OpenShift Commons Gathering included two talks about Keycloak, an open-source identity and access management solution for modern applications and services, built on top of industry security standard protocols.

The following topics were discussed:

  1. Keycloak: the Open Source IAM for Modern Applications
  2. Keycloak for Securing APIs a Case Study

Keycloak: the Open Source IAM for Modern Applications

This first talk was about how to secure applications by taking advantage of authentication and authorization mechanisms with all the flexibility you need and in a streamlined way.

The speaker, Alexander Schwartz, has worked with Keycloak for eight years; he’s now a part of the Engineering Team at Red Hat. Alexander presented an overview of the main functionalities of Keycloak to make applications secure by taking advantage of robust protocols such as OpenID Connect and OAUTH 2.0. 

Alexander focuses on AuthZ and AuthN functionalities that are critical for applications to ensure that any access has been validated for authentication and authorization before accessing the application. Keycloak gives flexibility to developers, who can integrate with different enterprise mechanisms, such as any stores from LDAP to relational databases. Additionally, it provides features to strengthen security, such as Forget Password, One Time Password, and Update Password Policies.

Some of the highlights are:

  • Administrators can control the functionality by accessing a UI or a REST API, such as forgetting a password, remembering me, or enabling user registration.
  • Keycloak supports User Federation and Identity Brokering.
  • Enable continuous everything by exporting and importing realms, accessing REST API and CLI. 
  • Keycloak can be used in any cloud or non-cloud environment.

 

Keycloak for Securing APIs a Case Study

The speaker, Yuichi Nakamura, Ph.D. Hitachi, Ltd. Director, shared challenges finding a robust solution for APIs that run everywhere. The speaker focused on a Japanese bank case that required a robust and comprehensive solution for API management solutions for containers on OpenShift.

Some of the highlights are:

  • How security is necessary to secure any API access from different systems and users. 
  • A security mechanism is implemented with Keycloak based on token generation supporting different protocols. 
  • High-level security is required, especially for the financial and public sectors. 
  • FAPI (Financial grade API) is a security profile described as getting attention globally and integrated with OAUTH 2.0 and OpenID.

undefined-May-10-2023-04-50-32-2489-PM

Learn more about this security profile on the case study: 

 


저자 소개

Valentina Rodriguez is a Principal Technical Marketing Manager at Red Hat, focusing on the developer journeys in OpenShift and emerging technologies. Before this role, she worked with high-profile customers, helping them adopt new technologies, and worked closely with developers and platform engineers. Her background is in software engineering. She built software for 15 years, working in diverse roles from Developer to Tech Lead and Architect, from retail, healthcare, financial, e-commerce, telco, and many other industries. She loves contributing to the community and the industry and has spoken at conferences such as O'Reilly, KubeCon, Open Source Summit, Red Hat DevNation Day, and others. She's very passionate about technology and has been pursuing several certifications in this space, from frameworks to Kubernetes and project management. She possesses a Master's in Computer Science and an MBA.

UI_Icon-Red_Hat-Close-A-Black-RGB

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Virtualization icon

가상화

온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래