Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Identity Provider — for Keycloak™ / Troubleshooting

Troubleshoot DCA Hardened Identity Provider — for Keycloak™

SymptomCheckFix
Browser can't open http://localhost:8080/admin/Is the SSH tunnel (-L 8080:127.0.0.1:8080) still open? On the VM: curl -fsS http://127.0.0.1:9000/health/readyRe-open the tunnel. The first start takes a while — wait until health/ready reports UP.
'HTTPS required' when signing in from another machineAre you using plain HTTP to a non-loopback address?The master realm requires SSL for external requests. Use the tunnel, or configure HTTPS on 8443 (Configuration page).
Keycloak won't start after editing keycloak.confjournalctl -u keycloak -n 80db, cache, health and features are build options: run sudo -u keycloak /opt/keycloak/bin/kc.sh build after changing them. Check that certificate paths exist and are readable by the keycloak user.
The password in /root/keycloak-admin-credentials.txt is rejectedWas the bootstrap admin deleted or re-passworded?The file records the first-boot credential only. Sign in with the permanent administrator you created.

Logs & useful commands

Still stuck? Email support@dcassociatesgroup.com with the product name, cloud + region, instance size, and the output of the health command — first response within 1 business day, most tickets same-day.

Keycloak™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Keycloak project.