The issuer is based on the URL used to access Keycloak. If the application requests the token with the DNS name that'll be the issuer, if it requests the token with the IP address that'll be the issuer.

On 12 May 2016 at 15:55, Brian Cook <bcook@redhat.com> wrote:
I have a keycloak server in a test environment with several realms on it.  It noticed yesterday that the issue in tokens from one realm seems to use the DNS name while in tokens from another realm it uses the the IP address.  When is the issuer determined, and is it possible to change it?

Thanks,
Brian

_______________________________________________
keycloak-user mailing list
keycloak-user@lists.jboss.org
https://lists.jboss.org/mailman/listinfo/keycloak-user