OIDC 0.9 extension
Janne Lauros
janne.lauros at csc.fi
Fri Mar 29 05:57:28 EDT 2019
To be absolutely sure you are sending acr on the wire, you may locate the actual response from the log, for instance by
grep id_token /opt/shibboleth-idp/logs/idp-process.log
you should see following debug (provided you have debug level logs on) line:
Content:{"access_token":"AAdzZWNyZXQxfk9ATSvhUlMT0oD35RxgYYo6_D3Mu-eNZT9wvSixJNK_eOc9UO-IWsO90KW3wiaj9rTzRp2_eAqvrw1CzbhwppeW67pVfDdie4u8CLVAp896zj4fUXf-OHc_upac8QTqf8vIFgHqXG-3M5A8JHAfs3004DiOzafZGKcFswaXFfKaiECy-v6k1FwOg27VdACOnWupYZtfrNN05vx-y_RdtL7RgTz8TVuzvmzaOaNy9aJ4rlLxJU9_0EoY477jEgmSeQ3YIq8Hic5IpbX0FydBhQnzbA5c5-zZ9J8iA3UF8bL03kDwcPI3rtzs5-lC50NWNMktaU3vH_VY7oD5NMn8qzLmDoT_a4Lkp6ZMhFmEVD95RQGatOOg49t1_8NAlk6NBBMF5sOBZIt5HPyBtFjHw9eXXw7kxPmwzr1fGL_j97yflSETckvq_L2kEikZqoMFgxSCzusGHKD5nMuGnd-G6kGnbi2GdJ0HnF2Sd14LXHdt4g","id_token":"eyJraWQiOiJ0ZXN0a2V5UlMiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiVlNjYlBqeHdrYU1DSjRjcXNMWTh2ZyIsInN1YiI6IlZVRzQ3NzdZUDNOTVU1S1JGRVNYNlNLUkFQWExFNE1JIiwiYXVkIjoiXzBhMGU0OTY0NTllYmMyZjJhZTQ0M2JhODY0ZGU0ZmRmIiwiYWNyIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE1NTM4NDg1MzksImlzcyI6Imh0dHBzOlwvXC90ZXN0b3AuZnVuZXQuZmkiLCJleHAiOjE1NTM4NTM5NDAsImlhdCI6MTU1Mzg1MDM0MCwibm9uY2UiOiJweU45blB0N3UydHZsNGR1In0.NTskERDwbNMOw0Oidi3c8S408oZg27v6AUYpxlzNKAdCiJSbVN9FuOtodc_Dj37yg-mRrZx-obxl9tZdfKcb3ckuEefcpkFjhg4yOgOdIiPHUJOOS4oj9ZRz9R6OxylSh8G-RprfCPQxNfFzg9zrbGEyYyiigvQqDgwzS6LWwan1xVZI3UgX7pVQBmIHJx7iPXUjL9RfMlvBo5FmtPooGRVi3DM9NOkHWR8t9VWnlLs8iMnCIYmt_1p2O_3kvODZe06mLMH15MriqG2H7fnsEHyxHz94Hpcm1C9aXTiR1d6FvkYeamP-M7DD3n8MoVsD8tY788HLuBq7lAK50ahBFg","token_type":"Bearer","expires_in":600}
that is contents of actual response to be sent on the wire. Extract now the id_token token, in this example it would be
eyJraWQiOiJ0ZXN0a2V5UlMiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiVlNjYlBqeHdrYU1DSjRjcXNMWTh2ZyIsInN1YiI6IlZVRzQ3NzdZUDNOTVU1S1JGRVNYNlNLUkFQWExFNE1JIiwiYXVkIjoiXzBhMGU0OTY0NTllYmMyZjJhZTQ0M2JhODY0ZGU0ZmRmIiwiYWNyIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE1NTM4NDg1MzksImlzcyI6Imh0dHBzOlwvXC90ZXN0b3AuZnVuZXQuZmkiLCJleHAiOjE1NTM4NTM5NDAsImlhdCI6MTU1Mzg1MDM0MCwibm9uY2UiOiJweU45blB0N3UydHZsNGR1In0.NTskERDwbNMOw0Oidi3c8S408oZg27v6AUYpxlzNKAdCiJSbVN9FuOtodc_Dj37yg-mRrZx-obxl9tZdfKcb3ckuEefcpkFjhg4yOgOdIiPHUJOOS4oj9ZRz9R6OxylSh8G-RprfCPQxNfFzg9zrbGEyYyiigvQqDgwzS6LWwan1xVZI3UgX7pVQBmIHJx7iPXUjL9RfMlvBo5FmtPooGRVi3DM9NOkHWR8t9VWnlLs8iMnCIYmt_1p2O_3kvODZe06mLMH15MriqG2H7fnsEHyxHz94Hpcm1C9aXTiR1d6FvkYeamP-M7DD3n8MoVsD8tY788HLuBq7lAK50ahBFg
and copy that to some online decoder - http://calebb.net/ - resulting in
{
kid: "testkeyRS",
alg: "RS256"
}.
{
at_hash: "VScbPjxwkaMCJ4cqsLY8vg",
sub: "VUG4777YP3NMU5KRFESX6SKRAPXLE4MI",
aud: "_0a0e496459ebc2f2ae443ba864de4fdf",
acr: "password",
auth_time: 1553848539,
iss: "https:\/\/testop.funet.fi",
exp: 1553853940,
iat: 1553850340,
nonce: "pyN9nPt7u2tvl4du"
}
and there you either have or have not the acr claim.
BR Janne
ps. This is handled also as an exercise in our training material on https://wiki.eduuni.fi/display/CSCHAKA/181211-12+@+Shibboleth+OIDC+Extension+Tutorial
----- Original Message -----
From: "Jim Fox" <fox at washington.edu>
To: "dev" <dev at shibboleth.net>
Sent: Friday, 29 March, 2019 01:18:46
Subject: OIDC 0.9 extension
I'm using the extension from the master branch of the github repo.
I can request MFA, and force reauth, but I never get back any claim that those things were done.
I think that information should be in a 'acr' claim. However, I never see one.
Am I looking in the wrong place? Is there another way to tell what acr valuw was used?
Thanks,
Jim
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
More information about the dev
mailing list