Can a URI be used as an OIDC client ID?

Wessel, Keith kwessel at illinois.edu
Wed Feb 22 17:28:19 UTC 2023


And if anyone else who knows the plumbing in the plugin better than me can suggest why a colon might be a point where the client ID stops being processed for a back-channel call to the IDToken endpoint, we'd love if you could shed some light on that.

Keith


From: users <users-bounces at shibboleth.net> On Behalf Of Wessel, Keith via users
Sent: Wednesday, February 22, 2023 11:26 AM
To: Ullfig, Roberto A (UIC) <rullfig at uic.edu>; Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: RE: Can a URI be used as an OIDC client ID?

That, to me, points even more to your client version. I didn't get that error when I tested. The fact that the IdP gets the entire client ID string for the call to the authorize endpoint (which is going through the browser) but truncates everything from the colon on to the IDToken request endpoint (which is a back channel call) tells me there's something else going on. You could turn up your Apache logging to debug to see what Apache says it's sending for the IDToken request.

I'll try again to reproduce this on my side this afternoon, too. It's still not out of the question that it's an IdP bug, but I don't think so.

Keith


From: Ullfig, Roberto Alfredo <rullfig at uic.edu>
Sent: Wednesday, February 22, 2023 11:07 AM
To: Wessel, Keith <kwessel at illinois.edu>; Shib Users <users at shibboleth.net>
Subject: Re: Can a URI be used as an OIDC client ID?

Notice how the client id on the IDP changes from debugthis:\/\/shibsp-2.uic.edu to debugthis. We're having some issues reproducing this problem. Do these log messages give any insight?

2023-02-22 10:41:06,230 - DEBUG [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.SetAuthorizationCodeToResponseContext:392] - [64EEE44CBAF888F66D5CB98988A2CFEC] - [128.248.2.59] - Profile Action SetAuthorizationCodeToResponseContext: Setting authz code {"sub":"URCISMG7SJB7Z4TGPTZPNMHCYFUW7Z32","iss":"https:\/\/shibboleth.uic.edu","cnsnt":false,"prncpl":"rullfig","type":"ac","nonce":"O9Gt_I7ceMppE9nFc4rGcNen8AjLZp32j7m01wtmVhA","client_id":"<https://urldefense.com/v3/__https:/shibboleth.uic.edu*22,*22cnsnt*22:false,*22prncpl*22:*22rullfig*22,*22type*22:*22ac*22,*22nonce*22:*22O9Gt_I7ceMppE9nFc4rGcNen8AjLZp32j7m01wtmVhA*22,*22client_id*22:*22__;JSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpvm4wxSA$>debugthis:\/\/shibsp-2.uic.edu","sid":"_a4301f4ee7036485285a1fc2f10fd42a","auth_time":1677084059,"scope":"openid email profile","redirect_uri":"https:\/\/shibsp-2.uic.edu\/oidc\/redirect_uri","exp":1677084366,"iat":1677084066,"jti":"_5afceea932ef5f6407d61a2e8f56b220"<https://urldefense.com/v3/__https:/shibsp-2.uic.edu*5C/oidc*5C/redirect_uri*22,*22exp*22:1677084366,*22iat*22:1677084066,*22jti*22:*22_5afceea932ef5f6407d61a2e8f56b220*22__;JSUlJSUlJSUlJSU!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpRAts0Sg$>} as AAdzZWNyZXQxJxHR-visQ8NUMCJVA0t4DNohXVgUN6qlIHRnnG8b5sUjneWZmuqgkk9tOVfp6AwDT16CNJaM6LRTco0ccej3LkdQEpahuzJW4w5N2bMobaO0BbjOmO6fvFFR0W66BkHE6fR_lnqSgdv268bcotK2djb6bERJmNRB9uuKI53c3TELlvoHTAorBMinQiQKLXxN6xKfj7W_peiagF6hVihXT-yOF-GiiRbMOgiWRKOZ8vmGWLOI_IXsh2XKD5Ldd-59SRMtN1zQ0UGfPdlaIxOXhXIlzcV7Dlzw3Vi1yVgv3pOzglJ3pM7duX6yV5SXbmXX6en6wnaYRO3iQy5NmyYiNN8QiXbdWYHSlCcuiwRLCIroNDhpr88rXqYAJpQbUX5O4pz4qvBioSlWpeMn2c_WK5PnXb_QwXYViGEw9HRVzPK2pVzUmZV0gCH56GrCPG5c3CUHfeEAqmZQe-Kd1GSmrR6R8asw3-t2_YtXVEQeW8W3r77W6M6i0KXw7ji2EsJjRqinw48 to response context
2023-02-22 10:41:06,278 - INFO [Shibboleth-Audit.OIDC.SSO:338] - [64EEE44CBAF888F66D5CB98988A2CFEC] - [128.248.2.59] - 2023-02-22T16:41:06.278883Z|AuthenticationRequest||debugthis://shibsp-2.uic.edu|http://shibboleth.net/ns/profiles/oidc/sso/browser|https://shibboleth.uic.edu|AuthenticationSuccessResponse||rullfig|||URCISMG7SJB7Z4TGPTZPNMHCYFUW7Z32||
2023-02-22 10:41:06,751 - DEBUG [PROTOCOL_MESSAGE.OAUTH2:77] - [037455C6356F66D7216E2ECDE78D8482] - [128.248.156.240] - OIDCTokenRequestDecoder{authorizationGrant=AuthorizationCodeGrant{authorizationCode=AAdzZWNyZXQxJxHR-visQ8NUMCJVA0t4DNohXVgUN6qlIHRnnG8b5sUjneWZmuqgkk9tOVfp6AwDT16CNJaM6LRTco0ccej3LkdQEpahuzJW4w5N2bMobaO0BbjOmO6fvFFR0W66BkHE6fR_lnqSgdv268bcotK2djb6bERJmNRB9uuKI53c3TELlvoHTAorBMinQiQKLXxN6xKfj7W_peiagF6hVihXT-yOF-GiiRbMOgiWRKOZ8vmGWLOI_IXsh2XKD5Ldd-59SRMtN1zQ0UGfPdlaIxOXhXIlzcV7Dlzw3Vi1yVgv3pOzglJ3pM7duX6yV5SXbmXX6en6wnaYRO3iQy5NmyYiNN8QiXbdWYHSlCcuiwRLCIroNDhpr88rXqYAJpQbUX5O4pz4qvBioSlWpeMn2c_WK5PnXb_QwXYViGEw9HRVzPK2pVzUmZV0gCH56GrCPG5c3CUHfeEAqmZQe-Kd1GSmrR6R8asw3-t2_YtXVEQeW8W3r77W6M6i0KXw7ji2EsJjRqinw48, redirectionURI=https://shibsp-2.uic.edu/oidc/redirect_uri<https://urldefense.com/v3/__https:/shibsp-2.uic.edu/oidc/redirect_uri__;!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSp3rkgA5Q$>, type=authorization_code}, clientAuthentication=ClientAuthentication{clientId=debugthis, method=client_secret_basic}, customParameters={state=[nsSH7i0TIsye_rrnGY7Fc5c8xWg]}, endpointURI=https:/idp/profile/oidc/token<https://urldefense.com/v3/__https:/idp/profile/oidc/token__;!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSp8YEUI0g$>}

---
Roberto Ullfig - rullfig at uic.edu<mailto:rullfig at uic.edu>
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: Wessel, Keith <kwessel at illinois.edu<mailto:kwessel at illinois.edu>>
Sent: Friday, February 17, 2023 11:03 AM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Cc: Ullfig, Roberto Alfredo <rullfig at uic.edu<mailto:rullfig at uic.edu>>
Subject: RE: Can a URI be used as an OIDC client ID?


Yes, but the issue is that the IdP is trying to look up an OIDC client with ID of just https. It's dropping the rest of the string.

(RPID https) from the second-to-last log message.



Regardless of whether there's a need to have a colon in the client ID, the spec doesn't state that you can't. So, that sounds like a bug to me.



Thanks, Scott, for confirming that. I'll file a bug.



Keith





From: users <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>> On Behalf Of Ullfig, Roberto Alfredo via users
Sent: Friday, February 17, 2023 9:32 AM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Cc: Ullfig, Roberto A (UIC) <rullfig at uic.edu<mailto:rullfig at uic.edu>>
Subject: Re: Can a URI be used as an OIDC client ID?



With IDP 4.3, we are trying to configure an OIDC client id of https://shibsp-2.uic.edu<https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fshibsp-2.uic.edu__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq7a522kk*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=AW2Kp2COnEy5xYpeSLZsMqtGEMQE1mhIKiDMutEQ9p8*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpoRbIr8o$>. The error is:



2023-02-17 09:25:39,229 - WARN [org.opensaml.saml.metadata.resolver.impl.AbstractDynamicHTTPMetadataResolver:354] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - Metadata Resolver FunctionDrivenDynamicHTTPMetadataResolver incommon: Non-ok status code '404' returned from remote metadata source: https://mdq.incommon.org/entities/https<https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fmdq.incommon.org*2Fentities*2Fhttps__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq6uMjZS6*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=lChtdM*2BYTS48XzMLmzZvvQOcAvNZ4Txqi2Lujv1G5So*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpK8rMCBY$>

2023-02-17 09:25:39,232 - WARN [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:170] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - Profile Action SelectProfileConfiguration: Profile http://shibboleth.net/ns/profiles/oauth2/token<https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__http*3A*2Fshibboleth.net*2Fns*2Fprofiles*2Foauth2*2Ftoken__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq2C-EmYq*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=xP*2BytYpaxUWrbGTg0Oj52jSm299D777rJBGzciot7ZI*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpkv6Glf8$> is not available for RP configuration shibboleth.UnverifiedRelyingParty (RPID https)

2023-02-17 09:25:39,238 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - A non-proceed event occurred while processing the request: InvalidProfileConfiguration



This is the first time that we are trying out the OIDC plugin. We haven't addressed all the deprecated warnings yet so maybe it's related to that. If we remove the ":" character it works just fine. Using a FQDN seems like a good solution at present.



---

Roberto Ullfig - rullfig at uic.edu<mailto:rullfig at uic.edu>
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago

________________________________

From: users <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>> on behalf of Cantor, Scott via users <users at shibboleth.net<mailto:users at shibboleth.net>>
Sent: Friday, February 17, 2023 8:51 AM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Cc: Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>>
Subject: Re: Can a URI be used as an OIDC client ID?



It's a major bug if it doesn't work, I would never use anything but a URI as a client_id, the idea is just ridiculous.

I can't imagine we wouldn't have tested it, but I suppose it's possible it doesn't work with the original JSON resolvers. Still a bug. Even OIDC doesn't *preclude* doing it.

-- Scott


--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Crullfig%40uic.edu%7C183ab72050274a26845a08db10f68082%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C638122423124388779%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=GLF9clUCxeDbdjirAT28pyU3isnjV%2FO9eiFLsAp2yaw%3D&reserved=0<https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fnam04.safelinks.protection.outlook.com*2F*3Furl*3Dhttps*3A*2F*2Fshibboleth.atlassian.net*2Fwiki*2Fx*2FZYEpPw*26data*3D05*7C01*7Crullfig*40uic.edu*7C183ab72050274a26845a08db10f68082*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122423124388779*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C*26sdata*3DGLF9clUCxeDbdjirAT28pyU3isnjV*2FO9eiFLsAp2yaw*3D*26reserved*3D0__*3BJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSU!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOqy0EQ1Ly*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=5zVvLzCKmHlkK1RFvluyDEK4Hf9KZLrQRiZu744q668*3D&reserved=0__;JSUlJSUlJSUlJSoqKioqKiUlKioqKioqKioqKioqKioqJSUqKiUlJSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpG4WsWsE$>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230222/8895f7ab/attachment.htm>


More information about the users mailing list