<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US"><div class="m_5585767571852646917gmail-m_8486057101887247765gmail-m_-9026284899358157043WordSection1"><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">One question before I try this, though: why do I have to manually download the OP’s metadata and install it? Isn’t part of the whole thing the module’s ability
 to dynamically discover and download the OP’s information?<br></span></p></div></div></blockquote><div><br></div><div>I think that it's supposed to be able to download the metadata. </div><div><br></div><div>I believe if you give it a hostname, it's supposed to try to find the well-known information, and I think that <a href="mailto:username@example.edu" target="_blank">username@example.edu</a> looks require that .well-known information be located at <a href="https://example.edu" target="_blank">https://example.edu</a>.</div><div><br></div><div>I think that hostname based discovery has issues (at least it did in mid-March).   If I don't specify the protocol, it complains..</div><div><br></div><div>[Fri Mar 15 16:09:00 2019] [error] [client xxx.xxx.xxx.xxx] oidc_metadata_provider_is_valid: requested issuer (<a href="http://idp.example.edu" target="_blank">idp.example.edu</a>) does not match the "issuer" value in the provider metadata file: <a href="https://idp.example.edu" target="_blank">https://idp.example.edu</a>, referer: <a href="https://sp.example.umich.edu/oidc/" target="_blank">https://sp.example.umich.edu/oidc/</a></div><div><br></div><div>The spec says iss is supposed to be a case sensitive HTTPS url.   I had assumed the hostname was sufficient based on the default form and "<a href="http://mitreid.org" target="_blank">mitreid.org</a>" (but even <a href="http://mitreid.org" target="_blank">mitreid.org</a> generates an error, requiring "<a href="https://mitreid.org" target="_blank">https://mitreid.org</a>" to work).</div><div><br></div><div>I asked the developer (Hans Zandbelt) and he said he believed that it was due to a change at some point in the code where he started to put more strict requirements on the provided issuer values because of recent attacks but failed to adapt the HTML discovery pages.</div><div><br></div><div>Liam</div><div><br></div></div></div></div></div><div name="sortd_readrcpt" style="max-width:0;max-height:0;overflow:hidden"><img alt="" style="width:0;max-height:0;overflow:hidden;" src="https://app.sortd.com/rr/5cdc92866cdc02604b7b87e8?from=c9d5bd757ef464da4b7b9dfb04f879b5"></div></div>