<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SocketTimeoutException when resolving OpenID Connect configuration for external IdP]]></title><description><![CDATA[<p dir="auto">We are using OpenID Connect to integrate with an external identity provider for SSO. Since a specific date, we've seen an escalating number of timeout errors when FusionAuth attempts to discover the OpenID Connect configuration.</p>
<p dir="auto">The configuration and FusionAuth version have not changed. Here is an example error from the Event Log:</p>
<pre><code>Unable to resolve OpenID Connect configuration using issuer [https://accounts.example.com/tenant] for [tenant/provider/ProviderName].
Request to the [https://accounts.example.com/tenant/.well-known/openid-configuration] endpoint failed.
Status code [-1]

Exception encountered.

java.net.SocketTimeoutException : Message: Read timed out
</code></pre>
<p dir="auto">The errors appear intermittently and occur at various times. When testing manually, the endpoint sometimes responds successfully and quickly (within milliseconds), but the timeouts persist in production.</p>
<p dir="auto">Is this a known issue with external OpenID Connect identity providers? Could there be network-level issues between FusionAuth and the external provider causing intermittent connectivity problems?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3157/sockettimeoutexception-when-resolving-openid-connect-configuration-for-external-idp</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 00:55:33 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3157.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 16:10:07 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to SocketTimeoutException when resolving OpenID Connect configuration for external IdP on Mon, 28 Sep 2026 16:45:32 GMT]]></title><description><![CDATA[<p dir="auto">The <code>SocketTimeoutException: Read timed out</code> error indicates that FusionAuth successfully initiates a connection to the external identity provider's discovery endpoint, but the provider doesn't respond within the configured timeout period. This is an intermittent connectivity issue between FusionAuth and the external provider.</p>
<h2>Investigation Steps</h2>
<ol>
<li><strong>Check FusionAuth Event Logs</strong>: Navigate to <strong>System → Event Log</strong> to find specific instances of the timeout errors with timestamps. The <a href="https://fusionauth.io/docs/apis/event-logs" rel="nofollow ugc">Event Log</a> contains messages from asynchronous code execution, including connection errors to external services.</li>
<li><strong>Verify the external endpoint</strong>: Test the discovery endpoint manually (e.g., via curl) to confirm it's responding correctly</li>
<li><strong>Look for patterns</strong>: Note the times when errors occur to identify if there's a pattern</li>
<li><strong>Enable debug logging</strong>: Turn on debugging in FusionAuth to get more detailed information about the OIDC connection attempts. This is a recommended first step when troubleshooting any OIDC connection issues.</li>
</ol>
<h2>Root Cause</h2>
<p dir="auto">Based on investigation, when the external provider's endpoint:</p>
<ul>
<li>DNS resolves correctly</li>
<li>TLS handshake completes successfully</li>
<li>Returns HTTP 200 with valid JSON during manual testing</li>
<li>But still fails intermittently from FusionAuth</li>
</ul>
<p dir="auto">This indicates the external provider may be rate-limiting, blocking, or experiencing intermittent service issues that affect automated requests from FusionAuth.</p>
<h2>Workaround</h2>
<p dir="auto">Instead of using the OpenID Connect Discovery URL, manually configure the endpoints in your FusionAuth identity provider settings. This bypasses the discovery mechanism and eliminates the timeout errors during the configuration resolution phase.</p>
<p dir="auto">To configure manual endpoints:</p>
<ol>
<li>Go to your OIDC Identity Provider configuration (<strong>Settings → Identity Providers</strong>)</li>
<li>Toggle <strong>Discover endpoints</strong> to <code>Off</code> (disabled)</li>
<li>Explicitly set the three required endpoints:
<ul>
<li><strong>Authorization endpoint</strong>: <code>https://accounts.example.com/tenant/oauth/authorize</code></li>
<li><strong>Token endpoint</strong>: <code>https://accounts.example.com/tenant/oauth/token</code></li>
<li><strong>Userinfo endpoint</strong>: <code>https://accounts.example.com/tenant/oauth/userinfo</code></li>
</ul>
</li>
</ol>
<p dir="auto">This manual configuration approach is commonly used with providers like GitHub and Discord that don't implement standard discovery endpoints, and can also be used to work around discovery endpoint reliability issues.</p>
<p dir="auto"><strong>Note</strong>: If your external provider uses RS256 to sign tokens (rather than HS256), be aware that FusionAuth currently doesn't allow manual configuration of the JWKS URL when discovery is disabled. This may cause <code>id_token</code> signature verification issues. If you encounter this, you may need to continue using discovery or contact FusionAuth support for alternatives.</p>
<h2>Next Steps</h2>
<p dir="auto">Contact your external identity provider to:</p>
<ul>
<li>Report the intermittent timeout issues</li>
<li>Share the timeout error logs and timestamps</li>
<li>Ask if they're experiencing service issues or if FusionAuth's IP range needs to be whitelisted</li>
<li>Inquire about any rate limiting policies that might affect discovery endpoint calls</li>
</ul>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers/overview-oidc#create-an-openid-connect-identity-provider" rel="nofollow ugc">Add an OpenID Connect Identity Provider</a> - Complete guide to configuring OIDC IdPs</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers/overview-oidc#troubleshooting" rel="nofollow ugc">OIDC Troubleshooting</a> - First steps for troubleshooting OIDC connections</li>
<li><a href="https://fusionauth.io/docs/apis/identity-providers/openid-connect" rel="nofollow ugc">OpenID Connect API</a> - API reference for managing OIDC identity providers</li>
<li><a href="https://fusionauth.io/docs/apis/event-logs" rel="nofollow ugc">Event Log API</a> - How to access and query event logs programmatically</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8652</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8652</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 16:45:32 GMT</pubDate></item></channel></rss>