[keycloak-user] Encrypt samlp:Response with Keycloak

Hynek Mlnarik hmlnarik at redhat.com
Wed Apr 19 03:17:38 EDT 2017


On Tue, Apr 18, 2017 at 3:04 PM, Metehan Selvi <mselvi78 at gmail.com> wrote:
> Hi there,
> I configured OpenAM as IDP and Keycloak as SP together.
> I use the sales-post-enc - example App.

Do you mean using Keycloak adapters as SP and OpenAM as IdP, or OpenAM
as brokered IdP while using Keycloak as IdP for sales-post-enc SP?

> SAML-AuthnRequests and SAML-Repsonses are working.
> ( Encryption disabled)
>
> When I enable Encrpytion in OpenAM and in the app, the SAML Repsonses
> cannot be encrypted in OpenAM as it throws Exceptions with Http 500
> Responses.

Is it OpenAM or Keycloak returning HTTP 500 error? If Keycloak, can
you share details of the exception?

> How do I get out from the Problem ?
>
> When I want to export the SPSSODescriptor form Keycloak for the OpenAM IDP,
> it contains only the KeyDescriptor for Signing. Normally it should be also
> possible to export the KeyDescriptor for encryption. Is this maybe the
> failure?
>
> Other ideas to get rid of the problem.. ?!
>
> Cheers
> Metehan Selvi
> _______________________________________________
> keycloak-user mailing list
> keycloak-user at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-user



-- 

--Hynek


More information about the keycloak-user mailing list