<div dir="ltr">Thanks Scott. Is this the secret key store ?<br><div><br></div><div>idp.properties:idp.sealer.storeResource = %{idp.home}/credentials/sealer.jks<br></div><div><br></div><div>And this needs to be the same on all IdP server instances? </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Mar 2, 2021 at 8:45 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 3/2/21, 8:37 AM, "users on behalf of Mohamed Lrhazi" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:lrhazi@cua.edu" target="_blank">lrhazi@cua.edu</a>> wrote:<br>
<br>
>    I am setting up my first OIDC config and after it started working for a few days, several users report that it suddenly<br>
> stopped working. I find the following in the log:<br>
<br>
That's impossible unless you corrupted the secret key store (i.e. you have two different keys under the same alias on different servers) or the token was actually corrupted by the caller. <br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>