Further reading
Refer to the following links for more information on the topics covered in this chapter:
- Keycloak user and session management: https://www.keycloak.org/docs/latest/server_admin/#user-session-management
- Mutual TLS client authentication: https://www.keycloak.org/docs/latest/server_admin/#advanced-settings
- Token revocation endpoint: https://tools.ietf.org/html/rfc7009
- Keycloak threat model mitigation: https://www.keycloak.org/docs/latest/server_admin/#compromised-access-and-refresh-tokens
- OAuth 2.0 threat model and security considerations: https://tools.ietf.org/html/rfc6819
- OAuth 2.0 security best current practice: https://www.keycloak.org/docs/latest/server_admin/#_account-service
Join our community on Discord
Join our community’s Discord space for discussions with the authors and other readers: