TLS in Keycloak
Enabling SSL/TLS in Keycloak
Using tls crt and key
Keycloak can be configured to load the required certificate infrastructure using files in PEM format or from a Java Keystore. When both alternatives are configured, the PEM files takes precedence over the Java Keystores.
./kc.sh start --hostname=keycloak-poc\
--http-port=80\
--proxy reencrypt\
--https-certificate-file=/root/certs/tls.crt \
--https-certificate-key-file=/root/certs/tls.key\
> keycloak.stdout 2>&1 & echo "$!" > keycloak.pid
Using java Keystore
From #Tutorials / https://www.keycloak.org/server/enabletls:
When no keystore file is explicitly configured, but
http-enabledis set to false, Keycloak looks for aconf/server.keystorefile.