<div dir="ltr"><span style="font-size:12.8000001907349px">hi bill,</span><br><div><span style="font-size:12.8000001907349px"><br></span></div><div><span style="font-size:12.8000001907349px">can you advise regarding the global sign out issue? </span></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Mar 5, 2015 at 9:29 AM, Chen Keong Yap <span dir="ltr"><<a href="mailto:chenkeong.yap@izeno.com" target="_blank">chenkeong.yap@izeno.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>hi bill,</div><div><br></div><div>Thanks for the solution given and it has resolved the first issue ( login to the app via pl sp filter but the login session cannot be seen in keycloak admin console)</div><div><br></div><div>However now there are few more issues with single sign out.</div><div><br></div><div>a) When i click on the global logout link (<a href="http://localhost:8080/employee/?GLO=true" target="_blank">http://localhost:8080/employee/?GLO=true</a>), the page just did a self refresh and it's not redirected to keycloak login page. I can see the keycloak session was gone from the keycloak admin console but the sample employee session still there.</div><div><br></div><div>b) When i click on the local logout link (<a href="http://localhost:8080/employee/?LLO=true" target="_blank">http://localhost:8080/employee/?LLO=true</a>), the page just did a self refresh and it's not redirected to keycloak login page. I can see the keycloak session still in the keycloak admin console but the sample employee session still there.</div><div><br></div><div>c) When i click on the logout link (<a href="http://localhost:8080/employee/logout.jsp" target="_blank">http://localhost:8080/employee/logout.jsp</a>), the page just did a self refresh and it's not redirected to keycloak login page. I noticed the keycloak session still in the keycloak admin console but the sample employee session still there. Just wondering do i need to implement session.invalidate() in the logout,jsp but how to invalidate the keycloak session?</div><div><div class="h5"><br><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Mar 4, 2015 at 11:12 PM, Bill Burke <span dir="ltr"><<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">Ok, I may have diagnosed the problem. Go to the admin console. Go to the definition of your application. Look at the Admin Url. Does it have a "/" at the end of the URL? If not, add a '/' at the end of this.<br>
<br>
i.e.<br>
<br>
<a href="http://somhere.com/app/" target="_blank">http://somhere.com/app/</a><br>
<br>
If that solves the issue, let me know and I'll explain what is going on. FYI, I ran into the same problem running the SAML example in the distro and this fixed the problem.<span><br>
<br>
<br>
<br>
<br>
On 3/4/2015 9:07 AM, Chen Keong Yap wrote:<br>
</span><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
Hi bill,<br>
<br><span>
If i understand from you correctly,<br>
PL SAML SP and keycloak adapters are the same and referring to below items.<br>
<br>
Tomcat 6, 7, 8<br>
Jetty 8, 9<br>
EAP 6.x<br>
Wildfly<br>
Node.js<br>
Browser Javascript adapter.<br>
<br>
So far i have tested PL SAML SP filter using the following libs and it<br>
got the same 2 issues that was mentioned in the previous email.<br>
<br>
Picketlink lib : Picketlink 2.70 cr2, picketlink 2.5.3 (commercial)<br>
<br>
keycloak lib : keycloak 1.1.0 final, keycloak 1.1.0 beta 2<br>
<br>
On Mar 4, 2015 9:44 PM, "Bill Burke" <<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a><br></span><span>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>>> wrote:<br>
<br>
Our testsuite uses PL SAML SP, not the filter though, and it works<br>
fine. I'd have to recreate the problem using the PL SAML SP filter.<br>
<br>
On 3/4/2015 8:04 AM, Chen Keong Yap wrote:<br>
<br>
Hi bill,<br>
<br>
Yup. I have configured the app in keycloak admin console. However i<br>
encountered 2 issues.<br>
<br>
First issue is that i was able to login to the app via pl sp<br>
filter but<br>
the login session cannot be seen in keycloak admin console<br>
<br>
Second issue is that global logout was not working and the<br>
landing page<br>
just did a self refresh.<br>
<br>
On Mar 4, 2015 8:55 PM, "Bill Burke" <<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a><br>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>><br></span><div><div>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a> <mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>>>> wrote:<br>
<br>
You can still use the PL Filter SP. Just configure the<br>
application<br>
in the admin console to use SAML.<br>
<br>
On 3/3/2015 11:36 PM, Chen Keong Yap wrote:<br>
<br>
Hi bill,<br>
<br>
the existing adapters cannot support jboss eap 5.0.2 and<br>
websphere 8.5<br>
and we are not allowed to use keycloak proxy.<br>
<br>
can you suggest any other alternative similar to<br>
picketlink sp<br>
filter?<br>
<br>
On Tue, Mar 3, 2015 at 11:45 PM, Bill Burke<br>
<<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a> <mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>><br>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a> <mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>>><br>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a> <mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>><br>
<mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a> <mailto:<a href="mailto:bburke@redhat.com" target="_blank">bburke@redhat.com</a>>>>> wrote:<br>
<br>
There is no Keycloak SP filter. We have various<br>
adapters<br>
for different<br>
platforms that hook into servlet security to make<br>
integration seamless:<br>
<br>
Tomcat 6, 7, 8<br>
Jetty 8, 9<br>
EAP 6.x<br>
Wildfly<br>
Node.js<br>
Browser Javascript adapter.<br>
<br>
On 3/2/2015 10:22 PM, Chen Keong Yap wrote:<br>
> Hi,<br>
><br>
> Please share some lights for implementing<br>
Keycloak sp<br>
filter which is<br>
> similar to picketlink sp filter.<br>
><br>
><br></div></div>
org.picketlink.identity.____<u></u>federation.web.filters.____<u></u>SPFilter<br>
><br>
><br>
> ______________________________<u></u>_____________________<span><br>
> keycloak-user mailing list<br>
> <a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.jboss.org</a><br>
<mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>><br>
<mailto:<a href="mailto:keycloak-user@lists." target="_blank">keycloak-user@lists.</a>__<a href="http://jboss.org" target="_blank"><u></u>jboss.org</a><br>
<mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>>><br></span>
<mailto:<a href="mailto:keycloak-user@lists" target="_blank">keycloak-user@lists</a>.<br>
<mailto:<a href="mailto:keycloak-user@lists" target="_blank">keycloak-user@lists</a>.>_<u></u>___<a href="http://jboss.org" target="_blank">jboss.org</a> <<a href="http://jboss.org" target="_blank">http://jboss.org</a>><br>
<mailto:<a href="mailto:keycloak-user@lists." target="_blank">keycloak-user@lists.</a>__<a href="http://jboss.org" target="_blank"><u></u>jboss.org</a><br>
<mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>>>><br>
><br>
<a href="https://lists.jboss.org/____mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/____<u></u>mailman/listinfo/keycloak-user</a><br>
<<a href="https://lists.jboss.org/__mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/__<u></u>mailman/listinfo/keycloak-user</a><u></u>><br>
<br>
<<a href="https://lists.jboss.org/__mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/__<u></u>mailman/listinfo/keycloak-user</a><br>
<<a href="https://lists.jboss.org/mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/<u></u>mailman/listinfo/keycloak-user</a><u></u>>__><span><br>
><br>
<br>
--<br>
Bill Burke<br>
JBoss, a division of Red Hat<br>
<a href="http://bill.burkecentral.com" target="_blank">http://bill.burkecentral.com</a><br></span>
______________________________<u></u>_____________________<span><br>
keycloak-user mailing list<br>
<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.jboss.org</a> <mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>><br>
<mailto:<a href="mailto:keycloak-user@lists." target="_blank">keycloak-user@lists.</a>__<a href="http://jboss.org" target="_blank"><u></u>jboss.org</a><br>
<mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>>><br></span>
<mailto:<a href="mailto:keycloak-user@lists" target="_blank">keycloak-user@lists</a>.<br>
<mailto:<a href="mailto:keycloak-user@lists" target="_blank">keycloak-user@lists</a>.>_<u></u>___<a href="http://jboss.org" target="_blank">jboss.org</a> <<a href="http://jboss.org" target="_blank">http://jboss.org</a>><br>
<mailto:<a href="mailto:keycloak-user@lists." target="_blank">keycloak-user@lists.</a>__<a href="http://jboss.org" target="_blank"><u></u>jboss.org</a><br>
<mailto:<a href="mailto:keycloak-user@lists.jboss.org" target="_blank">keycloak-user@lists.<u></u>jboss.org</a>>>><br>
<a href="https://lists.jboss.org/____mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/____<u></u>mailman/listinfo/keycloak-user</a><br>
<<a href="https://lists.jboss.org/__mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/__<u></u>mailman/listinfo/keycloak-user</a><u></u>><br>
<br>
<<a href="https://lists.jboss.org/__mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/__<u></u>mailman/listinfo/keycloak-user</a><br>
<<a href="https://lists.jboss.org/mailman/listinfo/keycloak-user" target="_blank">https://lists.jboss.org/<u></u>mailman/listinfo/keycloak-user</a><u></u>>__><span><br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
--<br>
Bill Burke<br>
JBoss, a division of Red Hat<br>
<a href="http://bill.burkecentral.com" target="_blank">http://bill.burkecentral.com</a><br>
<br>
<br>
--<br>
Bill Burke<br>
JBoss, a division of Red Hat<br>
<a href="http://bill.burkecentral.com" target="_blank">http://bill.burkecentral.com</a><br>
<br>
</span></blockquote><div><div>
<br>
-- <br>
Bill Burke<br>
JBoss, a division of Red Hat<br>
<a href="http://bill.burkecentral.com" target="_blank">http://bill.burkecentral.com</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div><br><div><div dir="ltr"><div style="text-align:left"><br></div></div></div>
</div></div></div></div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>Best Regards,</div><div><br></div><div>CK Yap</div><div>Technology Consultant</div><div><br></div><div>Tel: +65 6100 2788</div><div>Fax:+65 6233 9376</div><div><br></div><div>iZeno Pte Ltd</div><div>72 Bendemeer Road</div><div>Luzerne #05-28</div><div>Singapore 339941</div><div><br></div><div><br></div><div style="text-align:left">This communication contains information which may be confidential or privileged. The information is intended solely for the use of the individual or entity named above. If you are not the intended recipient,be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited.If you have received this communication in error, please notify me by telephone immediately.</div><div style="text-align:left"><br></div></div></div>
</div>