Can you configure pinniped (on VKS) with F5 OIDC? #2599
-
|
Hi, we have a vSphere Kubernetes Supervisor (vSphere 8.0.3) on which we are trying to set up the use of an external identity provider. We tried running curl -ILkv https://auth-adm.lab.domain.com/f5-oauth2/v1/jwks from several places, including the supervisor nodes, and we don't see any redirects happening, and it gives us an application/json content type back, which seems to be correct We also tried setting up Okta as an external identity provider, and that one works fine. It seems to be an issue related to F5. Has anyone been able to configure an F5 as an external identity provider in VKS? Or does anyone know how we can further troubleshoot what goes wrong? Many thanks! |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
|
You are using the wrong issuer URL. The URL that you used is the issuer's JWKS endpoint, not the issuer's URL. For an OIDC issuer URL, you should be able to append |
Beta Was this translation helpful? Give feedback.
-
|
Correct! In the meantime we figured it out with the networking team. The URL was incorrectly setup on the F5 side indeed and they made the necessary adjustments. Everything is working fine now. |
Beta Was this translation helpful? Give feedback.
You are using the wrong issuer URL. The URL that you used is the issuer's JWKS endpoint, not the issuer's URL. For an OIDC issuer URL, you should be able to append
/.well-known/openid-configurationto the end of the URL and then curl that. For example,https://accounts.google.comis an OIDC issuer, and you can curlhttps://accounts.google.com/.well-known/openid-configurationto get its discovery response.