Authentication with external Identity provider fails with token signature validation failed error

Solution Verified - Updated -

Issue

  • Integrated an external identity provider in RH-SSO but when trying to login using the external identity provider following error is observed in the logs
ERROR [org.keycloak.broker.oidc.AbstractOAuth2IdentityProvider] (default task-6) Failed to make identity provider oauth callback: org.keycloak.broker.provider.IdentityBrokerException: token signature validation failed
        at org.keycloak.keycloak-services@15.0.8.redhat-00001//org.keycloak.broker.oidc.OIDCIdentityProvider.validateToken(OIDCIdentityProvider.java:556)
        at org.keycloak.keycloak-services@15.0.8.redhat-00001//org.keycloak.broker.oidc.OIDCIdentityProvider.validateToken(OIDCIdentityProvider.java:544)
        at org.keycloak.keycloak-services@15.0.8.redhat-00001//org.keycloak.broker.oidc.OIDCIdentityProvider.getFederatedIdentity(OIDCIdentityProvider.java:370)

Environment

  • Red Hat Single Sign-On (RH-SSO)
  • Red Hat build of Keycloak (RHBK)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content