FIPS compliance with keycloak? #1083
notwithoutcid
started this conversation in
Q&A
Replies: 1 comment 3 replies
-
Just to clarify, Keycloak is not a pre-requisite for STIG Manager, just a convenient open source choice. STIG Manager integrates with any standards-compliant OIDC Provider that issues JWT. Some non-open-source examples are Azure AD, Okta, Auth0, and Red Hat SSO (which provides Keycloak with FIPS). For Keycloak, perhaps this page might be helpful? |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Keycloak is not FIPS compliant.
Enforcing FIPS compliance is a CAT I STIG.
I'm very curious as to how .mil organizations are getting around this?
Beta Was this translation helpful? Give feedback.
All reactions