18+ rmdes, to random
@rmdes@mstdn.social avatar

spent the last few weeks on and API Gateway, with the goal of securing a set of API endpoints deployed on the open web.

It’s both challenging and fascinating learning curve, from deployment (kubernetes/helm/openshift) to configurations and tweaking.

rmdes,
@rmdes@mstdn.social avatar

passé les dernières semaines sur et API Gateway, dans le but de sécuriser des points de terminaison d’API déployés sur le web

C’est une courbe d’apprentissage à la fois stimulante et fascinante, du déploiement (Kubernetes/Helm/Openshift) aux configurations et aux ajustements.

fedora, to fedora
@fedora@fosstodon.org avatar

"Keycloak is an open source identity provider (IdP) with single-sign on (SSO) capabilities. It supports the most widely used enterprise authentication protocols, namely OpenID Connect (OIDC), OAuth 2.0, and SAML. With Keycloak, users sign in once and share the same identity across multiple applications and platforms in a transparent manner."

Learn how to set it up!

➡️ https://fedoramagazine.org/keycloak-on-fedora-workstation-with-podman/

b1systems, to random German
@b1systems@mastodon.social avatar

Interested in the integration of relational databases with Keycloak? Explore our article showcasing our Keycloak extension "proof-of-concept": https://blog.b1-systems.de/lessons-learned-when-implementing-custom-user-storage-provider-keycloak




freiefunken, to linux German
@freiefunken@mastodon.social avatar

Wer mag, kann bei den Chemnitzer Linuxtagen was über Single Sign-on für Webanwendungen von mir hören. Ist aber für die, die sonntags morgens nicht verschlafen. 😉

https://chemnitzer.linux-tage.de/2024/de/programm/beitrag/213

lsmith, to random
@lsmith@mastodon.green avatar

Do I know anyone with experience building a custom federation provider in ? https://github.com/keycloak/keycloak/discussions/26181

dgoosens, (edited ) to Symfony
@dgoosens@phpc.social avatar

Just had the time to catch up a little on @ApiPlatform conf 2023...

Excellent talk by @vincentchalamon about & and the integration with &

Vincent very clearly explains the core principles and the history behind these technologies before showing how «easy» it is to setup with

Talk will be available soon on the @cooptilleuls YouTube channel (and possibly in English)

https://www.youtube.com/@coopTilleuls

tbroyer, to security
@tbroyer@piaille.fr avatar

CVEs reported without version, and/or never updated to limit their CPEs to exclude versions where the vulnerability is fixed;

and now I get false positives every single time I update that dependency 😭

(in this case, specifically, Keycloak's CVE-2022-1438 and CVE-2023-0105, both still reported on version 22.0.4 by Dependency Track; the GitHub Advisories have the accurate information, but not the NVD 😡)

MarcusSchwemer, to php
@MarcusSchwemer@muenchen.social avatar

TIL: EU Captcha != captcha.eu

The last one is a payed service and has nothing to do with the open source captcha solution by the european union (despite the name nearly similar name)

Don't get hooked!

lukas, to Matrix German
@lukas@social.lukas-schieren.de avatar

Hat wer Erfahrungen mit der Anbindung von keycloak als SSO an Matrix?

kpwn, to infosec

If not secured properly, one-time passwords are a lot more likely to be guessed than you think!

Ever since I've learned that 's default configuration does not prevent brute-forcing, I wanted to discuss the topic in detail and raise awareness.

Enjoy reading! 👇

https://infosec.exchange/@kpwn/110600013869408508

nosherwan, to security
@nosherwan@fosstodon.org avatar

🌩️
Cloud Authentication Services

There is a sea of Cloud Auth / Identity management providers.

There was a time I used to roll my own, but as security is getting complicated, it seems for startups & small to medium businesses it is better to use a cloud auth provider.

Please share your thoughts on your experience with this as I look into this area.

So far I have come across:


(by Okta)





socreatory, to random German

Hier ist des Rätsels Lösung:
💐Herzlich Willkommen @dasniko – wir freuen uns sehr ihn in unserem Trainer:innen-Team begrüßen zu können!
🗝️🧥 Hier findet ihr sein erstes Training bei uns – natürlich zum Thema : https://www.socreatory.com/de/trainings/keycloak/events/c29db1185e07

blake, to random

I could probably make a little shim between clients and to handle client lookup and registration. Not completely sure how IndieAuth clients would handle the redirect though (as it would be undoubtedly cross-subdomain)...

blake, to random

I've started reading a bit about -- for some reason, I started with the spec on W3.org, which makes more sense to me than a lot of stuff I've read but it also doesn't "feel" complete.

I'm wondering if I can configure to function sufficiently as an IndieAuth provider.

thomasdarimont, to random

The team is looking for feedback about using the Keycloak Authorization Services and authorization use-cases in general.

You can help to improve the Authorization Support in Keycloak!

Survey: https://www.keycloak.org/2023/07/authorization-survey.html

tyil, to grafana

Wondering if I could leverage for my personal services (, , , , , , )

blake, to random

I just hooked up source.blakes.dev to (exclusively) sign in with . All it took was setting it up in /admin/auths and in Keycloak and adding a redirect to Traefik according to this comment: https://github.com/go-gitea/gitea/issues/13606#issuecomment-1421630270

francis, to random Norwegian Bokmål
@francis@babb.no avatar

Ant Keycloak admin out there who’s willing to discuss a Configuration Issue l?

francis, to Oslo
@francis@babb.no avatar

My (since I changed instance):

I am a Norwegian IT-engineer at the University of . Originally from , I moved to in 2011.

I work mostly with VMware stuff, but also spend most part of my days configuring images for VDI's, , , , , etc.

I love , baking and became in Feb 2022. I have .

I started https://mastodon.babb.no for friends and colleagues.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • rosin
  • InstantRegret
  • ethstaker
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • tacticalgear
  • slotface
  • Durango
  • khanakhh
  • kavyap
  • megavids
  • everett
  • vwfavf
  • normalnudes
  • osvaldo12
  • cubers
  • GTA5RPClips
  • cisconetworking
  • ngwrru68w68
  • anitta
  • provamag3
  • tester
  • modclub
  • JUstTest
  • All magazines