OIDC InvalidGrant errors

Mohamed Lrhazi lrhazi at cua.edu
Tue Mar 2 15:08:15 UTC 2021


Thanks Scott. Is this the secret key store ?

idp.properties:idp.sealer.storeResource = %{idp.home}/credentials/sealer.jks

And this needs to be the same on all IdP server instances?

On Tue, Mar 2, 2021 at 8:45 AM Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 3/2/21, 8:37 AM, "users on behalf of Mohamed Lrhazi" <
> users-bounces at shibboleth.net on behalf of lrhazi at cua.edu> wrote:
>
> >    I am setting up my first OIDC config and after it started working for
> a few days, several users report that it suddenly
> > stopped working. I find the following in the log:
>
> That's impossible unless you corrupted the secret key store (i.e. you have
> two different keys under the same alias on different servers) or the token
> was actually corrupted by the caller.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210302/c352c721/attachment.htm>


More information about the users mailing list