[keycloak-user] client certificate authentication using HAProxy and Keycloak

Nalyvayko, Peter pnalyvayko at agi.com
Wed Nov 22 11:25:15 EST 2017


Hi WEI LI,

Is this what you are looking for? https://github.com/keycloak/keycloak/pull/4546
________________________________________
From: keycloak-user-bounces at lists.jboss.org [keycloak-user-bounces at lists.jboss.org] on behalf of Wei Li [weil at redhat.com]
Sent: Wednesday, November 22, 2017 10:37 AM
To: keycloak-user at lists.jboss.org
Subject: [keycloak-user] client certificate authentication using HAProxy and    Keycloak

Hi,

We are using HAProxy as the reverse proxy for the Keycloak server, and we
are terminating the SSL connection at HAProxy.

Now we want to enable client certificate authentication. Because the SSL is
terminated at HAProxy, we can't use the existing CCA feature provided by
Keycloak. But we can get the client cert info in HAProxy and pass them onto
Keycloak in headers. So is there a way to allow Keycloak to get the user
info from the headers and perform authentication?

Thanks for your help in advance!

--

WEI LI

SENIOR SOFTWARE ENGINEER

Red Hat Mobile <https://www.redhat.com/>

weil at redhat.com    M: +353862393272
<https://red.ht/sig>
_______________________________________________
keycloak-user mailing list
keycloak-user at lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-user



More information about the keycloak-user mailing list