Error: oauth2.request.invalid.redirecturl during SSO login in standalone VMware NSX 4.2.x
search cancel

Error: oauth2.request.invalid.redirecturl during SSO login in standalone VMware NSX 4.2.x

book

Article ID: 447621

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • The Single Sign-On (SSO) configuration script was executed using an individual NSX Manager node FQDN for the -n parameter instead of the NSX Cluster VIP FQDN.
    Note:  See the following KB for further details on the above 'Procedure to configure SSO on a standalone NSX 4.2'.
  • Attempts to log in to NSX Manager via SSO fail.
  • The browser or NSX UI displays the following error:
    "oauth2.request.invalid.redirecturl Invalid redirect URL specified in authorize request""

Environment

VMware NSX 4.2.x

Cause

The SSO configuration script was executed using an individual NSX Manager node FQDN for the -n parameter instead of the NSX Cluster VIP FQDN.

NSX only supports a single redirect URI for the entire cluster. If the redirect URI registered in the Identity Provider does not match the URL used to access the login page, the authentication request is rejected.

Resolution

This is a condition that may occur in a VMware NSX environment.

Workaround
If you believe you have encountered this issue, open a support case with Broadcom Support and refer to this KB article.

For more information, see Creating and managing Broadcom support cases.