# Import LDAP certificate into keycloak running on kubernetes

**URL:** <https://forum.keycloak.org/t/import-ldap-certificate-into-keycloak-running-on-kubernetes/13840>\
**Category:** Getting advice\
**Tags:** ldap\
**Created:** [February 24, 2022, 3:59am UTC](https://forum.keycloak.org/t/import-ldap-certificate-into-keycloak-running-on-kubernetes/13840 "2022-02-24T03:59:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vinayus](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/vinayus/32/2079_2.png) [@vinayus](https://forum.keycloak.org/u/vinayus)\
**Post date:** [February 24, 2022, 3:59am UTC](https://forum.keycloak.org/t/import-ldap-certificate-into-keycloak-running-on-kubernetes/13840/1 "2022-02-24T03:59:41Z")

</div>

Hello, i’m trying to configure my ldap server under with secure connection for user federation. Test connectivity passes but test authentication fails.  
The keycloak is running as a pod in kubernetes using default public docker image.

In server logs, I see that certificate is not recognized because certificate is not CA(known) signed. It is a self-signed certificate. Would love to have some suggestion to solve this issue in kubernetes without having to include certificates as part of docker image.

Is there a way to handle via init container or secrets? Or any recommended approach is appreciated

Kindly suggest

---

<div class="post-metadata">

**Author:** ![reisman234](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/reisman234/32/6843_2.png) [@reisman234](https://forum.keycloak.org/u/reisman234)\
**Post date:** [October 20, 2022, 11:48am UTC](https://forum.keycloak.org/t/import-ldap-certificate-into-keycloak-running-on-kubernetes/13840/2 "2022-10-20T11:48:19Z")

</div>

Hello, I’m also had confusion with this topic.

Our LDAP Server also has a self-sign certificate, signed by the IT with a internal CA. To add the CA, I created a cacert-store file with keytool and added it in Keycloak with required parameter at server start ([Configure a Truststore](https://www.keycloak.org/server/keycloak-truststore)).  
What I didn’t know at first, these parameters overwrite the default used cacert-store, which in my case leads to an untrusted smtp server error, but that one is signed by a well-known provider.

To work around that, I created my own Container and added the CA in the global PKI store (for keycloak:19.0.2 add ca in `/usr/share/pki/ca-trust-source/anchors/` and exec `update-ca-cert`)

So I’m also interested in a simple and recommended approach to just add CAs to the default cacert-store used by keycloak

regards  
reisman

---

<div class="post-metadata">

**Author:** ![BadgerOps](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/badgerops/32/9582_2.png) [@BadgerOps](https://forum.keycloak.org/u/BadgerOps)\
**Post date:** [February 7, 2024, 1:47pm UTC](https://forum.keycloak.org/t/import-ldap-certificate-into-keycloak-running-on-kubernetes/13840/3 "2024-02-07T13:47:56Z")

</div>

Hey all, I noticed this never got a clear answer, and I recently had to do this too.

Referencing [All provider configuration - Keycloak](https://www.keycloak.org/server/all-provider-config#_truststore) and [keycloak/docs/documentation/release\_notes/topics/24\_0\_0.adoc at main · keycloak/keycloak · GitHub](https://github.com/keycloak/keycloak/blob/main/docs/documentation/release_notes/topics/24_0_0.adoc#keycloak-cr-truststores) I did the following:

Create a new keystore with the LDAPS certificate chain:

```auto
keytool -import -keystore ldaps.jks -file ldaps-chain.pem

```

Add a Kubernetes secret `ldaps-keystore` for example, containing that keystore, then in your deployment add a `volume` and `volumeMount`

```yaml
spec:
  volumes:
    - name: ldaps-keystore
      secret:
        secretName: <secret-name>
        defaultMode: 420

--- <volumeMount> ---

volumeMounts:
  - name: ldaps-keystore
    readOnly: true
    mountPath: /mnt/truststore

```

then add the correct env variables:

```auto
env:
  - name: KC_SPI_TRUSTSTORE_FILE_FILE
    value: /mnt/truststore/ldaps.jks
  - name: KC_SPI_TRUSTSTORE_FILE_PASSWORD
    value: <keystore password> (you can make this a secretRef, for clarity I'm just doing this)

```

This will then make the keystore contents available to your Keycloak instance in Kubernetes.

If you’re using the operator, then you’ll want to reference [keycloak/docs/documentation/release\_notes/topics/24\_0\_0.adoc at main · keycloak/keycloak · GitHub](https://github.com/keycloak/keycloak/blob/main/docs/documentation/release_notes/topics/24_0_0.adoc#keycloak-cr-truststores)
