camunda / issues

4 stars 0 forks source link

Upgrade supported Keycloak version to 22.x and 21.x #272

Closed engineering-issue-sync-app[bot] closed 1 year ago

engineering-issue-sync-app[bot] commented 1 year ago

Related to https://github.com/camunda/product-hub/issues/1512

Description of the related problem to solve Keycloak releases a new major version every 3-6 months while dropping support for the older versions. This leads to unfixed security vulnerabilities found over time both in Keycloak and in it's libraries.

Describe a possible solution According to https://confluence.camunda.com/pages/viewpage.action?spaceKey=HAN&title=Camunda+8+Supported+Environments (TODO: document strategy there) in the next 8.3 release we should support Keycloak 22.0 and 21.1. Therefore we need to upgrade the libraries in our code, upgrade documentation and the default version in helm charts

Acceptance criteria

Security considerations

E2E test cases

Additional context

:robot: This issue is automatically synced from: source

engineering-issue-sync-app[bot] commented 1 year ago

@MaxTru we are working on the issue with high priority. With my first analysis I assume that Keycloak 22.0 might not pick up the right configuration from our helm charts. @Ben-Sheppard will follow up with the distribution team to get it confirmed and fixed

:robot: This comment from @dlavrenuek is automatically synced from: source