keycloak/keycloak
Client credentials hashing (encryption / decryption)
Open
#15,567 opened on Nov 18, 2022
area/weaknesshelp wantedkind/featureteam/core-clients
Repository metrics
- Stars
- (34,398 stars)
- PR merge metrics
- (Avg merge 6d 19h) (384 merged PRs in 30d)
Description
Description
Client credentials are currently stored as clear text. To improve Keycloak security, client credentials/secrets should be optionally be stored as hashes. A new pluggable SPI would be a great way to achieve this.
References:
- https://issues.redhat.com/browse/KEYCLOAK-10774
- https://github.com/keycloak/keycloak-community/blob/main/design/secure-credentials-store.md
Discussion
No response
Motivation
My Company, Transatel, is providing client credentials to our customers in order to use some of our APIs. These APIs give access to personal data, so, in order to respect the GDPR regulations, we must store these secrets in a secure way so that the secrets cannot be retrieved.
Details
No response