School modules not working with SSO / Keycloak - 401 Unauthorized

Hello,

iam running ucsschool at https://schulserver.internal.falbk.schule
i migrated SAML SSO to Keycloak with an external Domain https://sso.falbk.schule

At our schoolserver i set umc/saml/idp-server to the external Domain https://sso.falbk.schule
I left umc/saml/sp-server unset.

Login is working and after login at keycloak i get redirected https://schulserver.internal.falbk.schule

But then no school-module is working like class room or distribute

When i look at the Network-Request in Chrome i get a lot of 401 Unauthorized HTTP Responses
grafik
grafik

The saml sp returns a 200 OK
grafik

Only the schoolserver (schulserver) is not working. The school-modules at the backup-nodes are working properly

Any tips? Is Keycloak or the UCS missconfigured?

I forgot to run
service slapd restart
on the schoolserver

Mastodon