Using Keycloak as idP

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Using Keycloak as idP

L1 Bithead

Has anyone succeeded in using Keycloak as idP with Globalprotect?

We're having issues with the windows clients receiving "You are already logged in" while trying to log in, which also make the gp app hang. The GP app for macOS never experience this.

We've also experienced with openconnect on Ubuntu (since Palo's own ubuntu GP app does not work at all for us) using a wrapper handling the saml auth. This also works well with Keycloak.


Cyber Elite
Cyber Elite


Just looking into this briefly, you probably want to ask this on a keycloak forum as well if you haven't to gain some additional traction. Since Keycloak is the one servicing this response when encountering an already established session, GlobalProtect doesn't know how to handle the response.

L1 Bithead

As silly as this seems, don't use Enter key, use mouse click to submit the forms.

The fix is to use the "TRANSLATEENTERKEY" option (modify registry or at install).

Alternatively, use system browser instead of the embedded one.


I made it work once in Ubuntu with "gp-saml-gui", but it seems to break now for different reasons.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!