Hi,
The OAuth definition has authorization code enabled. Yes, the two Reverse Proxies have their /mga junction pointing to two different runtimes (localhost) of their respective appliances.
Yes we are in a cluster so the AAC Runtimes should have the same configuration, and I believe they have the same configuration, because I can see the same OAUTH definition in this appliance (which is sync'd from the master). Also, other configurations of AAC such as authentication policies, mapping rules are getting sync'd successfully. The reload of runtime is not an issue because I have also tried to manually reload it, even restart it, but no luck.
Yes I am working with support on this but unfortunately facing a delay in responses so thought to have feedback from team here.
Regards,
------------------------------
Jahanzaib Sarwar
------------------------------
Original Message:
Sent: Mon August 03, 2020 05:25 AM
From: Jon Harry
Subject: ISAM: OAUTH Access Token Generation Fails on Clustered Appliance
Hello,
This error is coming from the AAC Runtime and I think it would be generated when the OAuth definition does not have authorization code enabled. Since you have this working via one Reverse Proxy but not another, the implication is that the two Reverse Proxies have their /mga junction pointing to two different runtimes and that these have different configuration.
You say you're in a cluster so the AAC Runtimes should have the same configuration. Perhaps one of the AAC Runtimes has been reloaded since the OAuth configuration was set up but the other has not? If that's not the case, perhaps there's an issue with the configuration being sync'd in the cluster. I'm not an expert in that area but support should be able to help if that's the case.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------