-
Notifications
You must be signed in to change notification settings - Fork 7.9k
Closed
Labels
area/dist/quarkushelp wantedkind/featureCategorizes a PR related to a new featureCategorizes a PR related to a new featurerelease/26.0.16release/26.2.10release/26.4.1release/26.5.0team/cloud-native
Description
Description
Secure Client-Initiated Renegotiation is enabled by default on Keycloak:
While it is possible to disable this on an installation, I would like to request this as a default setting.
Value Proposition
Secure Client-Initiated Renegotiation can be abused as a Denial-of-Service condition. Having this option disabled by default will remove/mitigate that potential avenue of attack.
Goals
As a security platform, Keycloak should follow a secure by default approach. This would allow for the closing of a potential attack vector which is present by default.
Non-Goals
N/A
Discussion
Notes
The easiest way I know of would be to add this to JAVA_OPTS in kc.sh.
3XC1T3D, ahus1 and cpuschma
Metadata
Metadata
Assignees
Labels
area/dist/quarkushelp wantedkind/featureCategorizes a PR related to a new featureCategorizes a PR related to a new featurerelease/26.0.16release/26.2.10release/26.4.1release/26.5.0team/cloud-native