Authentication Failure in VCFA 9.1 when using VCF Identity Broker as OIDC Provider
search cancel

Authentication Failure in VCFA 9.1 when using VCF Identity Broker as OIDC Provider

book

Article ID: 451738

calendar_today

Updated On:

Products

VCF Automation VCF Operations

Issue/Introduction

When attempting to log in to VMware Cloud Foundation Automation (VCFA) 9.1 using VCF Identity Broker configured as an OpenID Connect (OIDC) Identity Provider, the authentication fails.

  • Users are immediately redirected to the following URL: /login/ssoFailure?service=provider
  • The login process does not complete successfully.

Environment

  • VCF Automation 9.1
  • VCF Operations 9.1

Cause

This issue occurs because the VCF SSO (vIDB with OIDC) must be joined and configured within the VCF Operations management interface to establish the0 integration for VCFA.

Resolution

Follow these steps to correctly set up VCF SSO for VCFA integration:

Step 1: Clear Existing OIDC Configuration in VCFA

  1. Log in to the VCFA interface.
  2. Navigate to the identity settings and delete any existing OIDC configuration.
    • Note: You must delete the associated users first before removing the configuration.

Step 2: Join VCF SSO in VCF Operations

  1. Log in to the VCF Operations console.
  2. Navigate to Manage > Identity & Access > VCF SSO Overview.
  3. Select the VCF Management tab.
  4. Locate the Automation component, tick the checkbox, and click JOIN VCF SSO.
  5. Confirm the operation as directed by the UI prompts.

Step 3: Configure Access Control

  1. Return to the VCF SSO Overview screen.
  2. Under the VCF SSO section, click on the vIDB FQDN link.
  3. Navigate to Access Control.
  4. Assign the appropriate privileges to the required users to restore access.

 

Additional Information

This procedure is required for the Provider ("System") organization to function correctly with VCF Identity Broker. For more details, refer to the Broadcom TechDocs page on Managing Identity Providers in VCF Automation.