Cookie secure flag not applied using "external requests" in "SSL required" parameter

Hi,

Recently we had a security audit which highlighted that the “Secure” flag is not present on Keycloak cookies although we configured the “Require SSL” setting to “External requests”.

I checked all open and closed issues on GitHub but could not find anything related to a potential malfunction of “Require SSL” setting. I also checked the release notes. FYI, we are using v12.04.

Is it a known issue? Have other users noticed this behavior? If yes, how did you solve the problem?

Thank you for your advice!