FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    SocketTimeoutException when resolving OpenID Connect configuration for external IdP

    Scheduled Pinned Locked Moved Solved
    Q&A
    openid-connect identity provider timeout socket-timeout
    1
    2
    17
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by dan

      We are using OpenID Connect to integrate with an external identity provider for SSO. Since a specific date, we've seen an escalating number of timeout errors when FusionAuth attempts to discover the OpenID Connect configuration.

      The configuration and FusionAuth version have not changed. Here is an example error from the Event Log:

      Unable to resolve OpenID Connect configuration using issuer [https://accounts.example.com/tenant] for [tenant/provider/ProviderName].
      Request to the [https://accounts.example.com/tenant/.well-known/openid-configuration] endpoint failed.
      Status code [-1]
      
      Exception encountered.
      
      java.net.SocketTimeoutException : Message: Read timed out
      

      The errors appear intermittently and occur at various times. When testing manually, the endpoint sometimes responds successfully and quickly (within milliseconds), but the timeouts persist in production.

      Is this a known issue with external OpenID Connect identity providers? Could there be network-level issues between FusionAuth and the external provider causing intermittent connectivity problems?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by dan

        The SocketTimeoutException: Read timed out error indicates that FusionAuth successfully initiates a connection to the external identity provider's discovery endpoint, but the provider doesn't respond within the configured timeout period. This is an intermittent connectivity issue between FusionAuth and the external provider.

        Investigation Steps

        1. Check FusionAuth Event Logs: Navigate to System → Event Log to find specific instances of the timeout errors with timestamps. The Event Log contains messages from asynchronous code execution, including connection errors to external services.
        2. Verify the external endpoint: Test the discovery endpoint manually (e.g., via curl) to confirm it's responding correctly
        3. Look for patterns: Note the times when errors occur to identify if there's a pattern
        4. Enable debug logging: Turn on debugging in FusionAuth to get more detailed information about the OIDC connection attempts. This is a recommended first step when troubleshooting any OIDC connection issues.

        Root Cause

        Based on investigation, when the external provider's endpoint:

        • DNS resolves correctly
        • TLS handshake completes successfully
        • Returns HTTP 200 with valid JSON during manual testing
        • But still fails intermittently from FusionAuth

        This indicates the external provider may be rate-limiting, blocking, or experiencing intermittent service issues that affect automated requests from FusionAuth.

        Workaround

        Instead of using the OpenID Connect Discovery URL, manually configure the endpoints in your FusionAuth identity provider settings. This bypasses the discovery mechanism and eliminates the timeout errors during the configuration resolution phase.

        To configure manual endpoints:

        1. Go to your OIDC Identity Provider configuration (Settings → Identity Providers)
        2. Toggle Discover endpoints to Off (disabled)
        3. Explicitly set the three required endpoints:
          • Authorization endpoint: https://accounts.example.com/tenant/oauth/authorize
          • Token endpoint: https://accounts.example.com/tenant/oauth/token
          • Userinfo endpoint: https://accounts.example.com/tenant/oauth/userinfo

        This manual configuration approach is commonly used with providers like GitHub and Discord that don't implement standard discovery endpoints, and can also be used to work around discovery endpoint reliability issues.

        Note: If your external provider uses RS256 to sign tokens (rather than HS256), be aware that FusionAuth currently doesn't allow manual configuration of the JWKS URL when discovery is disabled. This may cause id_token signature verification issues. If you encounter this, you may need to continue using discovery or contact FusionAuth support for alternatives.

        Next Steps

        Contact your external identity provider to:

        • Report the intermittent timeout issues
        • Share the timeout error logs and timestamps
        • Ask if they're experiencing service issues or if FusionAuth's IP range needs to be whitelisted
        • Inquire about any rate limiting policies that might affect discovery endpoint calls

        Related Documentation

        • Add an OpenID Connect Identity Provider - Complete guide to configuring OIDC IdPs
        • OIDC Troubleshooting - First steps for troubleshooting OIDC connections
        • OpenID Connect API - API reference for managing OIDC identity providers
        • Event Log API - How to access and query event logs programmatically

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Hidden
        • First post
          Last post