Conversation
Is it me or Keycloak became the de facto OSS IdP practically overnight? If so, yhy is that?
3
2
4

@buherator curious: What do you mean with overnight? Keycloak is at least 10 years old now and I’ve encountered instances of it many times. Maybe it got more popular since its donation to the CNCF in 2023?

1
0
0
@ulldma Can't tell about the exact time, but it felt like all of our clients suddenly started to using it a few years back. Maybe the timing is more about some local environmental change, but it's still interesting that it's always Keycloak not some other implementation esp. for OIDC.
1
0
0

@buherator swap our own bugs to somebody else’s bugs.

1
0
0

@buherator Ah I see. I‘d guess that for enterprises it counts a lot that Red Hat is the company behind Keycloak. (But it‘s only a guess)

1
0
1

@buherator funny that you mention keycloak on the very same day that we chose to disclose some vulnerabilities in it 🤷‍♂️ https://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/

1
1
0
@raptor wow nice! We've been discussing a Keycloak research idea for some time, really curious about what you found!
1
0
1

@buherator I wasn’t involved in this specific research. But my gut feeling is that there’s more of it…

0
0
0