Skip to content

Multiple Providers MetaDataURL validation #1170

Answered by zandbelt
OlivierBOEL asked this question in Q&A
Discussion options

You must be logged in to vote

not really: it would break OpenID Connect certification conformance; it is really the provider that is at fault here, it does not conform to the OpenID Connect Discovery spec and should be fixed; moreover, rather than using the wrong issuer, arguably it publishes the metadata at the wrong endpoint; the workaround is quite suitable here, it does not make any difference after the initial retrieval; also, I will consider removing support for OIDCValidateIssuer Off in the future as the time that mod_auth_openidc needs to adapt to broken providers is history by now

Replies: 2 comments 8 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
8 replies
@OlivierBOEL
Comment options

@zandbelt
Comment options

@OlivierBOEL
Comment options

@zandbelt
Comment options

Answer selected by OlivierBOEL
@OlivierBOEL
Comment options

@OlivierBOEL
Comment options

@zandbelt
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants