<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session]]></title><description><![CDATA[<p dir="auto">We were able to connect with OIDC via Keycloak with this guide (<a href="https://xen-orchestra.com/blog/xen-orchestra-5-80/" target="_blank" rel="noopener noreferrer nofollow ugc">https://xen-orchestra.com/blog/xen-orchestra-5-80/</a> Olivier Lambert being on top of everything as usual <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=c63c1619ba5" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> )<br />
Unfortunately when we disconnect, the user is not disconnected from Keycloak and the session stays active.<br />
We are using the .well-known/openid-configuration url so the logout url should be taken into account but we don't see any log showing further communication between XOA and Keycloak when we logout from XOA.<br />
Any idea is appreciated</p>
]]></description><link>https://xcp-ng.org/forum/topic/10412/authentication-with-oidc-keycloak-is-working-but-logout-doesn-t-disconnect-keycloak-session</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 06:57:37 GMT</lastBuildDate><atom:link href="https://xcp-ng.org/forum/topic/10412.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 05 Feb 2025 17:02:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session on Fri, 07 Feb 2025 14:51:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/dsmteam" aria-label="Profile: dsmteam">@<bdi>dsmteam</bdi></a> Yes I totally agree, a user who logs out from XO, might also have the choice to logout from all SSO'ed applications. That would be for the feature request list <img src="https://xcp-ng.org/forum/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=c63c1619ba5" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=";)" alt="😉" /></p>
]]></description><link>https://xcp-ng.org/forum/post/89383</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/89383</guid><dc:creator><![CDATA[nathanael-h]]></dc:creator><pubDate>Fri, 07 Feb 2025 14:51:54 GMT</pubDate></item><item><title><![CDATA[Reply to Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session on Fri, 07 Feb 2025 10:35:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nathanael-h" aria-label="Profile: nathanael-h">@<bdi>nathanael-h</bdi></a> In the contexte of SSO this makes sense to not logout the session of the IDP as it might be used for other SP but usually when one disconnect from an application (like logging out from Google), you get an option to log out from all other application.<br />
This would send the logout to the IDP ?</p>
]]></description><link>https://xcp-ng.org/forum/post/89370</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/89370</guid><dc:creator><![CDATA[dsmteam]]></dc:creator><pubDate>Fri, 07 Feb 2025 10:35:34 GMT</pubDate></item><item><title><![CDATA[Reply to Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session on Fri, 07 Feb 2025 10:29:39 GMT]]></title><description><![CDATA[<p dir="auto">Hello, thanks for the report. Actually XO does not implement Single Log Out. So it is expected that only the session related to XO is invalidated when the user click on the logout button.<br />
Maybe something to add in XO6 ping <a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/pdonias" aria-label="Profile: pdonias">@<bdi>pdonias</bdi></a> ?</p>
]]></description><link>https://xcp-ng.org/forum/post/89368</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/89368</guid><dc:creator><![CDATA[nathanael-h]]></dc:creator><pubDate>Fri, 07 Feb 2025 10:29:39 GMT</pubDate></item><item><title><![CDATA[Reply to Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session on Fri, 07 Feb 2025 10:29:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/olivierlambert" aria-label="Profile: olivierlambert">@<bdi>olivierlambert</bdi></a> We are in the process of purchasing entreprises licenses for a 4 hosts cluster. It's not a big deal so I'll wait untill we have support to open a ticket</p>
]]></description><link>https://xcp-ng.org/forum/post/89367</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/89367</guid><dc:creator><![CDATA[dsmteam]]></dc:creator><pubDate>Fri, 07 Feb 2025 10:29:03 GMT</pubDate></item><item><title><![CDATA[Reply to Authentication with OIDC (Keycloak) is working but logout doesn&#x27;t disconnect Keycloak session on Fri, 07 Feb 2025 10:18:51 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/forum/user/nathanael-h" aria-label="Profile: nathanael-h">@<bdi>nathanael-h</bdi></a> might take a look if we have the same problem and/or if it's "normal". Ideally, create a support ticket to get an investigation faster than via a community post.</p>
]]></description><link>https://xcp-ng.org/forum/post/89363</link><guid isPermaLink="true">https://xcp-ng.org/forum/post/89363</guid><dc:creator><![CDATA[olivierlambert]]></dc:creator><pubDate>Fri, 07 Feb 2025 10:18:51 GMT</pubDate></item></channel></rss>