Migration procedure

3. Migration procedure#

Keycloak replaces SimpleSAMLphp and the app OpenID Connect Provider as SAML IDP and OIDC provider in a future release of UCS. This section provides a general overview of the migration steps and the required considerations to make before migrating. This migration guide focuses on exclusively on UCS 5.0.

Before the migration can take place, please keep in mind:

  • You can migrate services step by step.

  • The migration is a manual process.

  • Create a backup of the current single sign-on configuration of your services before the migration, so that you can rollback in case a problem occurs.

  • SimpleSAMLphp and OpenID Connect Provider still work even if you installed Keycloak.

  • After you migrated a service, existing user sessions become invalid. Users have to sign in to the migrated service again.

The migration of one or multiple services always includes at least the following steps: