Login to VCF Automation with Single Sign On (SSO) is getting failed due to expired or OIDC Key's not refreshing.
search cancel

Login to VCF Automation with Single Sign On (SSO) is getting failed due to expired or OIDC Key's not refreshing.

book

Article ID: 443326

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

When attempting to log in to the VCF Automation Provider or Tenant portal using either local administrator credentials or Single Sign-On (SSO) authentication, the login attempt fails.

Users may encounter the error message: “Your Single Sign-On attempt failed.

can see the following error  /opt/vmware/vcloud-director/logs/vcloud-container-debug.log: 

YYYY-MM-DD  | DEBUG | pool-jetty-127900 | OAuthFilter | Could not obtain user details from token | requestId=#######,request=GET https://<VCFA-FQDN/login/oauth,requestTime=1777966876
689,remoteAddress=##.##.##.##:55922,userAgent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 ...,accept=text/html application/xhtml+xml application/xml;q 0.9 image/avif image/webp image/apng /;q 0.8 application/signed-exchange;...,Host=<VCFA FQDN>
com.vmware.vcloud.api.presentation.service.BadRequestException: Invalid OAuth key settings for org <Org ID######>

YYYY-MM-DD | DEBUG | pool-jetty-127900 | OAuthFilter | Could not obtain user details from token

 

Environment

VCF Automation 9.0.2

Cause

The OIDC Key Rotation job has likely entered a "stuck" state due to a rare scheduler timing race or is assigned to an inactive cell. This prevents the renewal of OAuth keys, leading to SSO failures.

 

Resolution

 To resolve this issue, please open a Support Request with Broadcom Technical Support and note this Article ID (443326) in the problem description. For more information, see Creating and managing Broadcom support cases.