In the SSO chapter, https://ea.forgerock.com/docs/ig/gateway-guide/sso-auth.html#proc-sso
The Validation Service must contain the URLs having a domain name named openig.example.com and not openig.ext.com (See Authenticate With SSO > bullet 1. Set up AM: > part b.)