It seems the truststore generated by the RH-SSO xPaaS image does not includes the underline JDK's cacerts... As a result the keycloak can't talk to any external endpoint using SSL cause it's truststore does not contains the standartd public CA's certs. The template should offer parameter telling if you the image should include the JDK's cacerts within the truststore used by the SSO for outgoing connections.