<div dir="ltr">The first would be at the &quot;Welcome to Keycloak&quot; page, clicking on Administration Console.  The link itself is not redirecting to http, but as part of the login page it looks like it forwards back to http. (eg. <a href="https://auth.psidox.com/auth/">https://auth.psidox.com/auth/</a> -&gt; <a href="https://auth.psidox.com/auth/admin/">https://auth.psidox.com/auth/admin/</a> -&gt; <a href="http://auth.psidox.com/auth/admin/master/console">http://auth.psidox.com/auth/admin/master/console</a> -&gt; <a href="http://auth.psidox.com/auth/realms/master/tokens/login?client_id=security-admin-console&amp;redirect_uri=http%3A%2F%2Fauth.psidox.com%2Fauth%2Fadmin%2Fmaster%2Fconsole%2F&amp;state=2ae3dfaa-fe7c-4973-8932-ffea553d8dfe&amp;response_type=code">http://auth.psidox.com/auth/realms/master/tokens/login?client_id=security-admin-console&amp;redirect_uri=http%3A%2F%2Fauth.psidox.com%2Fauth%2Fadmin%2Fmaster%2Fconsole%2F&amp;state=2ae3dfaa-fe7c-4973-8932-ffea553d8dfe&amp;response_type=code</a>)<div>
<br></div><div>I haven&#39;t really gotten too far beyond the login page.</div><div><br></div><div>- Josh</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Mon, Jun 16, 2014 at 3:33 AM, Stian Thorgersen <span dir="ltr">&lt;<a href="mailto:stian@redhat.com" target="_blank">stian@redhat.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">When does it forward the browser from https to http?<br>
<br>
As Bill pointed out, does auth-server-url in your keycloak.json point to your proxy with https?<br>
<br>
What adapter are you using?<br>
<div class="HOEnZb"><div class="h5"><br>
----- Original Message -----<br>
&gt; From: &quot;Josh&quot; &lt;<a href="mailto:smysnk@gmail.com">smysnk@gmail.com</a>&gt;<br>
&gt; To: <a href="mailto:keycloak-user@lists.jboss.org">keycloak-user@lists.jboss.org</a><br>
&gt; Sent: Friday, 13 June, 2014 8:41:32 AM<br>
&gt; Subject: [keycloak-user] Significant SSL issue: Support for reverse proxies<br>
&gt;<br>
&gt; Hi guys,<br>
&gt;<br>
&gt; So looking to help solve this issue possibly or at least get it on the radar,<br>
&gt; I&#39;ve reported it here: <a href="https://issues.jboss.org/browse/KEYCLOAK-497" target="_blank">https://issues.jboss.org/browse/KEYCLOAK-497</a><br>
&gt;<br>
&gt; To breifly recap the issue, when logging in via reverse proxy it keeps<br>
&gt; forwarding the browser from https back to regular http.<br>
&gt;<br>
&gt; Eg. Apache virtualhost configured as:<br>
&gt;<br>
&gt; &lt;VirtualHost *:443&gt;<br>
&gt; ServerName <a href="http://auth.domain.com" target="_blank">auth.domain.com</a><br>
&gt; SSLEngine On<br>
&gt;<br>
&gt; &lt;Proxy *&gt;<br>
&gt; Order deny,allow<br>
&gt; Allow from all<br>
&gt; &lt;/Proxy&gt;<br>
&gt;<br>
&gt; ProxyVia Off<br>
&gt; ProxyPreserveHost On<br>
&gt; ProxyRequests Off<br>
&gt;<br>
&gt; ProxyPass / <a href="http://keycloak.core.docker:8080/" target="_blank">http://keycloak.core.docker:8080/</a><br>
&gt; ProxyPassReverse / <a href="http://keycloak.core.docker:8080/" target="_blank">http://keycloak.core.docker:8080/</a><br>
&gt;<br>
&gt;<br>
&gt; &lt;/VirtualHost&gt;<br>
&gt;<br>
&gt; If I were to start looking into the code base, where would I start? Trying to<br>
&gt; find for example during the login process how the forward url is formed?<br>
&gt;<br>
&gt; Thanks,<br>
&gt;<br>
&gt; Josh<br>
&gt;<br>
</div></div><div class="HOEnZb"><div class="h5">&gt; _______________________________________________<br>
&gt; keycloak-user mailing list<br>
&gt; <a href="mailto:keycloak-user@lists.jboss.org">keycloak-user@lists.jboss.org</a><br>
&gt; <a href="https://lists.jboss.org/mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/mailman/listinfo/keycloak-user</a><br>
</div></div></blockquote></div><br></div>