Home / Docs / DCA Hardened Identity Provider — for Keycloak™ / Troubleshooting
| Symptom | Check | Fix |
|---|---|---|
| Browser can't open http://localhost:8080/admin/ | Is the SSH tunnel (-L 8080:127.0.0.1:8080) still open? On the VM: curl -fsS http://127.0.0.1:9000/health/ready | Re-open the tunnel. The first start takes a while — wait until health/ready reports UP. |
| 'HTTPS required' when signing in from another machine | Are you using plain HTTP to a non-loopback address? | The master realm requires SSL for external requests. Use the tunnel, or configure HTTPS on 8443 (Configuration page). |
| Keycloak won't start after editing keycloak.conf | journalctl -u keycloak -n 80 | db, cache, health and features are build options: run sudo -u keycloak /opt/keycloak/bin/kc.sh build after changing them. Check that certificate paths exist and are readable by the keycloak user. |
| The password in /root/keycloak-admin-credentials.txt is rejected | Was the bootstrap admin deleted or re-passworded? | The file records the first-boot credential only. Sign in with the permanent administrator you created. |
curl -fsS http://127.0.0.1:9000/health/ready → status UPKeycloak™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Keycloak project.