Lightning Talk: Surviving Certificate Expiry in Enterprise Keycloak: Per-Client Key… H. Wada

CNCF
AI summary

This lightning talk addresses the critical issue of Keycloak's hardcoded 10-year realm signing certificate expiry approaching for organizations who adopted it in the late 2010s. It explains why realm-wide key rotation is extremely risky in enterprise environments with many OIDC and SAML integrations, and presents a proposed solution: per-client signing key selection to enable gradual, safer key migration. Targeted at enterprise Keycloak administrators and architects managing production identity systems.