[keycloak-user] Logouts in a clustered environment with OIDC based apps

Pulkit Gupta pulgupta at redhat.com
Fri Apr 27 05:14:03 EDT 2018


Hi All,

Sometime back I reported an issue https://issues.jboss.org
/browse/KEYCLOAK-4288 <https://issues.jboss.org/browse/KEYCLOAK-4288> in
which the back channel logouts were not working for SAML in a clustered
JBoss environment with EAP6 SAML Adapter. It was fixed and released as well.

I started on an app and was using OIDC RH_SS0-7.2 EAP 6(3.4.3) adapter in a
clustered environment. We do not have an option for setting back
channel/Front channel logouts for OIDC client but it looks like we are
facing a similar issue for clustered application where even after logging
out we can see that all sessions are not invalidated and we can see secure
pages without logging in again.

Please suggest if someone has faced similar issue.

-- 

PULKIT GUPTA


More information about the keycloak-user mailing list