<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hi list,</p>
<p>this is now the second time I seem to be unable to set the OIDC
issuer for the IdP. This is an upgraded IdPv4, and GEANT OIDC
plugin installed along
<a class="moz-txt-link-freetext" href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/Installing-from-archive">https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/Installing-from-archive</a></p>
<p>Although I have set the issuer in idp-oidc.properties...</p>
<p>idp.oidc.issuer= <a class="moz-txt-link-freetext" href="https://portal-dev.example.prj/idp">https://portal-dev.example.prj/idp</a><br>
</p>
<p>...the OIDC ID token seems to contain the entityID instead:</p>
<p>[Tue Mar 09 09:08:42.616020 2021] [auth_openidc:error] [pid
18630] [client 10.0.8.7:44184] oidc_proto_validate_jwt: requested
issuer (<a class="moz-txt-link-freetext" href="https://portal-dev.example.prj/idp">https://portal-dev.example.prj/idp</a>) does not match
received "iss" value in id_token
(<a class="moz-txt-link-freetext" href="https://portal-dev.example.prj/idp">https://portal-dev.example.prj/idp</a><b>/</b><b>shibboleth</b>),
referer: <a class="moz-txt-link-freetext" href="https://ubuntu1804sp.daasi.test/dummy-oidc">https://ubuntu1804sp.daasi.test/dummy-oidc</a><br>
</p>
<p>Any idea why this could happen, and how to fix it? <br>
</p>
<p>Regards</p>
<p>Martin<br>
</p>
<p><br>
</p>
<p><br>
</p>
<pre class="moz-signature" cols="72">--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-0
fax: +49 7071 407109-9
email: <a class="moz-txt-link-abbreviated" href="mailto:martin.haase@daasi.de">martin.haase@daasi.de</a>
web: <a class="moz-txt-link-abbreviated" href="http://www.daasi.de">www.daasi.de</a>
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
</pre>
</body>
</html>