Lab 01 - OpenLDAP Enterprise Directory
Stand up an authoritative directory: schema, replication, ACLs.
Vendor-neutral fluency across the protocols and policy languages every identity system speaks.
# Track 03 Identity Standards 14 hands-on labs # prepare → do → prove → explain
Each lab is standalone but builds on the last. Capture evidence as you go, and read the track FAQ for the concepts behind them.
Stand up an authoritative directory: schema, replication, ACLs.
Build a Keycloak realm, register clients, issue tokens with OIDC.
Federate a service provider with a SAML IdP - metadata, signing, assertions.
Implement Authorization Code and PKCE - the modern SPA and mobile pattern.
WebAuthn, TOTP and step-up authentication end to end.
Cluster Keycloak, replicate caches, survive a node failure.
Automate joiner-mover-leaver across systems via SCIM 2.0.
Score sign-in signals and act on the risk level.
Understand what is really inside a token - and what can go wrong.
DPoP, PAR, sender-constrained tokens and modern threat mitigations.
Delegated and impersonated identity across service boundaries.
Front-channel and back-channel logout, session revocation, refresh flows.
Migrate role explosion to attribute-based decisions without a rewrite.
Externalise authorisation with Open Policy Agent, tested end to end.
New to Identity Standards? The knowledge-base article explains every concept in plain English before you touch a keyboard.