Skip to content

Identity & Access with Open Source and Enterprise Platforms

Identity projects rarely start with the product. They usually start with too many local accounts, separated user stores, missing single sign-on, manual provisioning, inconsistent groups and unclear responsibilities.

ForgeOne therefore separates identity source, directory, identity provider, applications and infrastructure. This creates a target model for SSO, federation, Linux identity, directory services and access policies.

ForgeOne designs Identity & Access architectures with Keycloak, Red Hat build of Keycloak, FreeIPA, Red Hat Identity Management and Univention Corporate Server.

Orientation

ForgeOne connects customer requirements, architecture roles, products and target models into a practical identity roadmap.

Typical problems

Why identity projects start.

Architecture model

Identity source, provider and target systems.

Products

The five product roles.

Typical identity problems

Users are managed separately across systems, passwords and accounts differ, joiner/mover/leaver processes remain manual and local server accounts grow without control.

Applications also support different identity protocols, environments span Linux, Windows and cloud, SSO is missing and the separation between identity store and identity provider is unclear.

Directory vs. identity provider

The important decisions come from roles, not product lists.

Keycloak / Red Hat build of Keycloak

Identity provider for authentication, SSO, federation, OIDC, OAuth 2.0, SAML, MFA and application access.

FreeIPA / Red Hat Identity Management

Directory and Linux identity management for users, groups, hosts, Kerberos, LDAP, DNS, HBAC, sudo policies and SSSD.

Univention Corporate Server

Broader identity and directory platform for central organization, domain services, heterogeneous environments, application integration and SSO.

Products in this group

The products are deliberately not interchangeable: they take different roles in identity architectures.

Keycloak

Open-source identity provider for SSO, federation and application authentication.

Red Hat build of Keycloak

Enterprise Keycloak in the Red Hat lifecycle and support context.

FreeIPA

Open-source Linux identity management with Kerberos, LDAP, HBAC, sudo and SSSD.

Red Hat Identity Management

Enterprise Linux identity management for RHEL/Linux infrastructures.

Univention Corporate Server

Central identity and directory platform for heterogeneous IT and integrated applications.

Common architecture models

ForgeOne does not generally replace existing landscapes, but integrates and modernizes step by step.

FreeIPA + Keycloak

Open-source Linux identity plus application SSO with clear role separation.

Red Hat IdM + Red Hat build of Keycloak

Enterprise Red Hat identity architecture: IdM for Linux identities, RHBK for application authentication.

Univention Corporate Server

Broader central platform for directory, domain, application integration and Keycloak based SSO.

Integrate existing Active Directory

AD remains an integration scenario, not a ForgeOne product: LDAP federation, coexistence, SSO and gradual modernization.

What ForgeOne delivers

From assessment to operations, the focus is architecture, migration, integration and secure operability.

Analysis & Assessment

Capture identity sources, protocols, risks, lifecycle and migration paths.

Solution Design & Planning

Plan target architecture, role model, federation, policies and operating processes.

Implementation & Migration

Implement identity stores, providers, clients, federation and migration in a controlled way.

Automation & Integration

Automate enrollment, policies, client configuration and operating processes.

Support & SLA

Secure updates, monitoring, backup, troubleshooting and continuous improvement.

Identity sits between security, Linux, platform operations and collaboration.

Security & Identity

Architecture problem around SSO, directory, access and identity lifecycle.

Linux & Infrastructure

Linux identity, SSSD, enrollment and central server authentication.

Container & Platform Engineering

Keycloak and RHBK in Kubernetes/OpenShift architectures.

Collaboration

SSO for OpenProject, XWiki, grommunio, Nextcloud and other platforms.

FAQ

Are the five products interchangeable?Show answer Action: Open answer

No. Keycloak/RHBK are identity providers for applications. FreeIPA/Red Hat IdM are directory and Linux identity systems. UCS can be a broader identity/directory platform for heterogeneous environments.

Does existing Active Directory have to be replaced?Show answer Action: Open answer

No. Active Directory can be integrated, federated or modernized step by step. ForgeOne evaluates the right coexistence or migration strategy.

What is the first step?Show answer Action: Open answer

An identity assessment clarifies user sources, protocols, applications, Linux/Windows scope, risks, lifecycle and operating responsibility.

Recommended next step

From the product group, the path leads into assessment, delivery or operations.

Recommended

Clarify current state

Assess environment, risks, maturity and priorities.

Plan delivery

Clarify architecture, migration, integration and operating model.

Structure your identity landscape cleanly

Want to connect users, systems and applications through a central identity architecture? ForgeOne analyzes your existing identity landscape and develops a suitable approach for directory services, SSO and access control.