[External Email] Re: disable oauth2-jwt
Cantor, Scott
cantor.2 at osu.edu
Thu Sep 19 20:43:05 UTC 2024
In point of fact, it sort of makes it look like that client thinks it wants to connect to that IP address URL, and if that were actually true, it should fail when the TLS cert doesn't line up.
So either the client is broken (very seriously) or that isn't the URL it's trying to reach and it's likely connecting to the expected URL in the OP's metadata.
The IdP is logging it obviously, so the client's managed to issue the request and get it into the log, so hopefully it used the real URL and not whatever that custom parameter says.
-- Scott
More information about the users
mailing list