<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Henri,</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Still no success</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
I'm using this to test</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
curl --location https://REDACTED/idp/profile/oidc/token --header "Content-Type: application/x-www-form-urlencoded" --header "Accept: application/json" --data-urlencode grant_type=client_credentials --data-urlencode client_id=https://REDacted/oidc --data-urlencode
client_secret=VERY_VERY_SECRET  --data-urlencode scope=openid</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
{"error":"invalid_request","error_description":"InvalidMessageContext"}</div>
<ul data-editing-info="{"applyListStyleFromLevel":true}" style="list-style-type: disc;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<div class="elementToProof"><b>idp-process.log</b></div>
</li></ul>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,485 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractInitializeOutboundResponseMessageContext:69] - Profile Action InitializeOutboundTokenResponseMessageContext: Initialized outbound message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler'
on INBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.oauth2.sdk.TokenRequest'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler:113] - Message Handler: No client information returned for https://REDACTED/oidc</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:162] - Attaching RelyingPartyContext for https://REDACTED/oidc</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler'
on INBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,487 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.oauth2.sdk.TokenRequest'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,488 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.oauth2.messaging.impl.SetEntityIdToSAMLPeerEntityContext'
on INBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,488 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.oauth2.sdk.TokenRequest'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,488 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.oauth2.messaging.impl.SetEntityIdToSAMLPeerEntityContext:98] - Message Handler: Set clientID 'https://REDACTED/oidc' to the peer entity context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,512 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler'
on INBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,512 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.oauth2.sdk.TokenRequest'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,512 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.oauth2.messaging.impl.PopulateOIDCMetadataContext'
on INBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,512 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.oauth2.sdk.TokenRequest'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,512 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.oauth2.messaging.impl.PopulateOIDCMetadataContext:96] - Message Handler: Client information found and attached</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,513 - IP_REDACTED - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:131] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer https://REDACTED/oidc</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,513 - IP_REDACTED - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:253] - Resolving relying party configuration</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,513 - IP_REDACTED - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:265] - Checking if relying party configuration csu.NoUserConsent is applicable</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,513 - IP_REDACTED - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:267] - Relying party configuration csu.NoUserConsent is applicable</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,513 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:174] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration csu.NoUserConsent for request</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,514 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.interceptor.impl.PopulateProfileInterceptorContext:147] - Profile Action PopulateProfileInterceptorContext: No inbound interceptor flows active for this request</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,514 - IP_REDACTED - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:222] - Profile Action InitializeAuthenticationContext: Created authentication context: AuthenticationContext{initiationInstant=2024-08-30T05:03:25.514537Z,
isPassive=false, forceAuthn=false, requiredName=null, hintedName=null, maxAge=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, authenticationStateMap={}, resultCacheable=true, authenticationResult=null, completionInstant=null}</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:213] - Profile Action PopulateAuthenticationContext: Installed 1 potential authentication flows into AuthenticationContext</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:152] - Profile Action InitializeRequestedPrincipalContext: Profile configuration did not supply any default authentication methods</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:57] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:76] - Profile Action FilterFlowsByNonBrowserSupport: Retaining flow authn/OAuth2Client, it supports non-browser authentication</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:88] - Profile Action FilterFlowsByNonBrowserSupport: Potential authentication flows left after filtering: [authn/OAuth2Client]</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,515 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:274] - Profile Action SelectAuthenticationFlow: No specific Principals requested</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,516 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:312] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,516 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/OAuth2Client</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,518 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:143] - Credential Validator oauth2-clientinfo: Attempting to authenticate effective client ID 'https://REDACTED/oidc'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - INFO [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:152] - Credential Validator oauth2-clientinfo: Login by 'https://REDACTED/oidc' succeeded</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.AbstractValidationAction:398] - Profile Action ValidateCredentials: Adding custom Principal(s) defined on underlying flow descriptor</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.PopulateSubjectCanonicalizationContext:75] - Profile Action PopulateSubjectCanonicalizationContext: Installing 2 canonicalization flows into SubjectCanonicalizationContext</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100] - Profile Action SelectSubjectCanonicalizationFlow: Checking canonicalization flow c14n/x500 for applicability...</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:106] - Profile Action SelectSubjectCanonicalizationFlow: Canonicalization flow c14n/x500 was not applicable: Neither a single X509Certificate nor
X500Principal were found</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,519 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100] - Profile Action SelectSubjectCanonicalizationFlow: Checking canonicalization flow c14n/simple for applicability...</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:83] - Profile Action SelectSubjectCanonicalizationFlow: Selecting canonicalization flow c14n/simple</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction:221] - Profile Action SimpleSubjectCanonicalization: trimming whitespace of input string 'https://REDACTED/oidc'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - DEBUG [net.shibboleth.idp.session.impl.DetectIdentitySwitch:148] - Profile Action DetectIdentitySwitch: No previous session found, nothing to do</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:116] - Profile Action FinalizeAuthentication: Canonical principal name was established as 'https://REDACTED/oidc'</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:171] - Profile Action FinalizeAuthentication: Request did not have explicit authentication requirements, result is accepted</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,520 - IP_REDACTED - INFO [net.shibboleth.idp.authn.impl.FinalizeAuthentication:196] - Profile Action FinalizeAuthentication: Principal https://REDACTED/oidc authenticated</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,521 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetAuthenticationContextClassReferenceToResponseContext:136] - Profile Action SetAuthenticationContextClassReferenceToResponseContext: Setting acr based on performed
flow</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,521 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetAuthenticationTimeToResponseContext:76] - Profile Action SetAuthenticationTimeToResponseContext: Setting authentication time to 2024-08-30T05:03:25.519366Z</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,522 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetSectorIdentifierForAttributeResolution:89] - Profile Action SetSectorIdentifierForAttributeResolution: Attribute recipient group id set to value public for generating
subject of type public</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,522 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.oauth2.profile.impl.ValidateAudience:194] - Profile Action ValidateAudience: No allowed audiences for client https://REDACTED/oidc, OP will be sole audience</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,522 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetSessionIdToResponseContext:70] - Profile Action SetSessionIdToResponseContext: Setting session id value to _ed426144985ed9ea780a104d85a8ed6b</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,522 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:174] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler'
on OUTBOUND message context</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,523 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler:105] - Message Handler: No client ID available</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,523 - IP_REDACTED - ERROR [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:144] - resource/audience ID Unable to obtain Profile Action InitializeRelyingPartyContext:</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,523 - IP_REDACTED - WARN [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event occurred while processing the request: InvalidMessageContext</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,524 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractBuildErrorResponseFromEvent:159] - Profile Action BuildTokenErrorResponseFromEvent: No mapped event found for InvalidMessageContext, creating general invalid_request</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,524 - IP_REDACTED - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractBuildErrorResponseFromEvent:166] - Profile Action BuildTokenErrorResponseFromEvent: ErrorResponse successfully set as the outbound message</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,525 - IP_REDACTED - INFO [Shibboleth-Audit.OIDC.Token:338] - IP_REDACTED|2024-08-30T05:03:25.485738Z|2024-08-30T05:03:25.525333Z|https://REDACTED/oidc|https://REDACTED/oidc|||2024-08-30T05:03:25.519366Z||https://REDACTED/oidc||false|||TokenRequest|TokenErrorResponse|||||curl/8.7.1</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2024-08-30 15:03:25,525 - IP_REDACTED - DEBUG [net.shibboleth.idp.profile.impl.RecordResponseComplete:89] - Profile Action RecordResponseComplete: Record response complete</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<ul data-editing-info="{"applyListStyleFromLevel":true}" style="list-style-type: disc;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<div class="elementToProof"><b>metadata file</b></div>
</li></ul>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
xmlns:oidcmd="urn:mace:shibboleth:metadata:oidc:1.0"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
entityID="https://REDACTED/oidc"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:SPSSODescriptor protocolSupportEnumeration="http://openid.net/specs/openid-connect-core-1_0.html"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:Extensions></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<oidcmd:OAuthRPExtensions</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
grant_types="client_credentials"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
response_types="code token id_token"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
token_endpoint_auth_method="client_secret_post"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
scopes="openid profile" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</md:Extensions></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:KeyDescriptor></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<oidcmd:ClientSecret>VERY_VERY_SECRET</oidcmd:ClientSecret></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</ds:KeyInfo></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</md:KeyDescriptor></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:NameIDFormat>urn:mace:shibboleth:metadata:oidc:1.0:nameid-format:public</md:NameIDFormat></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<md:AssertionConsumerService Binding="https://tools.ietf.org/html/rfc6749#section-3.1.2"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Location="https://REDACTED/restapi"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
index="1" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</md:SPSSODescriptor></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</md:EntityDescriptor></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<ul data-editing-info="{"applyListStyleFromLevel":true}" style="list-style-type: disc;">
<li style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<div class="elementToProof"><b>relying party override</b><br>
<br>
</div>
</li></ul>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<bean id="csu.NoUserConsent" parent="RelyingPartyByTag"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<constructor-arg name="candidates"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<list></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<bean id="noAttributeConsentRequired" parent="TagCandidate"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
c:name="RelyingPartyOverride"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
c:format="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"</div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
p:values="NoUserConsent" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</list></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</constructor-arg></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<property name="profileConfigurations"></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<list></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="Shibboleth.SSO" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML1.AttributeQuery" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML1.ArtifactResolution" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<bean parent="SAML2.SSO.MDDriven" p:postAuthenticationFlows="#{{'member'}}" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML2.ECP" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML2.Logout" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML2.AttributeQuery" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="SAML2.ArtifactResolution" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<bean parent="OIDC.SSO" p:postAuthenticationFlows="#{{'member'}}" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="OIDC.UserInfo"/></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="OAUTH2.Revocation"/></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<ref bean="OAUTH2.Introspection" /></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</list></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</property></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
</bean></div>
<div style="line-height: 19px; white-space: pre; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<p><span style="font-family: Arial, sans-serif; font-size: 10pt; color: rgb(218, 61, 15);"><b>Gary Lipscomb</b></span></p>
<p><span style="font-family: Arial, sans-serif; font-size: 9pt;">Technical Officer, Systems</span></p>
<p><span style="font-family: Arial, sans-serif; font-size: 9pt;">IT </span><span style="font-family: Arial, sans-serif; font-size: 9pt; color: rgb(65, 65, 65);">Infrastructure & Security | Division of Information Technology</span></p>
<p> </p>
</div>
<div id="appendonsend"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div id="divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Lipscomb, Gary via users <users@shibboleth.net><br>
<b>Sent:</b> Friday, 30 August 2024 08:21<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Lipscomb, Gary <glipscomb@csu.edu.au><br>
<b>Subject:</b> Re: Configuring OIDC to use client_credentials - InvalidMessageContext</span>
<div> </div>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi Henri,</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Thanks for the quick reply and your troubleshooting.</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
I'll work my way through this and let you know how I go.</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
regards</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Gary</div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="x_Signature">
<p style="margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<span style="font-family: Arial, sans-serif; font-size: 10pt; color: rgb(218, 61, 15);"><b>Gary Lipscomb</b></span></p>
<p style="margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<span style="font-family: Arial, sans-serif; font-size: 9pt;">Technical Officer, Systems</span></p>
<p style="margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<span style="font-family: Arial, sans-serif; font-size: 9pt;">IT </span><span style="font-family: Arial, sans-serif; font-size: 9pt; color: rgb(65, 65, 65);">Infrastructure & Security | Division of Information Technology</span></p>
<p style="margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
</p>
</div>
<div id="x_appendonsend"></div>
<div style="direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="direction: ltr; display: inline-block; width: 98%;">
<div id="x_divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Henri Mikkonen <henri.mikkonen@nimbleidm.com><br>
<b>Sent:</b> Thursday, 29 August 2024 16:45<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Configuring OIDC to use client_credentials - InvalidMessageContext</span>
<div> </div>
</div>
<div style="direction: ltr; font-size: 11pt;">Hi Gary,<br>
<br>
I was finally able to reproduce the behaviour with the following remarks:<br>
<br>
- scope 'openid' is registered in the metadata (like you do) and also<br>
requested by the client. This is the main reason for the confusing logs:<br>
the current code is using that scope to signal the use of OpenID Connect<br>
sequence, which is never the case with the client credentials grant. If<br>
you remove the use of that scope, you'll probably see error message with<br>
description "Improper or disallowed resource indicator".<br>
<br>
- The error description above is related to the lack of using resource<br>
indicator in the request, or the client does not have any registered<br>
audiences. See<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/SC/pages/1912406916/OAuthRPMetadataProfile" id="OWAd1b8eda5-3eb9-e2bc-bc78-92baddeebe0c" class="x_OWAAutoLink" shash="UIEFhTYLchihdEtmb2HI4E8wn/MzzQQfmw+M8yXUaCc4/EiW+139h4/kVmz5AT18Gzjj4PHsJDCGAqnHd5QzL/pDGgIzxfv24GcYybQOBvXAt2MrdMW/kqYZJqYt2iT/DbxRkMuqQSsOx+nEcIoVktf4PPCJcBjGRtDE6DVPI8Q=" originalsrc="https://shibboleth.atlassian.net/wiki/spaces/SC/pages/1912406916/OAuthRPMetadataProfile" data-auth="Verified">https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fspaces%2FSC%2Fpages%2F1912406916%2FOAuthRPMetadataProfile&data=05%7C02%7Cglipscomb%40csu.edu.au%7C960ba6ad52b74834f9cc08dcc7f6300b%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638605107406790513%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=UJh5E4ZJAgrY4TIGgw2PA8Gle7kAeinlav8FT4pjHwI%3D&reserved=0</a><br>
. The logic is that unless the client requests any specific resource,<br>
the first registered audience is used as the access token<br>
target/audience. In any case, the registered resources need to have<br>
OAUTH2.TokenAudience profile enabled. You should have that covered as<br>
you've enabled it via DefaultRelyingParty.<br>
<br>
Regarding the scopes, until OP 4.1.0 you need to be using some scope<br>
value in the request. See <a href="https://shibboleth.atlassian.net/browse/JOIDC-176" id="OWA4a07c630-57ad-1470-a17b-d5b5a4220721" class="x_OWAAutoLink" shash="JyvT8jXi/H5lqRBDuuaciEqJGz468dlZWwjoMUOl8o5KYNiPODYUCw2TZ8CdF+5E1zBFANXpX/Gi+0fZ7vCOoElXauXx8+vlNlfC9+ppAThdSvf6r6C/JDcuNgIn4nHU/cw4M4wIyaRwLoy1M+3vxP5WkBwpMwY4dOAW7yn5VwE=" originalsrc="https://shibboleth.atlassian.net/browse/JOIDC-176" data-auth="Verified">
https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fbrowse%2FJOIDC-176&data=05%7C02%7Cglipscomb%40csu.edu.au%7C960ba6ad52b74834f9cc08dcc7f6300b%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638605107406801278%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=9SsFLo2UGA31lODR72xruDw2QzlwNli3P%2FXkVVZWtpk%3D&reserved=0</a><br>
<br>
BR,<br>
Henri.<br>
<br>
On 29.8.2024 5.58, Lipscomb, Gary via users wrote:<br>
> Hi List,<br>
><br>
> Environment<br>
><br>
> *<br>
> RHEL 8<br>
> *<br>
> IdP 4.3.3 (currently migrating to 5.1.3)<br>
> *<br>
> Plugins<br>
> o<br>
> Plugin: net.shibboleth.oidc.common Current Version: 2.2.1<br>
> o<br>
> Plugin: net.shibboleth.idp.plugin.oidc.config Current Version:<br>
> 1.0.1<br>
> o<br>
> Plugin: net.shibboleth.idp.plugin.oidc.op Current Version:<br>
> 3.4.0<br>
> *<br>
> Java openjdk version "11.0.24"<br>
><br>
> I think I've got the authentication working but I'm getting this in the log<br>
><br>
> 2024-08-29 10:13:54,603 - IP REDACTED - INFO<br>
> [net.shibboleth.idp.plugin.oidc.op.authn.impl.OIDCClientInfoCredentialValidator:152] - Credential Validator oauth2-clientinfo: Login by '<a href="https://redacted.csu.edu.au/oidc" id="OWA3f3b0011-2fd4-ed46-83c2-a5bcb26481d5" class="x_OWAAutoLink" data-auth="NotApplicable">https://REDACTED.csu.edu.au/oidc</a>'
succeeded<br>
> 2024-08-29 10:13:54,603 -IP REDACTED - INFO<br>
> [net.shibboleth.idp.authn.impl.FinalizeAuthentication:196] - Profile<br>
> Action FinalizeAuthentication: Principal <a href="https://REDACTED" id="OWA17ae8a29-8bf1-5583-4fc7-c73ddd6a42e4" class="x_OWAAutoLink" data-auth="NotApplicable">
https://REDACTED</a><br>
> <<a href="https://REDACTED" id="OWA20a2a63b-cdf3-19d9-2e7d-b1eeb01a3f44" class="x_OWAAutoLink" data-auth="NotApplicable">https://REDACTED</a>>.csu.edu.au/oidc authenticated<br>
> 2024-08-29 10:13:54,604 - IP REDACTED - ERROR<br>
> [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:144] - resource/audience ID Unable to obtain Profile Action InitializeRelyingPartyContext:<br>
> 2024-08-29 10:13:54,605 - IP REDACTED - WARN<br>
> [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event<br>
> occurred while processing the request: I*nvalidMessageContext*<br>
> 2024-08-29 10:13:54,606 -IP REDACTED - INFO<br>
> [Shibboleth-Audit.OIDC.Token:338] -<br>
> 54.86.50.139|2024-08-29T00:13:54.582866Z|2024-08-29T00:13:54.606339Z|https://REDACTED.csu.edu.au/oidc|https://archibusqaupgrade.csu.edu.au/oidc|||2024-08-29T00:13:54.603402Z||https://REDACTED.csu.edu.au/oidc||false|||TokenRequest|TokenErrorResponse|||||PostmanRuntime/7.41.2<br>
><br>
> I've added<br>
> <ref bean="OAUTH2.Token" /><br>
> <ref bean="OAUTH2.TokenAudience" /><br>
> to the DefaultRelyingParty and my RelyingPartyOverrides but not to the<br>
> UnverifiedRelyingParty<br>
><br>
> The SP information is held in metadata<br>
> <oidcmd:OAuthRPExtensions<br>
> grant_types="client_credentials"<br>
> response_types="code token id_token"<br>
> token_endpoint_auth_method="client_secret_post"<br>
> scopes="openid profile" /><br>
> </md:Extensions><br>
><br>
><br>
> Any help on troubleshooting would be greatly appreciated<br>
><br>
> regards<br>
><br>
> Gary<br>
><br>
> *Gary Lipscomb*<br>
><br>
> Technical Officer, Systems<br>
><br>
> IT Infrastructure & Security | Division of Information Technology<br>
><br>
> Charles Sturt University, Bathurst, NSW 2795<br>
><br>
> Charles Sturt University<br>
><br>
> Charles Sturt <<a href="https://www.csu.edu.au/" id="OWA8a0d4c24-7604-efc2-f91c-f7340718d863" class="x_OWAAutoLink" data-auth="NotApplicable">https://www.csu.edu.au</a>><br>
><br>
> ------------------------------------------------------------------------<br>
><br>
> LEGAL NOTICE<br>
><br>
> This email (including correspondence comprising an email chain and any<br>
> attachment) is confidential and is intended for the use of the<br>
> addressee(s) only. If you are not the intended recipient of this email,<br>
> you must not copy, distribute, take any action in reliance on it or<br>
> disclose it to anyone.<br>
> Any confidentiality is not waived or lost by reason of mistaken<br>
> delivery. Any email should be checked for viruses and defects before<br>
> opening. Charles Sturt University does not accept liability for viruses<br>
> or any consequence which arise as a result of this email transmission.<br>
> Email communications with Charles Sturt University may be subject to<br>
> automated email filtering, which could result in the delay or deletion<br>
> of a legitimate email before it is read at Charles Sturt University. The<br>
> views expressed in this email are not necessarily those of Charles Sturt<br>
> University.<br>
><br>
> Charles Sturt University in Australia <<a href="https://www.csu.edu.au/" id="OWAc488e348-08e2-fb0b-0d40-2f980966c010" class="x_OWAAutoLink" data-auth="NotApplicable">https://www.csu.edu.au</a>> The<br>
> Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN:<br>
> 83 878 708 551). Charles Sturt University - TEQSA Provider<br>
> Identification: PRV12018 (Australian University). CRICOS Provider: 00005F.<br>
><br>
> Consider the environment before printing this email.<br>
><br>
><br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" id="OWA742f3725-6694-f030-8ef2-e0849cb6c740" class="x_OWAAutoLink" shash="iJiCc3vjviJvD+lMYdWneFgg9rittMWYRfJo4v38zEbyMjfLy9LHzqqgesSmNuudUmmdPkS8e3QH4HEyTBox+xqlcbEJOJfn5t/wNmFGH5y0RKD7y2HmDWbRjg80VkuSfEL8cQCgCWduEbES06fr/vM2F5BKx4o4a40Ah1R/a74=" originalsrc="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" data-auth="Verified">
https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cglipscomb%40csu.edu.au%7C960ba6ad52b74834f9cc08dcc7f6300b%7Cf0f76207a6104fc0b4a35d797fe5283c%7C0%7C0%7C638605107406807641%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=paFZnahXEWV7cZjtyegxbxirGgMjMoR4B%2FYaavDJ5hs%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
<p style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<a href="https://www.csu.edu.au/" id="OWAe4fccc56-a6bd-780b-068c-e56c3c24bc9e" class="OWAAutoLink" data-auth="NotApplicable" style="text-decoration: none; margin-top: 0px; margin-bottom: 0px;"><img alt="Charles Sturt" height="60" style="height: 60px; margin-top: 0px; margin-bottom: 0px; padding: 10px;" src="https://www.csu.edu.au/email/images/charles-sturt-logo/charles-sturt-university-logo.png"></a></p>
<hr style="direction: ltr;">
<p style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<b>LEGAL NOTICE</b></p>
<p style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
This email (including correspondence comprising an email chain and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance
on it or disclose it to anyone.<br>
Any confidentiality is not waived or lost by reason of mistaken delivery. Any email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email
transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email
are not necessarily those of Charles Sturt University.</p>
<p style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
<span style="color: rgb(218, 61, 15);"><a href="https://www.csu.edu.au/" id="OWAa957b50a-1dd0-a909-6ce4-191170eec1ba" class="OWAAutoLink" data-auth="NotApplicable" style="color: rgb(218, 61, 15); margin-top: 0px; margin-bottom: 0px;">Charles Sturt University
in Australia</a></span> The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551). Charles Sturt University - TEQSA Provider Identification: PRV12018 (Australian University). CRICOS Provider: 00005F.</p>
<p style="direction: ltr; margin-top: 0px; margin-bottom: 0px; font-family: arial, helvetica, sans-serif; font-size: 9px;">
Consider the environment before printing this email.</p>
</body>
</html>