-
Notifications
You must be signed in to change notification settings - Fork 14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Demo of external issuer #11
Comments
What is an I would suggest renaming As a side note:
AWS updated documentation that probable after issue were filed. Sif you put JWKS and openiid-connect to S3 bucket you don't need to deal with thumbrints. |
Basically it just means picking some URL unrelated to the Jenkins controller, hosting two static files there (the OIDC well-known metadata and the JWKS), and configuring the issuer in the Jenkins credentials entry to point to this external URL rather than the Jenkins root URL. It sounds simple but the server need to have a proper TLS certificate and the relying party may be finicky about |
Thank you for the clarification @jglick
I know how complicated it is :) especially regarding content type which is not a part of the spec but many enforce its validation (for multiple reasons). |
https://www.acorn.io/pricing might work well enough for demo purposes. |
Recheck after #26. |
Never managed to adjust the AWS demo to use an external issuer because neither GCS nor GitHub Pages worked (#8 (comment)), so we need a different free hosting site with TLS and support for
Content-Type
. render.com looks promising.The text was updated successfully, but these errors were encountered: