# User federation with Google secure ldaps - no luck

**URL:** <https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762>\
**Category:** Configuring the server\
**Tags:** ldap\
**Created:** [October 27, 2021, 4:42pm UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762 "2021-10-27T16:42:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![illoinventore](https://avatars.discourse-cdn.com/v4/letter/i/9f8e36/32.png) [@illoinventore](https://forum.keycloak.org/u/illoinventore)\
**Post date:** [October 27, 2021, 4:42pm UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762/1 "2021-10-27T16:42:45Z")

</div>

I’m using a Mac, latest version of Keycloak in standalone and I installed java jdk 8u66.  
I’m trying to implement Google secure ldap for user federation in Keycloak. I enabled LDAP service in the Google admin and downloaded the certificate (crt) and private key.

Then I added the certificate and private key in the Java cacerts keystore as PKCS #8. I also to tried to add the private key to the crt file and add the crt file to java cacerts keystore. Cacert is located: home/jre/lib/security/cacerts.

I also tried to my make own java keystore and adapted the standalone.xml file but no luck. … can’t find path… was the error in the server.log.

My settings (in a tenant - not in master):

The connection url: ldaps://ldap.google.com  
edit mode: read only  
users DN: dc=xxxx,dc=xx (no filter applied)  
search scope: subtree  
Bind type:  
When I set it to ‘none’ I get error: “error during sync of users” in server log:  
error code 50: insufficient access rights  
Uncaught server error: LDAP query failed.

When I enter a user:  
User + @domain = LDAP: error 50 - Not authorized to authenticate password  
User without @domain = error 49 - Incorrect password  
User in DN = uid or cn=xxxx, ou=xxxx - error 50 - Not authorized to authenticate password

My question is: what is the correct setting for bind type? Add both the crt and private key as PKCS #8 in the java cacerts keystore is correct? I also tried with a new certificate.

If anyone has an idea what is wrong? Thanks!

---

<div class="post-metadata">

**Author:** ![Badr.me](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Badr.me](https://forum.keycloak.org/u/Badr.me)\
**Post date:** [April 20, 2022, 11:23am UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762/2 "2022-04-20T11:23:33Z")

</div>

> [@illoinventore](#):
>
> is:

Hi @illoinventore ,  
i don’t know if you fix your problem, i have the same, any help 🙏

---

<div class="post-metadata">

**Author:** ![mighty44](https://avatars.discourse-cdn.com/v4/letter/m/34f0e0/32.png) [@mighty44](https://forum.keycloak.org/u/mighty44)\
**Post date:** [October 25, 2022, 2:53pm UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762/3 "2022-10-25T14:53:18Z")

</div>

Does any one have a solution for this?

---

<div class="post-metadata">

**Author:** ![neferin12](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/neferin12/32/7365_2.png) [@neferin12](https://forum.keycloak.org/u/neferin12)\
**Post date:** [January 6, 2023, 7:06pm UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762/4 "2023-01-06T19:06:50Z")

</div>

I found a solution for this: You can use stunnel to create an endpoint that keycloak can use without the certificate (or any authentication for that matter, so keep your firewall tightly closed for stunnel’s port).

More Details are on the bottom of this page:

> **[4. Connect LDAP clients to the Secure LDAP service - Google Workspace Admin Help](https://support.google.com/a/answer/9089736)**
>
> Use the instructions in this article to connect your LDAP client to the Secure LDAP service.
> IMPORTANT: Be sure to read your vendor documentation The details in this article for connecti

---

<div class="post-metadata">

**Author:** ![Aicha](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@Aicha](https://forum.keycloak.org/u/Aicha)\
**Post date:** [April 25, 2024, 8:59am UTC](https://forum.keycloak.org/t/user-federation-with-google-secure-ldaps-no-luck/11762/6 "2024-04-25T08:59:33Z")

</div>

Keycloak supports authentication (the certificate needs to be added to the cacert Java file or to Keycloak’s truststores), but I encountered the same issue as @illoinventore and @Badr.me . Why doesn’t Keycloak support synchronization with Google LDAPS like active directory?
