You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your suggestion related to a missing or misleading document? Please describe.
As reported in #16181, Federated authentication fails between two tenants in a host name changed IS. This is due to that if the certificate used for SSL communication has a cert, the hostname is checked in the defined SANs and newly defined hostname is not added into the SAN.
If the is.dev.wso2.com also added as a SAN issue gets resolved. Hence the document should be changed to add the is.dev.wso2.comalso as a SAN in,
Add localhost as SAN for the certificate (-ext SAN=dns:localhost) as the internal hostname is by default localhost. For that, navigate to the <IS_HOME>/repository/resources/security directory on the command prompt and use the following command to create a new keystore with CN=is.dev.wso2.com and localhost as SAN
LakshiAthapaththu
changed the title
Adding missing SAN in the certificate to resolve federated authentication flow failure
Adding missing SAN element in the certificate to resolve federated authentication flow failure
Jul 14, 2023
Is your suggestion related to a missing or misleading document? Please describe.
As reported in #16181, Federated authentication fails between two tenants in a host name changed IS. This is due to that if the certificate used for SSL communication has a cert, the hostname is checked in the defined SANs and newly defined hostname is not added into the SAN.
If the
is.dev.wso2.com
also added as a SAN issue gets resolved. Hence the document should be changed to add theis.dev.wso2.com
also as a SAN in,Add localhost as SAN for the certificate (-ext SAN=dns:localhost) as the internal hostname is by default localhost. For that, navigate to the <IS_HOME>/repository/resources/security directory on the command prompt and use the following command to create a new keystore with CN=is.dev.wso2.com and localhost as SAN
Describe the improvement
In https://is.docs.wso2.com/en/latest/deploy/change-the-hostname/#change-the-hostname options 1, the given command should be changed to add the
is.dev.wso2.com
as a SAN as below.Related Issues:
#16181
The text was updated successfully, but these errors were encountered: