[keycloak-user] URL to download the public certificate of IdPs

Hynek Mlnarik hmlnarik at redhat.com
Mon Nov 11 02:55:54 EST 2019


You can extract certificate from SAML metadata exposed
at /auth/realms/REALM_NAME/protocol/saml/descriptor (for exact address,
see SAML 2.0 Identity Provider Metadata link in the realm general settings).

On Fri, Nov 8, 2019 at 2:07 PM Rafael Weingärtner <
rafaelweingartner at gmail.com> wrote:

> Hello guys,
> I was wondering, is there a URL in Keycloak that one can use to download
> the public certificate (PEM or some other format) of the IdP? I do know
> about the "jwks_uri", but that only gives me the public key. However, I
> need a public certificate. I have been through both Keycloak and OpenID
> Connect specs, but so far I could not find anything.
>
> Any help here would be greatly appreciated.
>
> --
> Rafael Weingärtner
> _______________________________________________
> keycloak-user mailing list
> keycloak-user at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-user


More information about the keycloak-user mailing list