<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Qlik Sense for Windows: How to set up Keycloak as SAML Identity Provider in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/ta-p/1776626</link>
    <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;This is a quick guide on how to set up SAML authentication in Qlik Sense for Windows using Keycloak as the Identity Provider.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; February 2020 and later&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In Keycloak, navigate to &lt;STRONG&gt;General&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Realm Settings&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;download the IdP metadata&lt;/STRONG&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1671765374463.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96801i3B59FA26D7D2D1B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1671765374463.png" alt="Damien_Villaret_0-1671765374463.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In Qlik Sense Enterprise on Windows, set up a new virtual proxy:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1611302885434.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47641i2D581F1E6AA2341C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1611302885434.png" alt="Damien_Villaret_1-1611302885434.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML Host URI:&lt;/FONT&gt; The Qlik Sense server DNS name accessed by end users&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML Entity ID:&lt;/FONT&gt; Any string, but should match the Client ID in the Keycloak configuration.&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML attribute for user ID:&lt;/FONT&gt; this should be the attribute containing the value that will be used as the user ID in Qlik Sense. Those attributes are set in “Mappers” in the Keycloak configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In Keycloak, set up a test user:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1671765491608.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96802i93594A3BF629E8D3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1671765491608.png" alt="Damien_Villaret_1-1671765491608.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Save&lt;/STRONG&gt;&amp;nbsp;and go to &lt;STRONG&gt;Credentials&lt;/STRONG&gt;&amp;nbsp;to set the password&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_2-1671765595894.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96805iF20A2EAA4D802F09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_2-1671765595894.png" alt="Damien_Villaret_2-1671765595894.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In Keycloak, add a new Client.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; &lt;FONT face="courier new,courier"&gt;Client ID&lt;/FONT&gt; needs to be the&lt;FONT face="courier new,courier"&gt; Entity ID&lt;/FONT&gt; set in Qlik Sense in step 2.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_3-1671765686271.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96806iF622E128C1EE47D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_3-1671765686271.png" alt="Damien_Villaret_3-1671765686271.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In the &lt;STRONG&gt;Client settings&lt;/STRONG&gt; locate &lt;STRONG&gt;Signature and encryption&lt;/STRONG&gt; and make sure that &lt;STRONG&gt;Sign Assertions&lt;/STRONG&gt; is enabled. &lt;STRONG&gt;Sign Documents&lt;/STRONG&gt;&amp;nbsp;should be disabled (if it remains enabled, the implementation will still function, but Qlik Sense does not use&amp;nbsp;&lt;EM&gt;Sign Documents&amp;nbsp;&lt;/EM&gt;and will ignore it).&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_4-1671765741225.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96807i96CF773938F29CAA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_4-1671765741225.jpeg" alt="Damien_Villaret_4-1671765741225.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Switch to the&amp;nbsp;&lt;STRONG&gt;Keys&amp;nbsp;&lt;/STRONG&gt;tab and disable&amp;nbsp;&lt;STRONG&gt;Client Signature Required&lt;/STRONG&gt;. In order to enable this feature, some extra steps are needed, see at the end of this article (&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Optional Steps - Client Signature&lt;/FONT&gt;&lt;/STRONG&gt;) if you wish to enable the feature.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_5-1671767133315.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96810iE8DF065CFA800BED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_5-1671767133315.png" alt="Damien_Villaret_5-1671767133315.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Switch to the &lt;STRONG&gt;Advanced&amp;nbsp;&lt;/STRONG&gt;tab and&amp;nbsp;set the &lt;STRONG&gt;Assertion Consumer Service POST Binding URL&lt;/STRONG&gt;. &lt;BR /&gt;&lt;BR /&gt;It should be &lt;FONT face="courier new,courier"&gt;https://{SAML&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;Host URI}/{virtual proxy prefix}/samlauthn/&lt;/FONT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Make sure not to forget the ending slash after &lt;FONT face="courier new,courier"&gt;samlauthn&lt;/FONT&gt;, otherwise the authentication will fail.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1671777877902.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96812i8D2ABE57491501CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1671777877902.png" alt="Damien_Villaret_0-1671777877902.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;The last step is to add the X500 email User Property as we are using the attribute "email" as the User ID in the Qlik Sense virtual proxy settings.&lt;BR /&gt;&lt;BR /&gt;Under "Client Scopes", click on the name of client scope that has the description "Dedicated scope and mappers for this client", in the below screenshot the name is QSKeycloak-dedicted.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1671778247451.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96813i19C8F35272669434/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1671778247451.png" alt="Damien_Villaret_1-1671778247451.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Choose &lt;STRONG&gt;Add predefined mapper&lt;/STRONG&gt; and choose&lt;STRONG&gt; X500 email&lt;/STRONG&gt; then click &lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_2-1671778324089.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96814i627E733749F66589/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_2-1671778324089.png" alt="Damien_Villaret_2-1671778324089.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_3-1671778390270.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96815i1DB74F13F2D17CD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_3-1671778390270.png" alt="Damien_Villaret_3-1671778390270.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Everything is now set up and operational.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Optional steps&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H5&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Client Signature&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;P&gt;In order to enable &lt;STRONG&gt;Client Signature Required&lt;/STRONG&gt;, which means that Keycloak will check the signature on the &lt;STRONG&gt;SAMLAuthnRequest&lt;/STRONG&gt; sent from Qlik Sense, the Qlik Sense certificate needs to be added in the Keycloak client configuration.&lt;/P&gt;
&lt;P&gt;The certificate&amp;nbsp;can be copied directly from the SP Metadata downloaded from the Qlik Sense Management Console.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the Management Console and navigate to&amp;nbsp;&lt;STRONG&gt;Virtual Proxies&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Open your Virtual proxy set up for&amp;nbsp;&lt;STRONG&gt;Keycloak&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Download SP metadata&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315136765.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47656i588836BF275589DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1611315136765.png" alt="Damien_Villaret_0-1611315136765.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;It will look like this:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315433412.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47657i1E90F994E07FD9FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1611315433412.png" alt="Damien_Villaret_0-1611315433412.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Copy it to a new file, and add:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;[content]&lt;BR /&gt;-----END CERTIFICATE-----&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;then save it as a &lt;FONT face="courier new,courier"&gt;.pem&lt;/FONT&gt; file.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315759828.png" style="width: 468px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47659i26EE0E71219E6BAD/image-dimensions/468x254?v=v2" width="468" height="254" role="button" title="Damien_Villaret_0-1611315759828.png" alt="Damien_Villaret_0-1611315759828.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Import the certificate as PEM in Keycloak by clicking&lt;STRONG&gt; Client signature required&lt;/STRONG&gt; under &lt;STRONG&gt;Keys&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_4-1671779118041.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96818i081C91E86C4BDC9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_4-1671779118041.png" alt="Damien_Villaret_4-1671779118041.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_5-1671779634110.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96819i94091FD48BBD37CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_5-1671779634110.png" alt="Damien_Villaret_5-1671779634110.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;H5&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;SAML Assertion Encryption&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;FONT color="#000000"&gt;The SAML assertion can be encrypted by checking the option in Keycloak in &lt;STRONG&gt;Keys&lt;/STRONG&gt;&amp;nbsp;in the same way as for &lt;STRONG&gt;Client Signature required&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_6-1671779818853.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96820i27764825FDD1AC55/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_6-1671779818853.png" alt="Damien_Villaret_6-1671779818853.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;The certificate can be extracted in the same way that it is done when enabling &lt;STRONG&gt;Client signature required&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 29 Dec 2022 10:02:24 GMT</pubDate>
    <dc:creator>Damien_V</dc:creator>
    <dc:date>2022-12-29T10:02:24Z</dc:date>
    <item>
      <title>Qlik Sense for Windows: How to set up Keycloak as SAML Identity Provider</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/ta-p/1776626</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;This is a quick guide on how to set up SAML authentication in Qlik Sense for Windows using Keycloak as the Identity Provider.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Environment:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;LI-PRODUCT title="Qlik Sense Enterprise on Windows" id="qlikSenseEnterpriseWindows"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; February 2020 and later&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In Keycloak, navigate to &lt;STRONG&gt;General&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Realm Settings&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;download the IdP metadata&lt;/STRONG&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1671765374463.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96801i3B59FA26D7D2D1B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1671765374463.png" alt="Damien_Villaret_0-1671765374463.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In Qlik Sense Enterprise on Windows, set up a new virtual proxy:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1611302885434.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47641i2D581F1E6AA2341C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1611302885434.png" alt="Damien_Villaret_1-1611302885434.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML Host URI:&lt;/FONT&gt; The Qlik Sense server DNS name accessed by end users&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML Entity ID:&lt;/FONT&gt; Any string, but should match the Client ID in the Keycloak configuration.&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SAML attribute for user ID:&lt;/FONT&gt; this should be the attribute containing the value that will be used as the user ID in Qlik Sense. Those attributes are set in “Mappers” in the Keycloak configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;In Keycloak, set up a test user:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1671765491608.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96802i93594A3BF629E8D3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1671765491608.png" alt="Damien_Villaret_1-1671765491608.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Click &lt;STRONG&gt;Save&lt;/STRONG&gt;&amp;nbsp;and go to &lt;STRONG&gt;Credentials&lt;/STRONG&gt;&amp;nbsp;to set the password&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_2-1671765595894.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96805iF20A2EAA4D802F09/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_2-1671765595894.png" alt="Damien_Villaret_2-1671765595894.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In Keycloak, add a new Client.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; &lt;FONT face="courier new,courier"&gt;Client ID&lt;/FONT&gt; needs to be the&lt;FONT face="courier new,courier"&gt; Entity ID&lt;/FONT&gt; set in Qlik Sense in step 2.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_3-1671765686271.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96806iF622E128C1EE47D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_3-1671765686271.png" alt="Damien_Villaret_3-1671765686271.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;In the &lt;STRONG&gt;Client settings&lt;/STRONG&gt; locate &lt;STRONG&gt;Signature and encryption&lt;/STRONG&gt; and make sure that &lt;STRONG&gt;Sign Assertions&lt;/STRONG&gt; is enabled. &lt;STRONG&gt;Sign Documents&lt;/STRONG&gt;&amp;nbsp;should be disabled (if it remains enabled, the implementation will still function, but Qlik Sense does not use&amp;nbsp;&lt;EM&gt;Sign Documents&amp;nbsp;&lt;/EM&gt;and will ignore it).&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_4-1671765741225.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96807i96CF773938F29CAA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_4-1671765741225.jpeg" alt="Damien_Villaret_4-1671765741225.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Switch to the&amp;nbsp;&lt;STRONG&gt;Keys&amp;nbsp;&lt;/STRONG&gt;tab and disable&amp;nbsp;&lt;STRONG&gt;Client Signature Required&lt;/STRONG&gt;. In order to enable this feature, some extra steps are needed, see at the end of this article (&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Optional Steps - Client Signature&lt;/FONT&gt;&lt;/STRONG&gt;) if you wish to enable the feature.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_5-1671767133315.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96810iE8DF065CFA800BED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_5-1671767133315.png" alt="Damien_Villaret_5-1671767133315.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Switch to the &lt;STRONG&gt;Advanced&amp;nbsp;&lt;/STRONG&gt;tab and&amp;nbsp;set the &lt;STRONG&gt;Assertion Consumer Service POST Binding URL&lt;/STRONG&gt;. &lt;BR /&gt;&lt;BR /&gt;It should be &lt;FONT face="courier new,courier"&gt;https://{SAML&lt;/FONT&gt;&lt;SPAN&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;Host URI}/{virtual proxy prefix}/samlauthn/&lt;/FONT&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Make sure not to forget the ending slash after &lt;FONT face="courier new,courier"&gt;samlauthn&lt;/FONT&gt;, otherwise the authentication will fail.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1671777877902.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96812i8D2ABE57491501CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1671777877902.png" alt="Damien_Villaret_0-1671777877902.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;The last step is to add the X500 email User Property as we are using the attribute "email" as the User ID in the Qlik Sense virtual proxy settings.&lt;BR /&gt;&lt;BR /&gt;Under "Client Scopes", click on the name of client scope that has the description "Dedicated scope and mappers for this client", in the below screenshot the name is QSKeycloak-dedicted.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_1-1671778247451.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96813i19C8F35272669434/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_1-1671778247451.png" alt="Damien_Villaret_1-1671778247451.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Choose &lt;STRONG&gt;Add predefined mapper&lt;/STRONG&gt; and choose&lt;STRONG&gt; X500 email&lt;/STRONG&gt; then click &lt;STRONG&gt;Add&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_2-1671778324089.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96814i627E733749F66589/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_2-1671778324089.png" alt="Damien_Villaret_2-1671778324089.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_3-1671778390270.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96815i1DB74F13F2D17CD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_3-1671778390270.png" alt="Damien_Villaret_3-1671778390270.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Everything is now set up and operational.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Optional steps&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H5&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Client Signature&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;P&gt;In order to enable &lt;STRONG&gt;Client Signature Required&lt;/STRONG&gt;, which means that Keycloak will check the signature on the &lt;STRONG&gt;SAMLAuthnRequest&lt;/STRONG&gt; sent from Qlik Sense, the Qlik Sense certificate needs to be added in the Keycloak client configuration.&lt;/P&gt;
&lt;P&gt;The certificate&amp;nbsp;can be copied directly from the SP Metadata downloaded from the Qlik Sense Management Console.&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open the Management Console and navigate to&amp;nbsp;&lt;STRONG&gt;Virtual Proxies&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Open your Virtual proxy set up for&amp;nbsp;&lt;STRONG&gt;Keycloak&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Download SP metadata&lt;/STRONG&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315136765.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47656i588836BF275589DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1611315136765.png" alt="Damien_Villaret_0-1611315136765.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;It will look like this:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315433412.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47657i1E90F994E07FD9FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_0-1611315433412.png" alt="Damien_Villaret_0-1611315433412.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Copy it to a new file, and add:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;-----BEGIN CERTIFICATE-----&lt;BR /&gt;[content]&lt;BR /&gt;-----END CERTIFICATE-----&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;then save it as a &lt;FONT face="courier new,courier"&gt;.pem&lt;/FONT&gt; file.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_0-1611315759828.png" style="width: 468px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/47659i26EE0E71219E6BAD/image-dimensions/468x254?v=v2" width="468" height="254" role="button" title="Damien_Villaret_0-1611315759828.png" alt="Damien_Villaret_0-1611315759828.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Import the certificate as PEM in Keycloak by clicking&lt;STRONG&gt; Client signature required&lt;/STRONG&gt; under &lt;STRONG&gt;Keys&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_4-1671779118041.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96818i081C91E86C4BDC9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_4-1671779118041.png" alt="Damien_Villaret_4-1671779118041.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_5-1671779634110.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96819i94091FD48BBD37CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_5-1671779634110.png" alt="Damien_Villaret_5-1671779634110.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BR /&gt;
&lt;H5&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;SAML Assertion Encryption&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H5&gt;
&lt;FONT color="#000000"&gt;The SAML assertion can be encrypted by checking the option in Keycloak in &lt;STRONG&gt;Keys&lt;/STRONG&gt;&amp;nbsp;in the same way as for &lt;STRONG&gt;Client Signature required&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Damien_Villaret_6-1671779818853.png" style="width: 999px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/96820i27764825FDD1AC55/image-size/large?v=v2&amp;amp;px=999" role="button" title="Damien_Villaret_6-1671779818853.png" alt="Damien_Villaret_6-1671779818853.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;The certificate can be extracted in the same way that it is done when enabling &lt;STRONG&gt;Client signature required&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 29 Dec 2022 10:02:24 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/ta-p/1776626</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2022-12-29T10:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense for Windows: How to set up Keycloak as SAML Identity Provider</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/tac-p/2014691#M7973</link>
      <description>&lt;P&gt;Possible to do an update for this? New Keycloak UI and fields are different from these screenshots.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Dec 2022 09:15:03 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/tac-p/2014691#M7973</guid>
      <dc:creator>edhuangry</dc:creator>
      <dc:date>2022-12-09T09:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Qlik Sense for Windows: How to set up Keycloak as SAML Identity Provider</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/tac-p/2019558#M8076</link>
      <description>&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/210013"&gt;@edhuangry&lt;/a&gt;&amp;nbsp;Thank you for your feedback.&lt;/P&gt;
&lt;P&gt;The article has now been updated with screenshots from the current latest Keycloak (version 20)&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 07:20:15 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-for-Windows-How-to-set-up-Keycloak-as-SAML-Identity/tac-p/2019558#M8076</guid>
      <dc:creator>Damien_V</dc:creator>
      <dc:date>2022-12-23T07:20:15Z</dc:date>
    </item>
  </channel>
</rss>

