<div dir="ltr"><div>I was going to follow up but got distracted.</div><div><br></div><div>I've been able to test my setup with an OIDC RP using mod_auth_openidc so I know the configuration is working. The /idp/profile/oidc/register still is generating that error which is what I'll look at fixing now that I've got a few more tips on what to look at.<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Apr 16, 2020 at 11:56 AM Henri Mikkonen <<a href="mailto:henri.mikkonen@csc.fi">henri.mikkonen@csc.fi</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div style="overflow-wrap: break-word;"><div><blockquote type="cite"><div>I've followed that exact page form the wiki to get the extension configured but I'm stuck now with an error when testing an RP when the client tried to register or when I request the /idp/profile/oidc/discovery url. In the logs I keep seeing InvalidProfileConfiguration errors for both registration and for discovery. What files should I be focusing on to fix this issue?</div></blockquote></div><br><div>Check out from the conf/relying-party.xml that you have enabled OIDC.Configuration (corresponds to /idp/profile/oidc/discovery URL) and OIDC.Registration (/idp/profile/oidc/register) for shibboleth.UnverifiedRelyingParty.</div><div><br></div><div>The example on the installation instructions [1] only contains OIDC.Keyset, perhaps it should also contain OIDC.Configuration. The dynamic OP configuration (i.e. the OIDC.Configuration profile) is documented in here [2]</div><div><br></div><div>BR,</div><div>Henri.</div><div><br></div><div>[1] <a href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/Installing-from-archive#profile-configurations" target="_blank">https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/Installing-from-archive#profile-configurations</a></div><div>[2] <a href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/DiscoveryAndOPConfiguration#the-discovery-flow-configuration" target="_blank">https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/DiscoveryAndOPConfiguration#the-discovery-flow-configuration</a></div></div>-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><br>-- <br><div dir="ltr" class="gmail_signature">Darren Boss<br>Senior Programmer/Analyst<br>Programmeur-analyste principal<br><a href="mailto:darren.boss@computecanada.ca" target="_blank">darren.boss@computecanada.ca</a></div>