You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Mac环境下Keycloak 3.4.3连接openid.net测试时被拒绝求助

Hey there, let's walk through troubleshooting this connection refused issue you're hitting with Keycloak and the openid.net test platform. I've dealt with this exact scenario a few times, so here's what to check first:

Troubleshooting Connection Refused for Keycloak OpenID Testing

1. First, Confirm Keycloak is Actually Reachable Locally

Connection refused usually means the test tool can't even talk to your Keycloak instance. Start with the basics:

  • Run this command from your machine to test the discovery endpoint directly:
    curl http://localhost:8080/auth/realms/master/.well-known/openid-configuration
    
    Adjust the port or /auth path if you changed Keycloak/Wildfly defaults. If this fails, your instance isn't running properly, or there's a port conflict (check if another app is using 8080 with netstat -anp | grep 8080 on Linux or netstat -ano | findstr :8080 on Windows).
  • Check the Wildfly startup logs—look for a line like JBAS015874: WildFly Full [version] started to confirm it's fully up and running without errors.

2. Fix Network Binding (Common Gotcha!)

By default, Wildfly/Keycloak often binds only to localhost (127.0.0.1). That means even if the test tool is on the same machine, it might not reach Keycloak if it uses your public IP or hostname instead of localhost.

  • Restart Wildfly with the -b 0.0.0.0 flag to bind to all network interfaces:
    ./standalone.sh -b 0.0.0.0
    
  • After restarting, test the discovery endpoint using your machine's actual IP (e.g., http://192.168.1.100:8080/auth/realms/master/.well-known/openid-configuration) to confirm it's reachable outside the localhost loopback.

3. Check Firewall & Port Access

If the openid.net tool is on a different machine, or your local firewall is blocking traffic:

  • On Linux, temporarily allow traffic to your Keycloak port (e.g., 8080) with:
    sudo iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
    
  • On Windows, add an inbound rule in Windows Defender Firewall to allow traffic on your Keycloak port.
  • If you're on a corporate network, make sure your IT team hasn't blocked outbound traffic to your local instance (some corporate proxies interfere with local loopback requests too).

4. Double-Check Your Endpoint URLs

It's easy to copy the wrong endpoint from the Keycloak admin console:

  • The discovery endpoint should follow this pattern: http://<your-keycloak-ip>:<port>/auth/realms/<your-realm>/.well-known/openid-configuration
    • Note: Newer Keycloak versions might omit the /auth path, so adjust if needed.
  • If you created a custom realm for testing, make sure you're using that realm's endpoint—not the default master realm unless that's what you configured.

5. Proxy/Reverse Proxy Interference

If you're running Keycloak behind a proxy:

  • Ensure the proxy is correctly forwarding traffic to Keycloak's port.
  • Update Wildfly's standalone.xml to set proxy-address-forwarding=true so Keycloak recognizes the proxy's requests.

If you've tried all these steps and still have issues, share a bit more info:

  • Your exact Keycloak and Wildfly versions
  • The full endpoint URLs you're using in the openid.net tool
  • Any error messages from the Wildfly logs when you attempt the test

内容的提问来源于stack exchange,提问作者coffeesnob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:49:18