On 6/3/2014 1:46 PM, Stan Silvert wrote:
2. On first login, you are required to change the admin password. What
other initial setup should be required? Change realm public key?
Change client secret? Others?
You should be able to self-bootstrap a new install on initial boot. Its
what we do for the Aerogear UPS server.
5. Should Keycloak audit log be enabled by default? If so, what should
be the expiration value?
Not sure. We're relying on tools like fail2ban for brute force
detection at the moment, but hope to get fail2ban like features in
Keycloak after 1.0 is released.
--
Bill Burke
JBoss, a division of Red Hat
http://bill.burkecentral.com