Uploaded image for project: 'Red Hat Internal Developer Platform'
  1. Red Hat Internal Developer Platform
  2. RHIDP-4684

[Docs] Update Keycloak configuration instructions to improve performance and security

Create Doc EPIC for Fe...Prepare for Y ReleasePrepare for Z ReleaseXMLWordPrintable

    • 3
    • False
    • Hide


    • False

      Description of problem:

      After investigating in this issue, it was discovered that when configuring Keycloak with RHDH, we need to:

      1. Set the Access Token Lifespan to >5 min (ideally 10 or 15 minutes) to fix the performance issue (unnecessary refresh token request sent for every API call).
      2. Enable the Revoke Refresh Token option to improve security so that the refresh token rotation strategy can be used.

      The current instructions to set up the Keycloak instance as seen here should include these additional recommendations.

      Additional info (Such as Logs, Screenshots, etc):

          There are no Sub-Tasks for this issue.

              ffloreth@redhat.com Fabrice Flore-Thébault
              rh-ee-jhe Jessica He
              RHIDP - Documentation
              0 Vote for this issue
              1 Start watching this issue
