<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Yes, but the issue is that the IdP is trying to look up an OIDC client with ID of just https. It’s dropping the rest of the string.<o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black">(RPID https) from the second-to-last log message.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Regardless of whether there’s a need to have a colon in the client ID, the spec doesn’t state that you can’t. So, that sounds like a bug to me.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks, Scott, for confirming that. I’ll file a bug.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>Ullfig, Roberto Alfredo via users<br>
<b>Sent:</b> Friday, February 17, 2023 9:32 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Ullfig, Roberto A (UIC) <rullfig@uic.edu><br>
<b>Subject:</b> Re: Can a URI be used as an OIDC client ID?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">With IDP 4.3, we are trying to configure an OIDC client id of <a href="https://urldefense.com/v3/__https:/shibsp-2.uic.edu__;!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq7a522kk$">https://shibsp-2.uic.edu</a>.
 The error is:<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,229 - WARN [org.opensaml.saml.metadata.resolver.impl.AbstractDynamicHTTPMetadataResolver:354] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240]
 - Metadata Resolver FunctionDrivenDynamicHTTPMetadataResolver incommon: Non-ok status code '404' returned from remote metadata source:
<a href="https://urldefense.com/v3/__https:/mdq.incommon.org/entities/https__;!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq6uMjZS6$">
https://mdq.incommon.org/entities/https</a> <o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,232 - WARN [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:170] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - Profile Action
 SelectProfileConfiguration: Profile <a href="https://urldefense.com/v3/__http:/shibboleth.net/ns/profiles/oauth2/token__;!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq2C-EmYq$">
http://shibboleth.net/ns/profiles/oauth2/token</a> is not available for RP configuration shibboleth.UnverifiedRelyingParty (RPID https)<o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,238 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - A non-proceed event occurred while
 processing the request: InvalidProfileConfiguration<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">This is the first time that we are trying out the OIDC plugin. We haven't addressed all the deprecated warnings yet so maybe it's related to that. If we remove the ":"
 character it works just fine. Using a FQDN seems like a good solution at present.<o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div id="Signature">
<div>
<div id="divtagdefaultwrapper">
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">---
<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">
<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Sent:</b> Friday, February 17, 2023 8:51 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
<b>Subject:</b> Re: Can a URI be used as an OIDC client ID?</span> <o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal">It's a major bug if it doesn't work, I would never use anything but a URI as a client_id, the idea is just ridiculous.<br>
<br>
I can't imagine we wouldn't have tested it, but I suppose it's possible it doesn't work with the original JSON resolvers. Still a bug. Even OIDC doesn't *preclude* doing it.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Fshibboleth.atlassian.net*2Fwiki*2Fx*2FZYEpPw&data=05*7C01*7Crullfig*40uic.edu*7C183ab72050274a26845a08db10f68082*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122423124388779*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=GLF9clUCxeDbdjirAT28pyU3isnjV*2FO9eiFLsAp2yaw*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSU!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOqy0EQ1Ly$">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Crullfig%40uic.edu%7C183ab72050274a26845a08db10f68082%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C638122423124388779%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=GLF9clUCxeDbdjirAT28pyU3isnjV%2FO9eiFLsAp2yaw%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>