home.social

#keycloak — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #keycloak, aggregated by home.social.

fetched live
  1. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #identitymanagement #opensource #letsencrypt #reverseproxy #openjdk #selfhosting #selfhosted

    🚀 How to Deploy Keycloak on Ub...

  2. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #identitymanagement #opensource #letsencrypt #reverseproxy #openjdk #selfhosting #selfhosted

    🚀 How to Deploy Keycloak on Ub...

  3. It's been a while since my last post and a lot has happened. Hence, a quick update.

    I've fully migrated from #freeipa to #kanidm by now and while this path was definitely not without (also major) problems, a lot of back and forth also with the developers, and a steep learning curve on my side, overall I don't regret the decision at all.

    While kanidm arguably falls behind in popularity/visibility compared to #authentik, #keycloak, etc and seemingly also has (much?) less developers, and development therefore feels slower, it scores with simplicity and by offering exactly what I need. And it is MUCH more light-weight than #freeipa and has WAY fewer moving parts. And developers react quickly and are helpful. POSIX users/groups I could just "inherit" from the existing system.

    See here for a quick comparison:
    kanidm.com/comparisons/

    I have around 10 services connected to it using OIDC, SSH access to servers, and automatic SSH key provisioning. All is working fine (finally now).

    What is a bit annoying about OIDC is that not all services offer OIDC out of the box, i.e. sometimes additional plugins are needed. The other annoying thing is that OIDC implementations differ, e.g. in how group mapping are used (if at all). But this is not kanidm's fault.

    If you are looking for a one-stop solution that offers OIDC, SSH key provisioning and replication - don't look any further. I can most highly recommend it.

  4. It's been a while since my last post and a lot has happened. Hence, a quick update.

    I've fully migrated from #freeipa to #kanidm by now and while this path was definitely not without (also major) problems, a lot of back and forth also with the developers, and a steep learning curve on my side, overall I don't regret the decision at all.

    While kanidm arguably falls behind in popularity/visibility compared to #authentik, #keycloak, etc and seemingly also has (much?) less developers, and development therefore feels slower, it scores with simplicity and by offering exactly what I need. And it is MUCH more light-weight than #freeipa and has WAY fewer moving parts. And developers react quickly and are helpful. POSIX users/groups I could just "inherit" from the existing system.

    See here for a quick comparison:
    kanidm.com/comparisons/

    I have around 10 services connected to it using OIDC, SSH access to servers, and automatic SSH key provisioning. All is working fine (finally now).

    What is a bit annoying about OIDC is that not all services offer OIDC out of the box, i.e. sometimes additional plugins are needed. The other annoying thing is that OIDC implementations differ, e.g. in how group mapping are used (if at all). But this is not kanidm's fault.

    If you are looking for a one-stop solution that offers OIDC, SSH key provisioning and replication - don't look any further. I can most highly recommend it.

  5. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #letsencrypt #opensource #reverseproxy #openjdk #identitymanagement #selfhosting

  6. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #letsencrypt #opensource #reverseproxy #openjdk #identitymanagement #selfhosting

  7. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #reverseproxy #identitymanagement #opensource #selfhosting #letsencrypt #selfhosted #openjdk

  8. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #identitymanagement #openjdk #selfhosted #letsencrypt #opensource #reverseproxy #selfhosting

  9. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #opensource #selfhosted #reverseproxy #openjdk #letsencrypt #identitymanagement #selfhosting

    🚀 How to Deploy Keycloak on Ub...

  10. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #opensource #selfhosted #reverseproxy #openjdk #letsencrypt #identitymanagement #selfhosting

    🚀 How to Deploy Keycloak on Ub...

  11. Von 2005 bis 2011 habe ich bei Microsoft mitgeholfen, den Käfig zu bauen.

    Nicht die Produkte. Die Wörter.

    „Tenant". „App-Registrierung". „Verzeichnisrolle." Vokabular war dort nie ein Nebenprodukt, es war Strategie. Wer die Begriffe setzt, mit denen eine Branche denkt, muss seine Produkte nicht mehr verteidigen, die Konkurrenz muss in einer Fremdsprache antworten. Der MCSE war kein Wissensnachweis, er war ein Sprachkurs mit Urkunde. Heute heißt er SC-300 und tut exakt dasselbe.

    Es funktioniert bis heute. Es funktionierte sogar bei mir.
    Letzten Samstag saß ich vor Keycloak für die Isar Open Source Community und verstand kein Wort. Realm? Client? Protocol Mapper? Zwei Stunden später fiel der Groschen, und er fiel unangenehm laut:

    Ich kannte das alles. Seit zwanzig Jahren. Nur unter anderen Namen.
    Ein Realm ist ein Tenant. Ein Client ist eine App-Registrierung. Rollen sind Rollen. Claims sind Claims.

    Deshalb ist „der Wechsel weg von Entra ist zu komplex" keine Analyse. Es ist eine Ausrede, die sich als Sachverstand tarnt. Es fehlt kein Know-how. Es fehlen zwei Seiten Übersetzung.
    Ein Käfig aus Wörtern hält nur so lange, wie man das Wörterbuch nicht liest.

    Der neue Panolin:
    https://www.pandolin.io/keycloak-entra-woerterbuch/

    #Keycloak #EntraID #DigitaleSouveränität #OpenSource #SelfHosting #FOSS #Linux #Fediverse

  12. Von 2005 bis 2011 habe ich bei Microsoft mitgeholfen, den Käfig zu bauen.

    Nicht die Produkte. Die Wörter.

    „Tenant". „App-Registrierung". „Verzeichnisrolle." Vokabular war dort nie ein Nebenprodukt, es war Strategie. Wer die Begriffe setzt, mit denen eine Branche denkt, muss seine Produkte nicht mehr verteidigen, die Konkurrenz muss in einer Fremdsprache antworten. Der MCSE war kein Wissensnachweis, er war ein Sprachkurs mit Urkunde. Heute heißt er SC-300 und tut exakt dasselbe.

    Es funktioniert bis heute. Es funktionierte sogar bei mir.
    Letzten Samstag saß ich vor Keycloak für die Isar Open Source Community und verstand kein Wort. Realm? Client? Protocol Mapper? Zwei Stunden später fiel der Groschen, und er fiel unangenehm laut:

    Ich kannte das alles. Seit zwanzig Jahren. Nur unter anderen Namen.
    Ein Realm ist ein Tenant. Ein Client ist eine App-Registrierung. Rollen sind Rollen. Claims sind Claims.

    Deshalb ist „der Wechsel weg von Entra ist zu komplex" keine Analyse. Es ist eine Ausrede, die sich als Sachverstand tarnt. Es fehlt kein Know-how. Es fehlen zwei Seiten Übersetzung.
    Ein Käfig aus Wörtern hält nur so lange, wie man das Wörterbuch nicht liest.

    Der neue Panolin:
    https://www.pandolin.io/keycloak-entra-woerterbuch/

    #Keycloak #EntraID #DigitaleSouveränität #OpenSource #SelfHosting #FOSS

  13. I love it when an #update to my #selfhost environment is a complete non-event. Upgraded my #Keycloak to the latest 26.7.0 today and it took just a few moments and had no issues! #homelab #selfhosted

  14. I love it when an #update to my #selfhost environment is a complete non-event. Upgraded my #Keycloak to the latest 26.7.0 today and it took just a few moments and had no issues! #homelab #selfhosted

  15. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosting #letsencrypt #openjdk #identitymanagement #selfhosted #reverseproxy #opensource

  16. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosting #letsencrypt #openjdk #identitymanagement #selfhosted #reverseproxy #opensource

  17. Unterwegs zum Java Forum Stuttgart! Kommt mich dort gerne am Stand des besuchen und informiert euch über die JUGs in 🇩🇪 🇦🇹 🇨🇭 und welche tollen Vorteile ihr von einer Mitgliedschaft habt, zum Beispiel mit unserer eigenen Infrastruktur wie , , , , , , , und mehr!

  18. Unterwegs zum Java Forum Stuttgart! Kommt mich dort gerne am Stand des #iJUG besuchen und informiert euch über die JUGs in 🇩🇪 🇦🇹 🇨🇭 und welche tollen Vorteile ihr von einer Mitgliedschaft habt, zum Beispiel #Digitale #Unabhängigkeit mit unserer eigenen Infrastruktur wie #Nextcloud, #Mastodon, #Matrix, #Jitsi, #Mobilizon, #Forgejo, #Keycloak, und mehr!

    #Java #jfs #jfs2026

  19. Morgen geht sie los: die "IT-Tagung 2026".
    Veranstalter: Diakonisches Werk Traunstein e.V. · IT-Tagung 2026 in Kooperation mit Diakonisches Werk Bayern e.V. 👇
    it-gemeinsam.de/

    Unsere Vorbereitungen sind abgeschlossen: FOSC IT GmbH - Full Open Source Consulting. Wir berichten über Datensouveränität, Datenhoheit, Software wie Grommunio, Nextcloud, Keycloak/SSO u.v.m..

    #diakonie #Nextcloud #grommunio #keycloak

  20. Morgen geht sie los: die "IT-Tagung 2026".
    Veranstalter: Diakonisches Werk Traunstein e.V. · IT-Tagung 2026 in Kooperation mit Diakonisches Werk Bayern e.V. 👇
    it-gemeinsam.de/

    Unsere Vorbereitungen sind abgeschlossen: FOSC IT GmbH - Full Open Source Consulting. Wir berichten über Datensouveränität, Datenhoheit, Software wie Grommunio, Nextcloud, Keycloak/SSO u.v.m..

    #diakonie #Nextcloud #grommunio #keycloak

  21. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #reverseproxy #identitymanagement #opensource #letsencrypt #selfhosted #openjdk #selfhosting

  22. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #letsencrypt #reverseproxy #opensource #selfhosting #identitymanagement #openjdk #selfhosted

    🚀 How to Deploy Keycloak on Ub...

  23. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #letsencrypt #reverseproxy #opensource #selfhosting #identitymanagement #openjdk #selfhosted

    🚀 How to Deploy Keycloak on Ub...

  24. CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. radar.offseq.com/threat/cve-20 #OffSeq #Keycloak #Vuln #IAM

  25. Hab halt deren compose files in mein bestehendes Setup adaptiert. Eine Unzahl von ENB-Variablen deren Default direkt im Compose-File definiert sind, container Namen die in anderen Konfigurationen gesucht/ersetzt werden müssen, wenn man sie ändert.

    Und dann bin ich mir immer noch unsicher, brauch ich jetzt nen #Keycloak + Datenbank? 🤨
    Und den #LDAP? 🤔
    Oder was davon ist für ein Prod-Setup mit ner Handvoll Nutzer optional? 😵‍💫

    #OpenCloud #DockerCompose #SelfHosting

  26. Hab halt deren compose files in mein bestehendes Setup adaptiert. Eine Unzahl von ENB-Variablen deren Default direkt im Compose-File definiert sind, container Namen die in anderen Konfigurationen gesucht/ersetzt werden müssen, wenn man sie ändert.

    Und dann bin ich mir immer noch unsicher, brauch ich jetzt nen #Keycloak + Datenbank? 🤨
    Und den #LDAP? 🤔
    Oder was davon ist für ein Prod-Setup mit ner Handvoll Nutzer optional? 😵‍💫

    #OpenCloud #DockerCompose #SelfHosting

  27. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #letsencrypt #identitymanagement #selfhosted #reverseproxy #openjdk #selfhosting #opensource

    🚀 How to Deploy Keycloak on Ub...

  28. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ...
    Continued 👉 #letsencrypt #identitymanagement #selfhosted #reverseproxy #openjdk #selfhosting #opensource

    🚀 How to Deploy Keycloak on Ub...

  29. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #identitymanagement #openjdk #opensource #reverseproxy #letsencrypt #selfhosting

  30. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #selfhosted #identitymanagement #openjdk #opensource #reverseproxy #letsencrypt #selfhosting

  31. Nice, that was easy. #Vaultwarden single sign on with #KeyCloak has been successfully configured.

  32. Nice, that was easy. #Vaultwarden single sign on with #KeyCloak has been successfully configured.

  33. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #reverseproxy #selfhosting #letsencrypt #opensource #selfhosted #identitymanagement #openjdk

  34. RT @[email protected]
    #Keycloak pwnage, all public.
    1: CVE-2026-4282 forges admin tokens unauth
    2: view-clients leaks every client secret, all versions, open #49220 (PoC: tinyurl.com/kmkz2)
    3: restart revives rotated refresh tokens, CVE-2026-9802

    Not every vuln has a CVE
    x.com/i/status/206...

    Exploits/2026/KeyCloak-49220-s...

  35. RT @[email protected]
    #Keycloak pwnage, all public.
    1: CVE-2026-4282 forges admin tokens unauth
    2: view-clients leaks every client secret, all versions, open #49220 (PoC: tinyurl.com/kmkz2)
    3: restart revives rotated refresh tokens, CVE-2026-9802

    Not every vuln has a CVE
    x.com/i/status/206968547574122

  36. RT @[email protected]
    #Keycloak pwnage, all public.
    1: CVE-2026-4282 forges admin tokens unauth
    2: view-clients leaks every client secret, all versions, open #49220 (PoC: tinyurl.com/kmkz2)
    3: restart revives rotated refresh tokens, CVE-2026-9802

    Not every vuln has a CVE
    x.com/i/status/206968547574122

  37. Anyone got a few minutes to review a blog post about using Keycloak to assume an AWS role via OIDC? Will credit you of course

    #Keycloak

  38. Anyone got a few minutes to review a blog post about using Keycloak to assume an AWS role via OIDC? Will credit you of course

    #Keycloak

  39. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #letsencrypt #selfhosting #opensource #openjdk #identitymanagement #reverseproxy #selfhosted

  40. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide) Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ... Continued 👉 #opensource #openjdk #selfhosted #letsencrypt #selfhosting #identitymanagement #reverseproxy

    🚀 How to Deploy Keycloak on Ub...

  41. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide) Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak ... Continued 👉 #opensource #openjdk #selfhosted #letsencrypt #selfhosting #identitymanagement #reverseproxy

    🚀 How to Deploy Keycloak on Ub...

  42. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #reverseproxy #selfhosting #selfhosted #identitymanagement #opensource #openjdk #letsencrypt

  43. 🚀 How to Deploy #Keycloak on #Ubuntu #VPS (5 Minute Quick-Start Guide)

    Here’s a clear and detailed how-to guide for how to deploy Keycloak on Ubuntu VPS. This guide uses Keycloak in standalone mode with #PostgreSQL as the database and #NGINX as a reverse proxy with SSL.
    What is Keycloak?
    Keycloak is an open-source identity and access management (IAM) ...
    Continued 👉 blog.radwebhosting.com/deploy- #reverseproxy #selfhosting #selfhosted #identitymanagement #opensource #openjdk #letsencrypt

  44. @bert_hubert I'm the last owl to take the side of big tech, but just saying, have you ever personally tried integrating oauth2/webauthn/OIDC/SSO into various #OpenSource web services? No? I want to wish you all the best of luck with that, as you roll out your enterprise-scale OpenSource deployments.

    I think there's good reason all these big organizations with valiant intentions of escaping big tech, end up crawling back to big tech. The OpenSource SSO offerings leave something to be desired. Where is the realistic competitor to #Microsoft Entra? Would that be #KeyCloak? #Authelia?

    It's much harder than you think.

  45. @bert_hubert I'm the last owl to take the side of big tech, but just saying, have you ever personally tried integrating oauth2/webauthn/OIDC/SSO into various #OpenSource web services? No? I want to wish you all the best of luck with that, as you roll out your enterprise-scale OpenSource deployments.

    I think there's good reason all these big organizations with valiant intentions of escaping big tech, end up crawling back to big tech. The OpenSource SSO offerings leave something to be desired. Where is the realistic competitor to #Microsoft Entra? Would that be #KeyCloak? #Authelia?

    It's much harder than you think.

  46. WHERE OTHERS LOSE CONTROL – WE STAY IN THE LOOP.

    At Infinito.Nexus, we believe that AI should never replace human judgment. We are the captains. AI is our navigator. While others hand over responsibility to black-box systems, we stay in control. We design the architecture, review the code, verify every deployment, and make the decisions that shape the future of the systems we build. AI is one of the most powerful tools ever created. But it remains a tool. We are the engineers, architects, and craftsmen who use it to build sovereign digital infrastructure faster, more reliably, and at a scale that was impossible only a few years ago. […]

    blog.infinito.nexus/blog/2026/

  47. After trying #Keycloak for a while - trying to integrate it with ForgeJo for Single-Sign-On (#SSO), I wasn't really satisfied with Keycloak. Keycloak's error messages were too unhelpful. The documentation, too nebulous. I lurked in their forums a bit, but didn't really want to use Slack as some sort of depended-upon service. Whatever the Keycloak error messages said, the eventual solutions usually ended up being so disconnected with the error message, that it dawned on me that the Error messages were effectively "Red Herrings" - served only to throw me off the trail.

    Keycloak had a vibe to it that I'd describe as "Enterprise Bozak". It had the *look* of professionalism - making a solid effort to *appear* attractive to higher-up management types - but it didn't really *deliver* the helpfulness I was expecting, to actually overcome technical hurdles encountered. I've set Keycloak aside for now, and I'm trying out #Authelia instead, with an LLDAP backend. They seem easier to work with, as the error messages were good so far: had more of a technical helpfulness. After several hours of tinkering, I've set up my first LLDAP/Authelia users, including registering a passkey. I'll next see if I can integrate the Authelia SSO to #ForgeJo.

    #infosec #OpenSource

  48. New Release: We’ve extended c4k-keycloak with WebFinger support. Now, SSO via Tailscale works.

    repo.prod.meissa.de/meissa/c4k

    #DevOps #Clojure #Keycloak #sso