You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WSO2 IS与Spring Boot配置Issuer不匹配问题求助

Issue with Spring Boot OIDC Integration with WSO2 IS 5.11.0

I'm following the official WSO2 IS guide for Spring Boot integration, but I'm hitting an issuer mismatch error. Here's my setup:

Spring Boot OIDC Configuration (application.yaml)

provider:
  host: https://localhost:9443 #Change the host
spring:
  security:
    oauth2:
      client:
        registration:
          wso2:
            client-name : WSO2 Identity Server
            client-id: aXOWlNxT0aKIfKIeH82IfsmLjsYa #Change client-id
            client-secret: CVl_vmEYqRuZddBu3ZCYQQwGtYsa # Change client-secret
            authorization-grant-type: authorization_code
            scope: openid
        provider:
          wso2:
            issuer-uri: ${provider.host}/oauth2/oidcdiscovery
thymeleaf:
  cache: false

Error Stack Trace

Caused by: java.lang.IllegalStateException: The Issuer "https://localhost:9443/oauth2/token" provided in the configuration metadata did not match the requested issuer "https://localhost:9443/oauth2/oidcdiscovery"
    at org.springframework.util.Assert.state(Assert.java:97) ~[spring-core-5.3.2.jar:5.3.2]
    at org.springframework.security.oauth2.client.registration.ClientRegistrations.withProviderConfiguration(ClientRegistrations.java:239) ~[spring-security-oauth2-client-5.4.2.jar:5.4.2]
    at org.springframework.security.oauth2.client.registration.ClientRegistrations.lambda$oidc$0(ClientRegistrations.java:158) ~[spring-security-oauth2-client-5.4.2.jar:5.4.2]

WSO2 IS is running with default configurations, and the identity provider setup is correct. How can I fix this issuer mismatch issue?


Solution

Let me help you fix this issuer mismatch issue—it’s a common gotcha when integrating Spring Boot with WSO2 IS 5.11.0. Here’s what’s going wrong and how to fix it:

1. Fix the issuer-uri in Your Spring Config

The root problem is that you’re using the wrong OIDC discovery endpoint. WSO2 IS 5.11.0 follows the standard OIDC discovery spec, which uses the endpoint /.well-known/openid-configuration under the OAuth2 context.

Update your provider.wso2.issuer-uri to this:

issuer-uri: ${provider.host}/oauth2/.well-known/openid-configuration

When Spring Security hits this endpoint, it’ll fetch the correct OIDC metadata, including the proper issuer value (https://localhost:9443/oauth2), which will match the expected value.

2. Fallback: Configure Endpoints Explicitly

If the automatic discovery still gives you trouble, you can manually define all required OAuth2/OIDC endpoints for WSO2 IS. This avoids any confusion with discovery metadata:

provider:
  host: https://localhost:9443 # Keep your host config
spring:
  security:
    oauth2:
      client:
        registration:
          wso2:
            client-name : WSO2 Identity Server
            client-id: aXOWlNxT0aKIfKIeH82IfsmLjsYa
            client-secret: CVl_vmEYqRuZddBu3ZCYQQwGtYsa
            authorization-grant-type: authorization_code
            scope: openid
            redirect-uri: "{baseUrl}/login/oauth2/code/wso2" # Match this to your WSO2 client's redirect URI
        provider:
          wso2:
            issuer-uri: ${provider.host}/oauth2 # Correct issuer value
            authorization-uri: ${provider.host}/oauth2/authorize
            token-uri: ${provider.host}/oauth2/token
            user-info-uri: ${provider.host}/oauth2/userinfo
            jwk-set-uri: ${provider.host}/oauth2/jwks

3. Double-Check Your WSO2 IS Client Setup

Don’t forget to verify these in your WSO2 IS service provider configuration:

  • Ensure the redirect URI matches exactly what’s in your Spring config (the default is http://localhost:8080/login/oauth2/code/wso2 if you didn’t customize it).
  • Confirm the client has the authorization_code grant type enabled (it should be on by default for new clients).

4. Handle Self-Signed Certificate Issues

Since WSO2 IS uses a self-signed certificate out of the box, your Spring app will throw SSL errors unless you trust this cert. For development, you can:

  • Import the WSO2 IS cert into your Java truststore using this command:
    keytool -importcert -alias wso2is -file <path-to-wso2-is-cert> -keystore <path-to-java-truststore>
    
    (The default WSO2 cert is usually in <WSO2-IS-HOME>/repository/resources/security/wso2carbon.jks)
  • Or, for quick testing only, disable SSL validation (never do this in production!):
    @Bean
    public RestTemplate restTemplate() throws KeyStoreException, NoSuchAlgorithmException, KeyManagementException {
        TrustStrategy acceptingTrustStrategy = (X509Certificate[] chain, String authType) -> true;
        SSLContext sslContext = org.apache.http.ssl.SSLContexts.custom()
                .loadTrustMaterial(null, acceptingTrustStrategy)
                .build();
        SSLConnectionSocketFactory csf = new SSLConnectionSocketFactory(sslContext);
        CloseableHttpClient httpClient = HttpClients.custom()
                .setSSLSocketFactory(csf)
                .build();
        HttpComponentsClientHttpRequestFactory requestFactory =
                new HttpComponentsClientHttpRequestFactory();
        requestFactory.setHttpClient(httpClient);
        return new RestTemplate(requestFactory);
    }
    

Once you’ve made these changes, restart your Spring Boot app and try authenticating again. The issuer mismatch error should be gone.

内容的提问来源于stack exchange,提问作者tom johnes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:04:00