OIDC 0.9 extension

Janne Lauros janne.lauros at csc.fi
Fri Mar 29 05:57:28 EDT 2019



To be absolutely sure you are sending acr on the wire, you may locate the actual response from the log, for instance by

grep id_token /opt/shibboleth-idp/logs/idp-process.log

you should see following debug (provided you have debug level logs on) line:

Content:{"access_token":"AAdzZWNyZXQxfk9ATSvhUlMT0oD35RxgYYo6_D3Mu-eNZT9wvSixJNK_eOc9UO-IWsO90KW3wiaj9rTzRp2_eAqvrw1CzbhwppeW67pVfDdie4u8CLVAp896zj4fUXf-OHc_upac8QTqf8vIFgHqXG-3M5A8JHAfs3004DiOzafZGKcFswaXFfKaiECy-v6k1FwOg27VdACOnWupYZtfrNN05vx-y_RdtL7RgTz8TVuzvmzaOaNy9aJ4rlLxJU9_0EoY477jEgmSeQ3YIq8Hic5IpbX0FydBhQnzbA5c5-zZ9J8iA3UF8bL03kDwcPI3rtzs5-lC50NWNMktaU3vH_VY7oD5NMn8qzLmDoT_a4Lkp6ZMhFmEVD95RQGatOOg49t1_8NAlk6NBBMF5sOBZIt5HPyBtFjHw9eXXw7kxPmwzr1fGL_j97yflSETckvq_L2kEikZqoMFgxSCzusGHKD5nMuGnd-G6kGnbi2GdJ0HnF2Sd14LXHdt4g","id_token":"eyJraWQiOiJ0ZXN0a2V5UlMiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiVlNjYlBqeHdrYU1DSjRjcXNMWTh2ZyIsInN1YiI6IlZVRzQ3NzdZUDNOTVU1S1JGRVNYNlNLUkFQWExFNE1JIiwiYXVkIjoiXzBhMGU0OTY0NTllYmMyZjJhZTQ0M2JhODY0ZGU0ZmRmIiwiYWNyIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE1NTM4NDg1MzksImlzcyI6Imh0dHBzOlwvXC90ZXN0b3AuZnVuZXQuZmkiLCJleHAiOjE1NTM4NTM5NDAsImlhdCI6MTU1Mzg1MDM0MCwibm9uY2UiOiJweU45blB0N3UydHZsNGR1In0.NTskERDwbNMOw0Oidi3c8S408oZg27v6AUYpxlzNKAdCiJSbVN9FuOtodc_Dj37yg-mRrZx-obxl9tZdfKcb3ckuEefcpkFjhg4yOgOdIiPHUJOOS4oj9ZRz9R6OxylSh8G-RprfCPQxNfFzg9zrbGEyYyiigvQqDgwzS6LWwan1xVZI3UgX7pVQBmIHJx7iPXUjL9RfMlvBo5FmtPooGRVi3DM9NOkHWR8t9VWnlLs8iMnCIYmt_1p2O_3kvODZe06mLMH15MriqG2H7fnsEHyxHz94Hpcm1C9aXTiR1d6FvkYeamP-M7DD3n8MoVsD8tY788HLuBq7lAK50ahBFg","token_type":"Bearer","expires_in":600}

that is contents of actual response to be sent on the wire. Extract now the id_token token, in this example it would be

eyJraWQiOiJ0ZXN0a2V5UlMiLCJhbGciOiJSUzI1NiJ9.eyJhdF9oYXNoIjoiVlNjYlBqeHdrYU1DSjRjcXNMWTh2ZyIsInN1YiI6IlZVRzQ3NzdZUDNOTVU1S1JGRVNYNlNLUkFQWExFNE1JIiwiYXVkIjoiXzBhMGU0OTY0NTllYmMyZjJhZTQ0M2JhODY0ZGU0ZmRmIiwiYWNyIjoicGFzc3dvcmQiLCJhdXRoX3RpbWUiOjE1NTM4NDg1MzksImlzcyI6Imh0dHBzOlwvXC90ZXN0b3AuZnVuZXQuZmkiLCJleHAiOjE1NTM4NTM5NDAsImlhdCI6MTU1Mzg1MDM0MCwibm9uY2UiOiJweU45blB0N3UydHZsNGR1In0.NTskERDwbNMOw0Oidi3c8S408oZg27v6AUYpxlzNKAdCiJSbVN9FuOtodc_Dj37yg-mRrZx-obxl9tZdfKcb3ckuEefcpkFjhg4yOgOdIiPHUJOOS4oj9ZRz9R6OxylSh8G-RprfCPQxNfFzg9zrbGEyYyiigvQqDgwzS6LWwan1xVZI3UgX7pVQBmIHJx7iPXUjL9RfMlvBo5FmtPooGRVi3DM9NOkHWR8t9VWnlLs8iMnCIYmt_1p2O_3kvODZe06mLMH15MriqG2H7fnsEHyxHz94Hpcm1C9aXTiR1d6FvkYeamP-M7DD3n8MoVsD8tY788HLuBq7lAK50ahBFg

and copy that to some online decoder - http://calebb.net/ - resulting in 

{
 kid: "testkeyRS",
 alg: "RS256"
}.
{
 at_hash: "VScbPjxwkaMCJ4cqsLY8vg",
 sub: "VUG4777YP3NMU5KRFESX6SKRAPXLE4MI",
 aud: "_0a0e496459ebc2f2ae443ba864de4fdf",
 acr: "password",
 auth_time: 1553848539,
 iss: "https:\/\/testop.funet.fi",
 exp: 1553853940,
 iat: 1553850340,
 nonce: "pyN9nPt7u2tvl4du"
}

and there you either have or have not the acr claim.

BR Janne

ps. This is handled also as an exercise in our training material on https://wiki.eduuni.fi/display/CSCHAKA/181211-12+@+Shibboleth+OIDC+Extension+Tutorial



----- Original Message -----
From: "Jim Fox" <fox at washington.edu>
To: "dev" <dev at shibboleth.net>
Sent: Friday, 29 March, 2019 01:18:46
Subject: OIDC 0.9 extension

I'm using the extension from the master branch of the github repo.

I can request MFA, and force reauth, but I never get back any claim that those things were done. 
I think that information should be in a 'acr' claim.  However, I never see one.

Am I looking in the wrong place?  Is there another way to tell what acr valuw was used?

Thanks,

Jim

-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list