OIDC OP error
Lee, Dong
DLee at umaryland.edu
Fri Apr 17 12:34:29 UTC 2026
Good morning,
Thank you for the previous response. I was able to resolve that error and move forward.
After configuring SSO at the client site, I'm encountering a bad request error from the client application. The log is included below. It appears that OIDCTokenResponse is not in the expected format.
2026-04-17 08:01:07,931 - 104.211.51.176:3074 - INFO [Shibboleth-Audit.OIDC.SSO:333] - 104.211.51.176:3074|2026-04-17T12:01:07.931137699Z|AuthenticationRequest||cognitoforms-test-client|http://shibboleth.net/ns/profiles/oidc/sso/browser%7Chttps://webauth.umaryland.edu%7CAuthenticationSuccessResponse%7C%7Cdlee%7C%7C%7C1234567%7C%7C
2026-04-17 08:02:11,915 - 104.211.51.176:3074 - INFO [Shibboleth-Audit.OIDC.SSO:333] - 104.211.51.176:3074|2026-04-17T12:02:11.915192737Z|AuthenticationRequest||cognitoforms-test-client|http://shibboleth.net/ns/profiles/oidc/sso/browser%7Chttps://webauth.umaryland.edu%7CAuthenticationSuccessResponse%7C%7Cdlee%7C%7C%7C1234567%7C%7C
2026-04-17 08:02:12,236 - 4.156.104.40:32474 - INFO [Shibboleth-Audit.OIDC.Configuration:333] - 4.156.104.40:32474|2026-04-17T12:02:12.236592785Z||||http://shibboleth.net/ns/profiles/oidc/configuration%7C%7COpenIDConfigurationSuccessResponse%7C%7C%7C%7C%7C%7C%7C
2026-04-17 08:02:12,258 - 4.156.104.40:32474 - INFO [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:163] - Credential Validator oauth2-clientinfo: Login by 'cognitoforms-test-client' succeeded
2026-04-17 08:02:12,259 - 4.156.104.40:32474 - INFO [net.shibboleth.idp.authn.impl.FinalizeAuthentication:201] - Profile Action FinalizeAuthentication: Principal cognitoforms-test-client authenticated
2026-04-17 08:02:12,282 - 4.156.104.40:32474 - INFO [Shibboleth-Audit.OIDC.Token:333] - 4.156.104.40:32474|2026-04-17T12:02:12.282225174Z|TokenRequest||cognitoforms-test-client|http://shibboleth.net/ns/profiles/oauth2/token%7Chttps://webauth.umaryland.edu%7COIDCTokenResponse%7C%7Cdlee%7C%7Cat_hash,sub,aud,auth_time,iss,exp,iat,nonce,sid%7C1234567%7C%7C
To test our OIDC OP configuration, I used opendidconnect.net and Postman: I get the code from openidconnect.net and then used Postman to retrieve an access token and user information. This helped me understand the overall flow, but I'm not sure whether this is a valid end-to-end test for the client integration.
2026-04-17 07:45:49,950 - 104.211.51.177:56721 - INFO [Shibboleth-Audit.OIDC.SSO:333] - 104.211.51.177:56721|2026-04-17T11:45:49.950815744Z|AuthenticationRequest||kbyuFDidLLm280LIwVFiazOqjO3ty8KH|http://shibboleth.net/ns/profiles/oidc/sso/browser%7Chttps://webauth.umaryland.edu%7CAuthenticationSuccessResponse%7C%7Cdlee%7C%7C%7C1234567%7C%7C
2026-04-17 07:45:50,402 - 18.208.160.237:53746 - INFO [Shibboleth-Audit.OIDC.Configuration:333] - 18.208.160.237:53746|2026-04-17T11:45:50.402603889Z||||http://shibboleth.net/ns/profiles/oidc/configuration%7C%7COpenIDConfigurationSuccessResponse%7C%7C%7C%7C%7C%7C%7C
2026-04-17 07:46:19,739 - 172.31.64.31 - WARN [org.opensaml.saml.metadata.resolver.impl.AbstractDynamicHTTPMetadataResolver:346] - FunctionDrivenDynamicHTTPMetadataResolver MDQ_InCommon: Non-ok status code '404' returned from remote metadata source: /entities/kbyuFDidLLm280LIwVFiazOqjO3ty8KH
2026-04-17 07:46:19,753 - 172.31.64.31 - INFO [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:163] - Credential Validator oauth2-clientinfo: Login by 'kbyuFDidLLm280LIwVFiazOqjO3ty8KH' succeeded
2026-04-17 07:46:19,754 - 172.31.64.31 - INFO [net.shibboleth.idp.authn.impl.FinalizeAuthentication:201] - Profile Action FinalizeAuthentication: Principal kbyuFDidLLm280LIwVFiazOqjO3ty8KH authenticated
2026-04-17 07:46:19,790 - 172.31.64.31 - INFO [Shibboleth-Audit.OIDC.Token:333] - 172.31.64.31|2026-04-17T11:46:19.790952081Z|TokenRequest||kbyuFDidLLm280LIwVFiazOqjO3ty8KH|http://shibboleth.net/ns/profiles/oauth2/token%7Chttps://webauth.umaryland.edu%7COIDCTokenResponse%7C%7Cdlee%7C%7Cat_hash,sub,aud,auth_time,iss,exp,iat,sid%7C1234567%7C%7C
2026-04-17 07:46:44,820 - 172.31.64.31 - INFO [Shibboleth-Audit.OIDC.UserInfo:333] - 172.31.64.31|2026-04-17T11:46:44.820574422Z|UserInfoRequest||kbyuFDidLLm280LIwVFiazOqjO3ty8KH|http://shibboleth.net/ns/profiles/oidc/userinfo%7Chttps://webauth.umaryland.edu%7CUserInfoSuccessResponse%7C%7Cdlee%7C%7Cname,sub,given_name,family_name,email%7C1234567%7C%7C
Thank you for your time and help.
Dong Lee
Identity Management & System Integration
Center for Information Technology Services
University of Maryland, Baltimore
410-706-3027
dlee at umaryland.edu
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Scott Cantor via users
Sent: Thursday, April 9, 2026 6:41 PM
To: Shib Users <users at shibboleth.net>
Cc: Scott Cantor <scott at restingparrotsoftware.com>
Subject: Re: OIDC OP error
CAUTION: This message originated from a non-UMB email system. Hover over any links before clicking and use caution opening attachments.
You will get better support through member channels, I will send a contact at UM under separate cover.
> 2026-04-09 14:24:49,152 - 10.227.68.81 - WARN [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.ValidateScope:275] - Profile Action ValidateScope: Removing requested but unregistered scope offline_access for RP oidc-test-client
Unregistered, i.e., not in the client metadata (JSON or SAML, regardless). You can't request scopes that are not authorized by the client's metadata.
-- Scott
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list