[midPoint] OIDC authentication - Matching users by an attribute other than 'name'

Lothar Haeger lothar.haeger at is4it.de
Thu Jun 25 12:40:12 CEST 2026


> Am 25.06.2026 um 10:55 schrieb Markus Calmius via midPoint <midpoint at lists.evolveum.com>:
> 
> our keycloak config contains this:
> <nameOfUsernameAttribute>email</nameOfUsernameAttribute>

I ran into the same question as Gianluca and my understanding is that <nameOfUsernameAttribute>email</nameOfUsernameAttribute> means: "read the email claim from Keycloak, then look up the midPoint user whose name equals that email." If name isn't the email, it matches nobody. It does not search against an "email" property in midPoint.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/42e278ce/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3779 bytes
Desc: not available
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20260625/42e278ce/attachment.bin>


More information about the midPoint mailing list