<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491199#M40265</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In Alfresco admin console (Support Tools) check if there is something about authentication chain saved in DB:&lt;/P&gt;&lt;P&gt;/alfresco/s/enterprise/admin/admin-jmx-settings&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jul 2025 12:36:38 GMT</pubDate>
    <dc:creator>cesarista</dc:creator>
    <dc:date>2025-07-09T12:36:38Z</dc:date>
    <item>
      <title>Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/490983#M40245</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are upgrading ACS from 7.1 to 23.3, and adapt 23.3 with native Keycloak 24.0.3 for SSO (use Okta OIDC as IDP). We first try with native ACS 23.3 with Keycloak setup and it works fine. but after we apply our custom share and platform image, the SSO stop working. We do remote debug with share library and see below error through in AIMSFilter class on calling api&amp;nbsp;&lt;BR /&gt;/-default-/public/authentication/versions/1/tickets/-me-?noCache=&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;{
  "error" : {
    "errorKey" : "framework.exception.ApiDefault",
    "statusCode" : 401,
    "briefSummary" : "05290014 Authorization 'Bearer' not supported.",
    "stackTrace" : "For security reasons the stack trace is no longer displayed, but the property is kept for previous versions",
    "descriptionURL" : "https://api-explorer.alfresco.com",
    "logId" : "bed30bc2-7348-4a03-930b-c273481a035b"
  }
}&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;In ACS 7.1, share simply use /alfresco/s/api/login call with user and password to get alf_ticket for subsequent call. I'm not sure if the Bearer type of ticket call is something new in ACS 23.3 and require extra configure.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In summary:&lt;/P&gt;&lt;P&gt;Our dev environment SSO works with share + platform + native DB + keycloak&lt;/P&gt;&lt;P&gt;Our test environment SSO doesn't work with share+ platform + existing DB (upgraded from 7.1) + keycloak&lt;/P&gt;&lt;P&gt;Both environment use same customized image and same configuration.&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 19:37:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/490983#M40245</guid>
      <dc:creator>yuantao</dc:creator>
      <dc:date>2025-06-30T19:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491118#M40261</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;I assume you are using EE.&lt;/P&gt;&lt;P&gt;May you have (between migrated database) some JMX data persisted related authentication chain ?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jul 2025 09:24:20 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491118#M40261</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2025-07-04T09:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491198#M40264</link>
      <description>&lt;P data-unlink="true"&gt;Hi&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;cesarista,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes, we are trying to upgrade from ACS 7.1 to 23.3 and it's enterprise version. Not sure how to check JMX data for&amp;nbsp;&lt;SPAN&gt;authentication chain or there is a way to check issue in DB?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:28:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491198#M40264</guid>
      <dc:creator>yuantao</dc:creator>
      <dc:date>2025-07-09T12:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491199#M40265</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In Alfresco admin console (Support Tools) check if there is something about authentication chain saved in DB:&lt;/P&gt;&lt;P&gt;/alfresco/s/enterprise/admin/admin-jmx-settings&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 12:36:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491199#M40265</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2025-07-09T12:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491240#M40267</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;cesarista,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You are right. It turns out jmx setting didn't sync with the&amp;nbsp;authentication chain configuration in alfresco-global.properties. Much appreciate your help!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 00:29:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491240#M40267</guid>
      <dc:creator>yinyuantao</dc:creator>
      <dc:date>2025-07-10T00:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Urgent help need for Alfresco 23.3 SSO with Okta OIDC as IDP</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491318#M40282</link>
      <description>&lt;P&gt;We are upgrading ACS from 7.1 to 23.3, and adapt 23.3 with native Keycloak 24.0.3 for SSO (use Okta OIDC as IDP). We first try with native ACS 23.3 with Keycloak setup and it works fine. but after we apply our custom share and platform image, the SSO stop working. We do remote debug with &lt;A href="https://seovancouveragency.ca/" target="_self"&gt;share&lt;/A&gt; library and see below error through in AIMSFilter class on calling api&lt;/P&gt;&lt;P&gt;/-default-/public/authentication/versions/1/tickets/-me-?noCache=&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;"error" : {&lt;/P&gt;&lt;P&gt;"errorKey" : "framework.exception.ApiDefault",&lt;/P&gt;&lt;P&gt;"statusCode" : 401,&lt;/P&gt;&lt;P&gt;"briefSummary" : "05290014 Authorization 'Bearer' not supported.",&lt;/P&gt;&lt;P&gt;"stackTrace" : "For security reasons the stack trace is no longer displayed, but the property is kept for previous versions",&lt;/P&gt;&lt;P&gt;"logId" : "bed30bc2-7348-4a03-930b-c273481a035b"&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;In ACS 7.1, share simply use /alfresco/s/api/login call with user and password to get alf_ticket for subsequent call. I'm not sure if the Bearer type of ticket call is something new in ACS 23.3 and require extra configure.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 15:51:25 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/urgent-help-need-for-alfresco-23-3-sso-with-okta-oidc-as-idp/m-p/491318#M40282</guid>
      <dc:creator>woordnelson</dc:creator>
      <dc:date>2025-07-14T15:51:25Z</dc:date>
    </item>
  </channel>
</rss>

