I think SAML would be ok so long as you have sticky sessions enabled with your load balancer.


On 8/3/16 6:07 PM, John D. Ament wrote:
Thanks Bill.  What if I'm primarily using SAML? Same session issue?

John

On Wed, Aug 3, 2016 at 5:17 PM Bill Burke <bburke@redhat.com> wrote:

It is required.  The auth code flow for OAuth is an out of band HTTP request so you may be loadbalanced to a machine that doesn't have the user session.  We have "sticky sessions" for out of band requests like this planned, but not implemented yet.


On 8/3/16 4:55 PM, John D. Ament wrote:
Hey,

I was wondering, is clustering actually required on the keycloak server if I have multiple deployed? Or will it read data from the database?

John


_______________________________________________
keycloak-user mailing list
keycloak-user@lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-user

_______________________________________________
keycloak-user mailing list
keycloak-user@lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-user