This is fixed in master and will be released with 1.9.2 in 1 or 2 weeks.
On 3/21/2016 11:25 AM, Xiao Ma wrote:
Thank you, Bill! I am wondering what is our rough estimate on when
are
going to release 1.9.2.Final.
Best Regards,
Xiao
On Mon, Mar 21, 2016 at 10:26 AM, Bill Burke <bburke(a)redhat.com
<mailto:bburke@redhat.com>> wrote:
I think this is a bug. We probably don't refresh the token that
is obtained by the "child" IDP.
https://issues.jboss.org/browse/KEYCLOAK-2691
On 3/20/2016 10:58 AM, Xiao Ma wrote:
> Hi,
>
> I configured a OIDC identity provider by selecting the |OpenID
> Connect v1.0| identity provider from the drop-down box on the top
> right corner of the identity providers table in Keycloak's Admin
> Console. During the configuration process, I also configure
> "Logout Url" for the IDP logout url.
>
> When I try to logout to the external IDP, the browser is
> redirected to the external IDP to perform the logout. I can see
> some URL as follows:
>
> https://*keycloakdev.xxxxxxx.com
>
<
http://keycloakdev.xxxxxxx.com>*/auth/realms/*Internal*/protocol/openi...!
> raAz-YPO
>
cwyvmsOJ23bSrDR3Oa2HZ5JEGzs9IVFyhzQXJuDBCBWcPZl-eNxnxdGkNJBd7Cx03iWsUVUE9NeJYPjeZ5s8rmDtaX38V6JywugWRby5rfSZDLpu7xoGj6a_ZSZEXUfktwCMHS0Jnz_1M778Bmka0TcD1bvIpuqVl4-YQf2P3UZWgxqFQoNDVegZUNuekqUQyJiuRjlQuhITg5tDYfy2DbhkqVsN2gR7mUp21WNx2S5pG5Hb9cXajIVGR6SmW4qKA:
>
> "keycloakdev.xxxxxxx.com <
http://keycloakdev.xxxxxxx.com>" is
> where the externalIDP is located. "Internal" is the name of the
> realm. The parameters "state" and "id_token_hint" are
appended to
> the endpoint logout URL automatically during the logout process.
>
> However, this process failed because I got "Session Not Active"
> error in the UI. After some investigations, I found this "Session
> Not Active" error seems to be related to the value of Realm
> Setting —> Tokens —> Access Token Lifespan I configured.
> The default value is 5 minutes, if I trigger the logout within 5
> minutes, I can logout to the external IDP successfully. If I do
> the logout after 5 minutes, I will get this ""Session Not Active"
> error. Is this the expected behavior? Do I have to bump up the
> value of "Access Token Lifespan" to get a longer session for the
> logout purpose?
>
> Thanks a lot for the help!
>
> Xiao
>
>
>
>
>
>
>
>
>
>
>
>
>
>
> _______________________________________________
> keycloak-user mailing list
> keycloak-user(a)lists.jboss.org <mailto:keycloak-user@lists.jboss.org>
>
https://lists.jboss.org/mailman/listinfo/keycloak-user
--
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com
_______________________________________________
keycloak-user mailing list
keycloak-user(a)lists.jboss.org <mailto:keycloak-user@lists.jboss.org>
https://lists.jboss.org/mailman/listinfo/keycloak-user