HCL Domino - Web Federated Login Issue with Keycloak v26.6.0+ ·

If you are using Keycloak as an Identity Provider (IdP) for HCL Domino and have Web Federated Login enabled, exercise caution before upgrading to Keycloak v26.6.0 or newer. Starting with v26.6.0, Keycloak possibly changed how it validates the RFC8707 resource parameter, which effectively breaks Domino Web Authentication over OIDC. Downgrading to Keycloak v26.5.7 resolves the issue while the root cause is investigated.
This is a companion discussion topic for the original entry at https://milan.matejic.at/posts/domino_login_issue_with_keycloak_v2606/