Closed marcispauls closed 1 year ago
FYI we consider SSO generally out of bounds for community issues.
https://github.com/SecurityRiskAdvisors/VECTR/issues/146
I may have some time to look at this, Can you post the container logs for the tomcat container? Those usually are better for troubleshooting.
Ahh, didnt see that it has logs to stdout not to the files, figured out - idp sends wrong auth type as ES256 but its actually HS256 is it possible with params to change the alg that it uses only that and dont trust idp?
It's not possible to configure individual algorithms in community edition in that manner. Your "Well Known" IDP configuration as part of OIDC Discovery should be specifying the auth types.
ok, clear, tnx for support and hints. will deal with our idp team
Steps to reproduce the behavior:
Version: ce-8.8.1
Logs: