AWS Error: Specified provider doesn't exist Skip to main content
https://support.okta.com/help/answers?id=9062a000000qui8qac&refurl=http%3a%2f%2fsupport.okta.com%2fhelp%2fanswers
How satisfied are you with the Okta Help Center?
Thank you for your feedback!
How satisfied are you with the Okta Help Center?
1
2
3
4
5
Very Dissatisfied
Very satisfied
Enter content less than 200 characters.
Ask Search:
Philip ColmerPhilip Colmer 

AWS Error: Specified provider doesn't exist

I've successfully tested OCC with AWS and a single AWS account. However, after following the setup instructions to reconfigure OCC to work with AWS across multiple accounts, any attempt to select a role on AWS results in this error:

Specified provider doesn't exist (Service: AWSOpenIdDiscoveryService; Status Code: 400; Error Code: AuthSamlManifestNotFoundException; Request ID: 4de41592-e186-11e7-baa5-17bd1328b919) (Service: AWSSecurityTokenService; Status Code: 400; Error Code: InvalidIdentityToken; Request ID: 4de3c7de-e186-11e7-af96-255bc4cc42a8). Please try again.

OCC is successfully fetching the roles from all accounts and I've configured my OCC account to be able to select different roles from different accounts. However, it doesn't matter which role I pick, I get the same error.

What isn't clear in the documentation is how the trust policy in each role should be configured in a multi-account scenario. It isn't clear if I should be using the ARN for the master account IDP or the ARN for the IDP in that specific account.

I've actually tested both ARNs and neither works.

I'm completely stuck as to what has gone wrong here.

 
Cosmin OlteanuCosmin Olteanu (Okta, Inc.)
New integrations should follow the setup instructions from the Sign On tab and on the View Setup Instructions section of the Amazon Web Services app in OAN. In the case that every step has been followed from the guide and you are still encountering this issue, then the issue may reside on the AWS configuration. Please check the AWS documentation regarding the trust policy. 

If you still require assistance from us, please feel free to open a support case with us and we will be able to assist you further.

Thank you for choosing Okta!