# Understanding authenticatino process

**URL:** <https://community.sonatype.com/t/understanding-authenticatino-process/9315>\
**Category:** Sonatype Nexus Repository\
**Tags:** nexus-repository\
**Created:** [September 16, 2022, 9:59am UTC](https://community.sonatype.com/t/understanding-authenticatino-process/9315 "2022-09-16T09:59:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![masber](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/masber/32/2427_2.png) [@masber](https://community.sonatype.com/u/masber)\
**Post date:** [September 16, 2022, 9:59am UTC](https://community.sonatype.com/t/understanding-authenticatino-process/9315/1 "2022-09-16T09:59:15Z")

</div>

I have a sonatype nexus deployment with keycloak as identify provider. I can login and have admin access to nexus.

However I can’t push a container image:

```auto
ctr images push -u <my keycloak username>:<my keycloak password> registry.local/cray/k8s.gcr.io/pause:3.1
manifest-sha256:759c3f0f6493093a9043cc813092290af69029699ade0e3dbe024e968fcb7cca: done |++++++++++++++++++++++++++++++++++++++| 
layer-sha256:cf92024299791de93ad205151ab24e535c218bbea6465fd8f79c2611db913a50: done |++++++++++++++++++++++++++++++++++++++| 
config-sha256:da86e6ba6ca197bf6bc5e9d900febd906b133eaa4750e6bed647b0fbe50ed43e: done |++++++++++++++++++++++++++++++++++++++| 
elapsed: 0.1 s total: 527.0 (5.1 KiB/s)                                       
ctr: failed commit on ref "manifest-sha256:759c3f0f6493093a9043cc813092290af69029699ade0e3dbe024e968fcb7cca": unexpected status: 401 Unauthorized

```

Any idea how to solve this?

thank you

---

<div class="post-metadata">

**Author:** ![mmartz](https://avatars.discourse-cdn.com/v4/letter/m/e9bcb4/32.png) [@mmartz](https://community.sonatype.com/u/mmartz)\
**Post date:** [September 16, 2022, 1:32pm UTC](https://community.sonatype.com/t/understanding-authenticatino-process/9315/2 "2022-09-16T13:32:46Z")

</div>

You won’t be able to use SAML to login via command-line tooling. The standard solution to this problem is to use user tokens, but that is a Nexus Repository Pro feature ([Security Setup with User Tokens](https://help.sonatype.com/repomanager3/nexus-repository-administration/user-authentication/security-setup-with-user-tokens)). Other security solutions like LDAP will work in the way you expect, but a SAML server is completely disconnected from Nexus Repository. It requires a browser redirect to authenticate.

---

<div class="post-metadata">

**Author:** ![jeff.wise](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/jeff.wise/32/2421_2.png) [@jeff.wise](https://community.sonatype.com/u/jeff.wise)\
**Post date:** [September 16, 2022, 4:27pm UTC](https://community.sonatype.com/t/understanding-authenticatino-process/9315/3 "2022-09-16T16:27:23Z")

</div>

We use a local realm account to upload container images to NXRM via our continuous integration service. Developers are not allowed to upload from their laptops directly. User logins to the NXRM portal are protected with SAML.
