基于Keycloak 3.4.2实现跨浏览器共享登录功能问询
Alright, let's work through getting cross-browser single sign-on (SSO) working with your Keycloak 3.4.2 and Tomcat 7 setup. I’ve helped with similar configurations before, so here’s a practical, step-by-step guide:
Cross-browser SSO relies on Keycloak's persistent session tracking, not just browser-local cookies. Let’s start with the core Keycloak settings:
Enable Realm-Wide SSO & Remember Me
Head to your Realm in the Keycloak admin console → Settings → SSO tab:- Ensure
SSO Session IdleandSSO Session Maxare set to reasonable values (default 30 mins / 24 hrs works for most use cases) - Toggle on
Remember Me—this generates a persistent device-level cookie that’s key for cross-browser access
- Ensure
Update Both App Client Settings
For each of your Servlet app clients in the Realm:- Go to Settings tab:
- Set
Access Typetoconfidential(required for server-side web apps) - Check
Standard Flow Enabled(the authorization code flow for web apps) - Check
Remember Me Enabled—this lets the client use the realm’s remember-me functionality
- Set
- Go to Advanced tab:
- Set
Cookie SameSitetoNone(critical for cross-browser/cross-domain scenarios; pair with HTTPS, asNonerequires secure cookies) - Verify
Valid Redirect URIsincludes both apps’ full callback paths (e.g.,https://webapp1.yourdomain.com/*andhttps://webapp2.yourdomain.com/*)
- Set
- Go to Settings tab:
Your Tomcat adapters need to recognize Keycloak’s persistent remember-me cookie and handle session handoffs correctly:
Update
keycloak.jsonfor Both Apps
In each app’sWEB-INF/keycloak.json, add therememberMeflag to enable support for the persistent cookie:{ "realm": "your-realm-name", "auth-server-url": "https://your-keycloak-server/auth", "ssl-required": "external", "resource": "webapp1-client-id", "credentials": { "secret": "your-client-secret" }, "confidential-port": 0, "rememberMe": true, "use-resource-role-mappings": true }Adjust Tomcat Context Settings
If you’re configuring the Keycloak valve globally in Tomcat’scontext.xml, add therememberMe="true"attribute:<Valve className="org.keycloak.adapters.tomcat.KeycloakAuthenticatorValve" rememberMe="true"/>For cross-domain cookie support, update the
CookieProcessorincontext.xml(works for Tomcat 7.0.100+; if you’re on an older version, consider upgrading Tomcat for proper SameSite cookie handling):<CookieProcessor sameSiteCookies="None" secure="true"/>
Here’s how the flow will work once configured correctly:
User opens Browser A, navigates to webapp1 → redirected to Keycloak login page → user enters credentials and checks the Remember Me box → logs into webapp1 successfully. Keycloak sets a persistent
KEYCLOAK_REMEMBER_MEcookie on the user’s device (valid for the realm’s remember-me timeout). Later, the user opens Browser B (same device) and navigates to webapp2 → Keycloak adapter detects theKEYCLOAK_REMEMBER_MEcookie, automatically requests a token from Keycloak, and logs the user into webapp2 without prompting for credentials.
Critical Notes for Success:
- HTTPS is Non-Negotiable: The
KEYCLOAK_REMEMBER_MEcookie uses theSecureflag, so your Keycloak server and both web apps must run over HTTPS (use self-signed certs for testing, valid CA certs for production). - Same Device Only: This flow works for the same physical device, since the cookie is stored locally. Cross-device SSO would require additional mechanisms like OIDC device authorization, which isn’t relevant here.
- Test with Clean State: If you hit issues, clear all browser cookies first to eliminate stale session data interfering with testing.
- Cross-Domain Cookies Not Sent: If your apps are on subdomains, set the
Cookie Domainin your Realm’s Settings → Cookies tab to your parent domain (e.g.,yourdomain.com) so the remember-me cookie is shared across subdomains. - Remember Me Not Triggering: Double-check that the client has
Remember Me Enabledchecked,keycloak.jsonhas"rememberMe": true, and users are actually checking the Remember Me box during login. - Adapter Version Mismatch: Ensure your Tomcat Keycloak adapter is version 3.4.2 (matching your Keycloak server) — version mismatches cause silent failures and compatibility bugs.
内容的提问来源于stack exchange,提问作者Ernest Poldrige

