"oauth2.request.invalid.redirecturl Invalid redirect URL specified in authorize request""VMware NSX 4.2.x
The SSO configuration script was executed using an individual NSX Manager node FQDN for the -n parameter instead of the NSX Cluster VIP FQDN.
NSX only supports a single redirect URI for the entire cluster. If the redirect URI registered in the Identity Provider does not match the URL used to access the login page, the authentication request is rejected.
This is a condition that may occur in a VMware NSX environment.
Workaround
If you believe you have encountered this issue, open a support case with Broadcom Support and refer to this KB article.
For more information, see Creating and managing Broadcom support cases.