OIDC Client Secret Resolution with Hashed Secret

Cantor, Scott cantor.2 at osu.edu
Tue May 9 17:22:27 UTC 2023


I suggest you just rethink all this. The simplest way to achieve what you're after is already built-in, just set up client authn to leverage LDAP in the same way the IdP supports it for users. The LDAP bind will take care of keeping the password out of plain text.

-- Scott







More information about the users mailing list