ‘AuthType openid-connect’
- ‘Require valid-user’

logout\_uri: ‘/oidc’

logout\_redirect: ‘/oidc?logout=https%3A%2F%[2Fausondprd.corp.signaturescience.com](http://2Fausondprd.corp.signaturescience.com)’

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 20, 2025, 2:32pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/14 "2025-08-20T14:32:32Z")

</div>

here is my “auth\_openidc.conf”

OIDCProviderMetadataURL [http://ausondprd.corp.signaturescience.com:8080/realms/ondemand/.well-known/openid-configuration](http://ausondprd.corp.signaturescience.com:8080/realms/ondemand/.well-known/openid-configuration)  
OIDCClientID “[ausondprd.corp.signaturescience.com](http://ausondprd.corp.signaturescience.com)”  
OIDCClientSecret “1111111-1111-1111-1111-111111111111”  
OIDCRedirectURI [http://ausondprd.corp.signaturescience.com](http://ausondprd.corp.signaturescience.com)  
OIDCCryptoPassphrase “4444444444444444444444444444444444444444”

OIDCSessionInactivityTimeout 28800  
OIDCSessionMaxDuration 28800

OIDCRemoteUserClaim preferred\_username

OIDCPassClaimsAs environment

OIDCStripCookies mod\_auth\_openidc\_session mod\_auth\_openidc\_session\_chunks mod\_auth\_openidc\_session\_0 mod\_auth\_openidc\_session\_1

NOTE: the Secret and CryptoPass is changed following the directions from the install guide.

@jeff.ohrstrom my keycloak is at [ausondprd.corp.signaturescience.com:8080](http://ausondprd.corp.signaturescience.com:8080)

and my ood is on [ausondprd.corp.signaturescience.com](http://ausondprd.corp.signaturescience.com)

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 20, 2025, 4:04pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/15 "2025-08-20T16:04:53Z")

</div>

OK - so when you bounce httpd are there errors or similar in the unit file’s output?

Your configuration appears to be OK - so now we need to track down why it’s not generating the correct `.conf` file.

What you’ve given is not formmatted here on this page, but I’d ask that you’re sure it is formatted correctly in the YAML file itself.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 20, 2025, 4:30pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/16 "2025-08-20T16:30:43Z")

</div>

The format of the YAML file might be my issue here is an image

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/f/fd987e49b877a202165616bb4bc41629351285d2.png)

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/5/585e08f919410c95953f285f98fa86173beef4e3.png)

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 20, 2025, 4:34pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/17 "2025-08-20T16:34:50Z")

</div>

At a glance it looks OK. Are there errors in the systemd/journalctl output when you bounce httpd? Also I just want to check the `ood-portal.conf` and see what it looks like.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 20, 2025, 6:11pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/18 "2025-08-20T18:11:15Z")

</div>

there are no errors it looks fine.

also the file on my system unlike the directions is located at /etc/httpd/conf.d/od-portal.conf

/etc/httpd/conf.d/auth\_openidc.conf

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 20, 2025, 6:32pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/19 "2025-08-20T18:32:46Z")

</div>

🤦‍♂️ Actually now I’m thinking that page may be cached on your browser. Can you try in a different browser and/or private mode?

That said - I would still like to confirm the content of `ood-portal.conf` to be sure that it has the correct vhost in it and not the conf file that points to this public page.

---

<div class="post-metadata">

**Author:** ![alfredkwentua](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/alfredkwentua/32/2919_2.png) [@alfredkwentua](https://discourse.openondemand.org/u/alfredkwentua)\
**Post date:** [August 20, 2025, 7:09pm UTC](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450/20 "2025-08-20T19:09:19Z")

</div>

you are correct. it was cached. i now have to fix my keycloak as i cant login.

[Next page](https://discourse.openondemand.org/t/new-installation-on-rocky-linux-9-6-using-keycloak-for-auth/4450.md?page=2)
