<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
p.xmsonormal, li.xmsonormal, div.xmsonormal
        {mso-style-name:x_msonormal;
        margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">And if anyone else who knows the plumbing in the plugin better than me can suggest why a colon might be a point where the client ID stops being processed for a back-channel call to the IDToken endpoint, we’d love if you could shed some
 light on that.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>Wessel, Keith via users<br>
<b>Sent:</b> Wednesday, February 22, 2023 11:26 AM<br>
<b>To:</b> Ullfig, Roberto A (UIC) <rullfig@uic.edu>; Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Wessel, Keith <kwessel@illinois.edu><br>
<b>Subject:</b> RE: Can a URI be used as an OIDC client ID?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">That, to me, points even more to your client version. I didn’t get that error when I tested. The fact that the IdP gets the entire client ID string for the call to the authorize endpoint (which is going through the browser) but truncates
 everything from the colon on to the IDToken request endpoint (which is a back channel call) tells me there’s something else going on. You could turn up your Apache logging to debug to see what Apache says it’s sending for the IDToken request.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’ll try again to reproduce this on my side this afternoon, too. It’s still not out of the question that it’s an IdP bug, but I don’t think so.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> Ullfig, Roberto Alfredo <rullfig@uic.edu> <br>
<b>Sent:</b> Wednesday, February 22, 2023 11:07 AM<br>
<b>To:</b> Wessel, Keith <kwessel@illinois.edu>; Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Can a URI be used as an OIDC client ID?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">Notice how the client id on the IDP changes from debugthis:\/\/shibsp-2.uic.edu to debugthis. We're having some issues reproducing this problem. Do these log messages give
 any insight?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-22 10:41:06,230 - DEBUG [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.SetAuthorizationCodeToResponseContext:392] - [64EEE44CBAF888F66D5CB98988A2CFEC] -
 [128.248.2.59] - Profile Action SetAuthorizationCodeToResponseContext: Setting authz code {"sub":"URCISMG7SJB7Z4TGPTZPNMHCYFUW7Z32","iss":"<a href="https://urldefense.com/v3/__https:/shibboleth.uic.edu*22,*22cnsnt*22:false,*22prncpl*22:*22rullfig*22,*22type*22:*22ac*22,*22nonce*22:*22O9Gt_I7ceMppE9nFc4rGcNen8AjLZp32j7m01wtmVhA*22,*22client_id*22:*22__;JSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpvm4wxSA$">https:\/\/shibboleth.uic.edu","cnsnt":false,"prncpl":"rullfig","type":"ac","nonce":"O9Gt_I7ceMppE9nFc4rGcNen8AjLZp32j7m01wtmVhA","client_id":"</a><b>debugthis:\/\/shibsp-2.uic.edu</b>","sid":"_a4301f4ee7036485285a1fc2f10fd42a","auth_time":1677084059,"scope":"openid
 email profile","redirect_uri":"<a href="https://urldefense.com/v3/__https:/shibsp-2.uic.edu*5C/oidc*5C/redirect_uri*22,*22exp*22:1677084366,*22iat*22:1677084066,*22jti*22:*22_5afceea932ef5f6407d61a2e8f56b220*22__;JSUlJSUlJSUlJSU!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpRAts0Sg$">https:\/\/shibsp-2.uic.edu\/oidc\/redirect_uri","exp":1677084366,"iat":1677084066,"jti":"_5afceea932ef5f6407d61a2e8f56b220"</a>}
 as AAdzZWNyZXQxJxHR-visQ8NUMCJVA0t4DNohXVgUN6qlIHRnnG8b5sUjneWZmuqgkk9tOVfp6AwDT16CNJaM6LRTco0ccej3LkdQEpahuzJW4w5N2bMobaO0BbjOmO6fvFFR0W66BkHE6fR_lnqSgdv268bcotK2djb6bERJmNRB9uuKI53c3TELlvoHTAorBMinQiQKLXxN6xKfj7W_peiagF6hVihXT-yOF-GiiRbMOgiWRKOZ8vmGWLOI_IXsh2XKD5Ldd-59SRMtN1zQ0UGfPdlaIxOXhXIlzcV7Dlzw3Vi1yVgv3pOzglJ3pM7duX6yV5SXbmXX6en6wnaYRO3iQy5NmyYiNN8QiXbdWYHSlCcuiwRLCIroNDhpr88rXqYAJpQbUX5O4pz4qvBioSlWpeMn2c_WK5PnXb_QwXYViGEw9HRVzPK2pVzUmZV0gCH56GrCPG5c3CUHfeEAqmZQe-Kd1GSmrR6R8asw3-t2_YtXVEQeW8W3r77W6M6i0KXw7ji2EsJjRqinw48
 to response context <o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-22 10:41:06,278 - INFO [Shibboleth-Audit.OIDC.SSO:338] - [64EEE44CBAF888F66D5CB98988A2CFEC] - [128.248.2.59] - 2023-02-22T16:41:06.278883Z|AuthenticationRequest||debugthis://shibsp-2.uic.edu|http://shibboleth.net/ns/profiles/oidc/sso/browser|https://shibboleth.uic.edu|AuthenticationSuccessResponse||rullfig|||URCISMG7SJB7Z4TGPTZPNMHCYFUW7Z32||<o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-22 10:41:06,751 - DEBUG [PROTOCOL_MESSAGE.OAUTH2:77] - [037455C6356F66D7216E2ECDE78D8482] - [128.248.156.240] - OIDCTokenRequestDecoder{authorizationGrant=AuthorizationCodeGrant{authorizationCode=AAdzZWNyZXQxJxHR-visQ8NUMCJVA0t4DNohXVgUN6qlIHRnnG8b5sUjneWZmuqgkk9tOVfp6AwDT16CNJaM6LRTco0ccej3LkdQEpahuzJW4w5N2bMobaO0BbjOmO6fvFFR0W66BkHE6fR_lnqSgdv268bcotK2djb6bERJmNRB9uuKI53c3TELlvoHTAorBMinQiQKLXxN6xKfj7W_peiagF6hVihXT-yOF-GiiRbMOgiWRKOZ8vmGWLOI_IXsh2XKD5Ldd-59SRMtN1zQ0UGfPdlaIxOXhXIlzcV7Dlzw3Vi1yVgv3pOzglJ3pM7duX6yV5SXbmXX6en6wnaYRO3iQy5NmyYiNN8QiXbdWYHSlCcuiwRLCIroNDhpr88rXqYAJpQbUX5O4pz4qvBioSlWpeMn2c_WK5PnXb_QwXYViGEw9HRVzPK2pVzUmZV0gCH56GrCPG5c3CUHfeEAqmZQe-Kd1GSmrR6R8asw3-t2_YtXVEQeW8W3r77W6M6i0KXw7ji2EsJjRqinw48,
 redirectionURI=<a href="https://urldefense.com/v3/__https:/shibsp-2.uic.edu/oidc/redirect_uri__;!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSp3rkgA5Q$">https://shibsp-2.uic.edu/oidc/redirect_uri</a>, type=authorization_code},
 clientAuthentication=ClientAuthentication{clientId=<b>debugthis</b>, method=client_secret_basic}, customParameters={state=[nsSH7i0TIsye_rrnGY7Fc5c8xWg]}, endpointURI=<a href="https://urldefense.com/v3/__https:/idp/profile/oidc/token__;!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSp8YEUI0g$">https:/idp/profile/oidc/token</a>}<o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;color:black"><o:p> </o:p></span></p>
</div>
<div id="Signature">
<div>
<div id="divtagdefaultwrapper">
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">---
<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">
<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>><br>
<b>Sent:</b> Friday, February 17, 2023 11:03 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Ullfig, Roberto Alfredo <<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a>><br>
<b>Subject:</b> RE: Can a URI be used as an OIDC client ID?</span> <o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="xmsonormal">Yes, but the issue is that the IdP is trying to look up an OIDC client with ID of just https. It’s dropping the rest of the string.<o:p></o:p></p>
<p class="xmsonormal"><span style="font-size:12.0pt;color:black">(RPID https) from the second-to-last log message.</span><o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">Regardless of whether there’s a need to have a colon in the client ID, the spec doesn’t state that you can’t. So, that sounds like a bug to me.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">Thanks, Scott, for confirming that. I’ll file a bug.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">Keith<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="xmsonormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Ullfig, Roberto Alfredo via users<br>
<b>Sent:</b> Friday, February 17, 2023 9:32 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Ullfig, Roberto A (UIC) <<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a>><br>
<b>Subject:</b> Re: Can a URI be used as an OIDC client ID?<o:p></o:p></p>
</div>
</div>
<p class="xmsonormal"> <o:p></o:p></p>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black">With IDP 4.3, we are trying to configure an OIDC client id of <a href="https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fshibsp-2.uic.edu__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq7a522kk*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=AW2Kp2COnEy5xYpeSLZsMqtGEMQE1mhIKiDMutEQ9p8*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpoRbIr8o$">https://shibsp-2.uic.edu</a>.
 The error is:</span><o:p></o:p></p>
</div>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black"> </span><o:p></o:p></p>
</div>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,229 - WARN [org.opensaml.saml.metadata.resolver.impl.AbstractDynamicHTTPMetadataResolver:354] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240]
 - Metadata Resolver FunctionDrivenDynamicHTTPMetadataResolver incommon: Non-ok status code '404' returned from remote metadata source:
<a href="https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fmdq.incommon.org*2Fentities*2Fhttps__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq6uMjZS6*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=lChtdM*2BYTS48XzMLmzZvvQOcAvNZ4Txqi2Lujv1G5So*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpK8rMCBY$">
https://mdq.incommon.org/entities/https</a> </span><o:p></o:p></p>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,232 - WARN [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:170] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - Profile Action
 SelectProfileConfiguration: Profile <a href="https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__http*3A*2Fshibboleth.net*2Fns*2Fprofiles*2Foauth2*2Ftoken__*3B!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOq2C-EmYq*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=xP*2BytYpaxUWrbGTg0Oj52jSm299D777rJBGzciot7ZI*3D&reserved=0__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpkv6Glf8$">
http://shibboleth.net/ns/profiles/oauth2/token</a> is not available for RP configuration shibboleth.UnverifiedRelyingParty (RPID https)</span><o:p></o:p></p>
</div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black">2023-02-17 09:25:39,238 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [B2B49187738282D4A714FFBB4516683E] - [128.248.156.240] - A non-proceed event occurred
 while processing the request: InvalidProfileConfiguration</span><o:p></o:p></p>
</div>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black"> </span><o:p></o:p></p>
</div>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:12.0pt;color:black">This is the first time that we are trying out the OIDC plugin. We haven't addressed all the deprecated warnings yet so maybe it's related to that. If we remove the ":"
 character it works just fine. Using a FQDN seems like a good solution at present.</span><o:p></o:p></p>
</div>
<div>
<div>
<p class="xmsonormal"><span style="font-size:12.0pt;color:black"> </span><o:p></o:p></p>
</div>
<div id="x_Signature">
<div>
<div id="x_divtagdefaultwrapper">
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">---
</span><o:p></o:p></p>
<div>
<p class="xmsonormal" style="background:white"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">
</span><o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="x_divRplyFwdMsg">
<p class="xmsonormal"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Sent:</b> Friday, February 17, 2023 8:51 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
<b>Subject:</b> Re: Can a URI be used as an OIDC client ID?</span> <o:p></o:p></p>
<div>
<p class="xmsonormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="xmsonormal">It's a major bug if it doesn't work, I would never use anything but a URI as a client_id, the idea is just ridiculous.<br>
<br>
I can't imagine we wouldn't have tested it, but I suppose it's possible it doesn't work with the original JSON resolvers. Still a bug. Even OIDC doesn't *preclude* doing it.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/nam04.safelinks.protection.outlook.com/?url=https*3A*2F*2Furldefense.com*2Fv3*2F__https*3A*2Fnam04.safelinks.protection.outlook.com*2F*3Furl*3Dhttps*3A*2F*2Fshibboleth.atlassian.net*2Fwiki*2Fx*2FZYEpPw*26data*3D05*7C01*7Crullfig*40uic.edu*7C183ab72050274a26845a08db10f68082*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122423124388779*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C*26sdata*3DGLF9clUCxeDbdjirAT28pyU3isnjV*2FO9eiFLsAp2yaw*3D*26reserved*3D0__*3BJSUlJSUlJSUlJSUlJSUlJSUlJSUlJSU!!DZ3fjg!-R5RHUAsJvkHHd2Qn4tkRTWGg4M0V9IQmZZkiZXWmp-8VzYDT8HJx4AtadWO-QYXeBFUsDFN3tTOqy0EQ1Ly*24&data=05*7C01*7Crullfig*40uic.edu*7C08eb238e6d294803a7d608db1108f558*7Ce202cd477a564baa99e3e3b71a7c77dd*7C0*7C0*7C638122502396507296*7CUnknown*7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0*3D*7C3000*7C*7C*7C&sdata=5zVvLzCKmHlkK1RFvluyDEK4Hf9KZLrQRiZu744q668*3D&reserved=0__;JSUlJSUlJSUlJSoqKioqKiUlKioqKioqKioqKioqKioqJSUqKiUlJSUlJSUlJSUlJSUlJSUlJSUl!!DZ3fjg!6ozkYDB3b9MQBGfVfwJ5zn8Sx5T9xqRDKjyR8d53YR_n0kNtBDrU6d3nLoqcjGgjh1RoFw5ZccSpG4WsWsE$">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Crullfig%40uic.edu%7C183ab72050274a26845a08db10f68082%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C638122423124388779%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=GLF9clUCxeDbdjirAT28pyU3isnjV%2FO9eiFLsAp2yaw%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>