OIDC client authentication issue

Guillaume Rousse guillaume.rousse at renater.fr
Mon Aug 10 14:48:40 UTC 2026



Le 10/08/2026 à 15:48, Scott Cantor via users a écrit :
> 
>> Is the RP supposed to tell the server which method he is using, or is
>> the OP supposed to adapt itself to whatever method is actually used ?
> 
> Yes to the former, and definitely not to the latter. You have to configure the security features you want to allow, generally with profile configuration settings, but we also assume that whatever registration metadata is used will be accurate, and both have to permit something.

Indeed. I just have to remember than with static registration, OIDC 
client metadata are actually maintained on server side, not on client 
side...

Regards.
-- 
Guillaume Rousse
Direction des Services Applicatifs
RENATER - Paris

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4330 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20260810/6f69a095/attachment.p7s>


More information about the users mailing list