I got this issue because my OS did not trust openid server's certs.
The curl https://keycloak.server/realms/<realm-name>/protocol/openid-connect/certs command should not throw SSL error.
curl https://keycloak.server/realms/<realm-name>/protocol/openid-connect/certs