This topic tells you how to resolve common errors that can arise when you configure a single sign-on partnership between two Single Sign‑On for VMware Tanzu Application Service service plans, one acting as an Identity Provider (IDP) and one acting as a Relying Party (RP).
The service provider login screen looks as follows:
You see an error similar to the following screenshot:
You might have configured your OAuth client ID incorrectly.
You see an error similar to the following screenshot:
You may have configured your OAuth client secret incorrectly.
You see an error similar to the following screenshot:
openid
scope in the IDP configuration on the RP service plan.openid
scopes.You see an error similar to the following screenshot:
The username you used might not have a value mapped to it. In the IDP attributes, map the “username” attribute to “username.”
You see an error similar to the following screenshot:
You may have configured the authorized redirect URI incorrectly. Confirm that your callback URL is entered correctly as an authorized redirect URI for the client configurations on the IDP service plan.