Problem: System Diagnosis Reports Missing Certificate with External TLS Termination

Problem

The Univention System Diagnosis may report a missing certificate during the file permissions check when Keycloak SSO uses external TLS termination:

File '/etc/univention/ssl/sso.univention.de' does not exist.

This can occur in environments where the public Keycloak SSO endpoint is provided through an upstream reverse proxy, for example:

https://sso.univention.de/

TLS termination takes place on the reverse proxy, which uses its own TLS certificate, such as a Let’s Encrypt certificate. Requests are then forwarded internally via HTTP to the UCS SSO service:

ucs-sso-ng.univention.local

Root Cause

The behavior originates from the System Diagnosis plugin:

management/univention-management-console-module-diagnostic/umc/python/diagnostic/plugins/31_file_permissions.py

The plugin determines the public SSO hostname from:

ucs/server/sso/uri

If keycloak/apache2/ssl/key is not configured, /etc/univention/ssl/ is used as the expected location of the SSO certificate.

On a UCS Primary, the diagnostic check expects the corresponding certificate path to exist:

if sso_domain != configRegistry.get('ldap/master') and sso_domain not in backup_fqdns:
    check_file_args.append(
        cf_type(sso_cert_path, 'root', 'DC Backup Hosts', 0o750, must_exist=is_primary),
    )

However, the check does not consider:

keycloak/server/sso/certificate/generation=false

This setting explicitly disables local SSO certificate generation. Therefore, in a setup where TLS termination is handled exclusively by an upstream reverse proxy, the absence of:

/etc/univention/ssl/<SSO-FQDN>

is intentional.

The diagnostic check nevertheless requires the certificate path on a UCS Primary and consequently reports a misleading File does not exist warning.

This issue is tracked in Bug 59949


Investigation

The UCS Primary may have a configuration similar to:

keycloak/server/sso/certificate/generation: false
keycloak/server/sso/fqdn: sso.univention.de
ucs/server/sso/fqdn: ucs-sso.univention.local
ucs/server/sso/uri: https://sso.univention.de/

At the same time, the following UCR variable is not set:

keycloak/apache2/ssl/key

The SSO service itself works correctly. The warning is caused by the System Diagnosis expecting a local certificate even though certificate generation on the UCS system has explicitly been disabled.


Solution

If TLS termination is handled exclusively by an upstream reverse proxy and the following setting is intentional:

keycloak/server/sso/certificate/generation=false

the missing certificate warning from the System Diagnosis can be ignored.

Verify that the public SSO endpoint is accessible via HTTPS and that the upstream reverse proxy provides the intended TLS certificate.

It is not necessary to create a local certificate under:

/etc/univention/ssl/<SSO-FQDN>

solely to satisfy the diagnostic check.

The diagnostic check should skip the local SSO certificate validation when certificate generation has explicitly been disabled. A possible adjustment is:

--- management/univention-management-console-module-diagnostic/umc/python/diagnostic/plugins/31_file_permissions.py
+++ management/univention-management-console-module-diagnostic/umc/python/diagnostic/plugins/31_file_permissions.py
@@ -143,1 +143,3 @@
-    if sso_domain != configRegistry.get('ldap/master') and sso_domain not in backup_fqdns:
+    if (sso_domain != configRegistry.get('ldap/master') and
+        sso_domain not in backup_fqdns and
+        configRegistry.get('keycloak/server/sso/certificate/generation') != 'false'):

Until the diagnostic check takes this configuration into account, the warning does not indicate a functional problem with Keycloak SSO when external TLS termination is configured correctly.