@silverwizard Keycloak handles OIDC, SAML etc. which is the SSO bit. If you don't have services that use those and LDAP is fine, just stick with OpenLDAP.