Secure authentication with Keycloak

Development of a centralised single sign-on platform for user management and access control

Challenge

Jungheinrich faces the challenge of integrating several internal and external intralogistics applications into bespoke solutions for process visualisation and control. As these applications do not have a centralised identity management system, customers previously had to log in separately to each application, which was not only time-consuming but also led to increased maintenance costs and security risks, as some of the authentication mechanisms used were outdated.
The aim was to create a modern, future-proof solution that meets current security standards, such as CRA/NIS 2, and can be integrated into existing systems.

ITQ solution

Single Sign-On (SSO) enables users to log in once and then access multiple applications and services – without having to authenticate again – and thus meets the requirements set out above. We have implemented a modular Identity and Access Management (IAM) solution by utilising and configuring Keycloak. Authentication is carried out via the Authorisation Code Flow (OpenID Connect) – a tried-and-tested, secure method for users to log in to web-based applications.

Our implementation included:

  • Integration of existing LDAP and Active Directory structures
  • Setting up Single Sign-On (SSO) across multiple applications
  • Introduction to role-based access control (RBAC)
  • Deployment within the customer’s infrastructure (Windows Server)
  • Monitoring and Logging

Results & Benefits

  • Single Sign-On (SSO): One-time login for all internal and external applications
  • Centralised user and role management: Consistent administration across all systems
  • Enhanced security: standardised protocols (OAuth 2.0, OpenID Connect) and secure token flows
  • High scalability: cloud-ready, container-ready
  • Seamless integration: Connecting existing directory services and applications
  • Reduced administrative workload: automated user management and role-based access control
  • Future-proof: Can be expanded to accommodate new applications, external partners or cloud services
About the client:
Jungheinrich AG is a leading global provider of intralogistics solutions, with its headquarters in Hamburg. The company develops and implements bespoke systems for material flow, warehouse technology and industrial trucks – including automation and digital software components.

Further information:

Sector: Logistics, Mechanical Engineering
Period: May 2025 – October 2025

You might also be interested in: