Unexpected unverified party error for OIDC RP
Darren Boss
darren.boss at computecanada.ca
Thu Jul 15 14:44:25 UTC 2021
I'm stuck stretching my head over this one and need some help. First
details about my environment
./plugin.sh -l Plugin: net.shibboleth.oidc.common Current Version:
1.1.0 Plugin: net.shibboleth.idp.plugin.oidc.op Current Version: 3.0.1
Plugin: net.shibboleth.idp.plugin.authn.duo.nimbus Current Version:
1.1.1
Shibboleth version 4.1.2
I have a research project using our IdP, they are using nginx
(openresty/1.19.3.1 to be specific Nginx + Lua) and lua-resty-openidc
1.7.4-1.
If I understand correctly, SSO and Userinfo are working just fine. I'm
using SAML style metadata for their RP. They also use
OAUTH2.Introspection, they are the only project so far that does but
this is what I see in the log when they try and use it:
Profile Action SelectProfileConfiguration: Profile
http://shibboleth.net/ns/profiles/oauth2/introspection is not
available for RP configuration shibboleth.UnverifiedRelyingParty (RPID
bentov2)
If I add OAUTH2.Introspection to UnverifiedRelyingParty, no more
errors but I know this isn't correct, I shouldn't have this enabled
for UnverifiedRelyingParty.
Does anyone have an idea about what might be happening here? I also
have an IdP running for just this group running 4.0.1 and working fine
for them because they were having problems after my upgrade to 4.1 and
the switch to the plugins. They had a new instance to setup so I
recommended they try again with dev IdP running 4.1.2 and now this
appears to be the only issue they are having and I'd really like to
move all their deployments over and shutdown that old IdP instance.
--
Darren Boss
Senior Programmer/Analyst
Programmeur-analyste principal
darren.boss at computecanada.ca
More information about the users
mailing list