WSO2 IS与Spring Boot配置Issuer不匹配问题求助
I'm following the official WSO2 IS guide for Spring Boot integration, but I'm hitting an issuer mismatch error. Here's my setup:
Spring Boot OIDC Configuration (application.yaml)
provider: host: https://localhost:9443 #Change the host spring: security: oauth2: client: registration: wso2: client-name : WSO2 Identity Server client-id: aXOWlNxT0aKIfKIeH82IfsmLjsYa #Change client-id client-secret: CVl_vmEYqRuZddBu3ZCYQQwGtYsa # Change client-secret authorization-grant-type: authorization_code scope: openid provider: wso2: issuer-uri: ${provider.host}/oauth2/oidcdiscovery thymeleaf: cache: false
Error Stack Trace
Caused by: java.lang.IllegalStateException: The Issuer "https://localhost:9443/oauth2/token" provided in the configuration metadata did not match the requested issuer "https://localhost:9443/oauth2/oidcdiscovery" at org.springframework.util.Assert.state(Assert.java:97) ~[spring-core-5.3.2.jar:5.3.2] at org.springframework.security.oauth2.client.registration.ClientRegistrations.withProviderConfiguration(ClientRegistrations.java:239) ~[spring-security-oauth2-client-5.4.2.jar:5.4.2] at org.springframework.security.oauth2.client.registration.ClientRegistrations.lambda$oidc$0(ClientRegistrations.java:158) ~[spring-security-oauth2-client-5.4.2.jar:5.4.2]
WSO2 IS is running with default configurations, and the identity provider setup is correct. How can I fix this issuer mismatch issue?
Let me help you fix this issuer mismatch issue—it’s a common gotcha when integrating Spring Boot with WSO2 IS 5.11.0. Here’s what’s going wrong and how to fix it:
1. Fix the issuer-uri in Your Spring Config
The root problem is that you’re using the wrong OIDC discovery endpoint. WSO2 IS 5.11.0 follows the standard OIDC discovery spec, which uses the endpoint /.well-known/openid-configuration under the OAuth2 context.
Update your provider.wso2.issuer-uri to this:
issuer-uri: ${provider.host}/oauth2/.well-known/openid-configuration
When Spring Security hits this endpoint, it’ll fetch the correct OIDC metadata, including the proper issuer value (https://localhost:9443/oauth2), which will match the expected value.
2. Fallback: Configure Endpoints Explicitly
If the automatic discovery still gives you trouble, you can manually define all required OAuth2/OIDC endpoints for WSO2 IS. This avoids any confusion with discovery metadata:
provider: host: https://localhost:9443 # Keep your host config spring: security: oauth2: client: registration: wso2: client-name : WSO2 Identity Server client-id: aXOWlNxT0aKIfKIeH82IfsmLjsYa client-secret: CVl_vmEYqRuZddBu3ZCYQQwGtYsa authorization-grant-type: authorization_code scope: openid redirect-uri: "{baseUrl}/login/oauth2/code/wso2" # Match this to your WSO2 client's redirect URI provider: wso2: issuer-uri: ${provider.host}/oauth2 # Correct issuer value authorization-uri: ${provider.host}/oauth2/authorize token-uri: ${provider.host}/oauth2/token user-info-uri: ${provider.host}/oauth2/userinfo jwk-set-uri: ${provider.host}/oauth2/jwks
3. Double-Check Your WSO2 IS Client Setup
Don’t forget to verify these in your WSO2 IS service provider configuration:
- Ensure the redirect URI matches exactly what’s in your Spring config (the default is
http://localhost:8080/login/oauth2/code/wso2if you didn’t customize it). - Confirm the client has the
authorization_codegrant type enabled (it should be on by default for new clients).
4. Handle Self-Signed Certificate Issues
Since WSO2 IS uses a self-signed certificate out of the box, your Spring app will throw SSL errors unless you trust this cert. For development, you can:
- Import the WSO2 IS cert into your Java truststore using this command:
(The default WSO2 cert is usually inkeytool -importcert -alias wso2is -file <path-to-wso2-is-cert> -keystore <path-to-java-truststore><WSO2-IS-HOME>/repository/resources/security/wso2carbon.jks) - Or, for quick testing only, disable SSL validation (never do this in production!):
@Bean public RestTemplate restTemplate() throws KeyStoreException, NoSuchAlgorithmException, KeyManagementException { TrustStrategy acceptingTrustStrategy = (X509Certificate[] chain, String authType) -> true; SSLContext sslContext = org.apache.http.ssl.SSLContexts.custom() .loadTrustMaterial(null, acceptingTrustStrategy) .build(); SSLConnectionSocketFactory csf = new SSLConnectionSocketFactory(sslContext); CloseableHttpClient httpClient = HttpClients.custom() .setSSLSocketFactory(csf) .build(); HttpComponentsClientHttpRequestFactory requestFactory = new HttpComponentsClientHttpRequestFactory(); requestFactory.setHttpClient(httpClient); return new RestTemplate(requestFactory); }
Once you’ve made these changes, restart your Spring Boot app and try authenticating again. The issuer mismatch error should be gone.
内容的提问来源于stack exchange,提问作者tom johnes

