Keycloak Custom Modules for SRG hardening
November 1, 2022 ยท View on GitHub
This repository includes custom policies to exetend Keycloak's functionalities to support STIG-ready content for securing Keycloak against the Defense Information Systems Agency's (DISA) Authentication, Authorization and Accounting Server Security Requirements Guide.
Content available on the Maven Central Repository.
See the subdirectory READMEs for info on using the modules/inserting them into your Keycloak installation
Custom Event Listener
- Emails an admin on User and Admin Events.
Custom Password Policy
- Enforces 24 hours as the minimum lifetime for passwords.