Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

private_key_jwt is not available in mod_auth_openidc 2.4.4.1 #881

Answered by zandbelt
tpimh asked this question in Q&A
Discussion options

After setting OIDCProviderTokenEndpointAuth to private_key_jwt, apache2 fails to start with this message:

Invalid value for directive 'OIDCProviderTokenEndpointAuth': invalid value 'private_key_jwt', must be one of ['client_secret_post'|'client_secret_basic'|'client_secret_jwt'|'none'|'bearer_access_token']

Is this not supported with version 2.4.4.1 (currently the latest version in alpine repo)?

You must be logged in to vote

it is supported but to be able to use private_key_jwt you'll also need to set OIDCPrivateKeyFiles and OIDCPublicKeyFiles as noted here https://github.com/zmartzone/mod_auth_openidc/blob/v2.4.4.1/auth_openidc.conf#L337

Replies: 1 comment 3 replies

Comment options

it is supported but to be able to use private_key_jwt you'll also need to set OIDCPrivateKeyFiles and OIDCPublicKeyFiles as noted here https://github.com/zmartzone/mod_auth_openidc/blob/v2.4.4.1/auth_openidc.conf#L337

You must be logged in to vote
3 replies
Comment options

Thanks! I didn't realize the order of the directives was important, so was setting the keys right after OIDCProviderTokenEndpointAuth private_key_jwt.

Comment options

thanks, I did not realize either that order was important indeed

Comment options

This also tripped me up. I think it would be helpful to put OIDCProviderTokenEndpointAuth after OIDCPublic/PrivateKeyFiles in the default config.

Answer selected by tpimh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet

AltStyle によって変換されたページ (->オリジナル) /