Skip to content

add config option to define a OIDC JWKS URL - #1106

Open
SilPan wants to merge 1 commit into
dfir-iris:masterfrom
SilPan:oidc-add-option-for-jwks-url
Open

add config option to define a OIDC JWKS URL#1106
SilPan wants to merge 1 commit into
dfir-iris:masterfrom
SilPan:oidc-add-option-for-jwks-url

Conversation

@SilPan

@SilPan SilPan commented Aug 5, 2026

Copy link
Copy Markdown

I had lots of trouble getting OIDC running, with my organizations IDP: NetScaler with a weird configuration.

IRIS' OIDC implementation works like the following source/app/iris_engine/access_control/oidc_handler.py:oidc_handler() tries to get the OIDC config via "OIDC_ISSUER_URL"/.well-known/openid-configuration, if this fails [1] it will consult the configuration values for each of the URLs.
This is a perfectly sane and good implementation.

Now because of the weird configuration of our IDP I had to set all the URLs manually.
Going down the exception handling branch - which may be not commonly used.

Doing so I kept being hit with a jwkest.jws.NoSuitableSigningKeys Exception.
For some reason, the whole flow worked, until IRIS tried to validate that the token came from the actual IDP.
It turned out that IRIS had 0 signing keys it compared with - so of course no key matched.

After lots of debugging I figured out that passing a jwks_uri to the ProviderConfigurationResponse in source/app/iris_engine/access_control/oidc_handler.py:oidc_handler() solved this.

Thus I made a PR that introduces this configuration value.

[1] e.g. because my genius sysadmins have the discovery document at https://access.company.tld/oauth/idp/.well-known/openid-configuration (note the /oauth/idp/ path) but the issuer still being https://access.company.tld/ instead of respective https://access.company.tld/oauth/idp/.

This can be usefull if the OIDC configuration discovery fails.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant