Skip to content

Why Not Use Keycloak? #357

@nelsonic

Description

@nelsonic

Someone asked the question on our call today: "why don't we just use keycloak for auth?"

https://github.com/keycloak/keycloak
image

In a single word: Security
https://github.com/keycloak/keycloak/security
image

Session hijacking, DoS, XSS, Leak of LADP, Path traversal ... 😬
Unless you plan to actively maintaining your keycloak instance with regular updates,
it's only a matter of time before another critical vulnerability appears and your auth is hacked.

It's a good thing that RedHat are using it: https://access.redhat.com/products/red-hat-build-of-keycloak
Means that security-minded people have their eyes on it. 👀
But unless you have a system to automatically update and reboot your instance, it will get out-of-date fast!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions