Lightning Talk: Surviving Certificate Expiry in Enterprise Keycloak: Per-Client Key… H. Wada
Keycloak Certificate Expiry Key Rotation Oidc Saml Jwks Enterprise Security Identity Management Realm Keys Keycloak Upstream Authentication Cloud Native
This lightning talk addresses the critical issue of Keycloak's hardcoded 10-year realm signing certificate expiry approaching for organizations who adopted it in the late 2010s. It explains why realm-wide key rotation is extremely risky in enterprise environments with many OIDC and SAML integrations, and presents a proposed solution: per-client signing key selection to enable gradual, safer key migration. Targeted at enterprise Keycloak administrators and architects managing production identity systems.