<div dir="ltr">Marc / Eric, <div><br></div><div>Thank you for your help in the past , i really appreciate it . but my issue did not get resolved yet .</div><div><br></div><div>My Application is really simple , i get a token from keycloak and use that token call API MAN services . </div><div><br></div><div>When the application is fresh installed , this problem does not happened often , but once many users using it and over time , it will start rejecting tokens with the "Token is not active" message . </div><div><br></div><div>for example if my service is on <a href="https://myserver.com/api-gateway/myservice">https://myserver.com/api-gateway/myservice</a> i pass a token like with an access_token parameter</div><div><br></div><div> <a href="https://myserver.com/api-gateway/myservice?access_token=">https://myserver.com/api-gateway/myservice?access_token=</a><token value> </div><div>some time it return a value and some times not . i'm always using a new browser , so its not the cashing. </div><div><br></div><div>The only way to solve the issue is to restart keycloak/apiman , seems they back in sync . </div><div><br></div><div>It started a small problem with dev , but now its expanding because our product with the QA people and this escalating .. Is there a way you guys can help us a little more ? is there a paid support ? </div><div><br></div><div>Thanks,</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 11, 2015 at 4:16 AM, Marc Savy <span dir="ltr"><<a href="mailto:marc.savy@redhat.com" target="_blank">marc.savy@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I think this may pertain to the Keycloak OAuth2 token. In which case, I<br>
provided Fadi with a version containing additional logging to see if we<br>
could track the issue down.<br>
<br>
It's not an issue I've ever been able to replicate, and we don't fiddle<br>
with the token data in any way, so I don't really see how we could<br>
affect things.<br>
<br>
My only suggestions are to ensure that time is accurate on all of the<br>
systems (NTP, Chronyd, etc), and I believe this has already been done.<div class="HOEnZb"><div class="h5"><br>
<br>
On 10/08/2015 18:00, Eric Wittmann wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
How often does this occur? What is the result?<br>
<br>
I assume this is triggering a re-login in the UI?<br>
<br>
There is no caching on the apiman side. However the tokens issued by<br>
keycloak to the apiman UI do have an expiration. You could try logging<br>
into the keycloak auth admin UI and increasing the lifespan of the tokens.<br>
<br>
Any more details you can provide would be great.<br>
<br>
-Eric<br>
<br>
On 8/10/2015 8:56 AM, Fadi Abdin wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
I keep getting occasional "Token is not active." on they keycloak side<br>
occasionally . its really frustrating , i cant figure out what could<br>
cause this to happen. everything seems correct.<br>
<br>
Is there caching between API Man and Keycloak i can turn off ? Have<br>
anyone seeen this behavior ?<br>
<br>
Thanks,<br>
Fadi<br>
Express.com<br>
<br>
<br>
_______________________________________________<br>
Apiman-user mailing list<br>
<a href="mailto:Apiman-user@lists.jboss.org" target="_blank">Apiman-user@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/apiman-user" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/apiman-user</a><br>
<br>
</blockquote>
_______________________________________________<br>
Apiman-user mailing list<br>
<a href="mailto:Apiman-user@lists.jboss.org" target="_blank">Apiman-user@lists.jboss.org</a><br>
<a href="https://lists.jboss.org/mailman/listinfo/apiman-user" rel="noreferrer" target="_blank">https://lists.jboss.org/mailman/listinfo/apiman-user</a><br>
<br>
</blockquote>
<br>
</div></div></blockquote></div><br></div>