You’re right, I configured the username scoped directly in the XDMoD client in some configuration attempts. I just removed this.
[ {
"id" : "08d22822-b1c7-4005-b23c-6748e17c263a",
"clientId" : "xdmod.exacta.eu.org",
"name" : "Open XDMoD",
"rootUrl" : "",
"adminUrl" : "",
"surrogateAuthRequired" : false,
"enabled" : true,
"alwaysDisplayInConsole" : false,
"clientAuthenticatorType" : "client-secret",
"redirectUris" : [ "https://xdmod.exacta.eu.org/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp" ],
"webOrigins" : [ "https://xdmod.exacta.eu.org" ],
"notBefore" : 0,
"bearerOnly" : false,
"consentRequired" : false,
"standardFlowEnabled" : true,
"implicitFlowEnabled" : false,
"directAccessGrantsEnabled" : false,
"serviceAccountsEnabled" : false,
"publicClient" : false,
"frontchannelLogout" : true,
"protocol" : "saml",
"attributes" : {
"saml.multivalued.roles" : "false",
"saml.force.post.binding" : "true",
"frontchannel.logout.session.required" : "false",
"oauth2.device.authorization.grant.enabled" : "false",
"backchannel.logout.revoke.offline.tokens" : "false",
"saml.server.signature.keyinfo.ext" : "false",
"use.refresh.tokens" : "true",
"saml.signing.certificate" : "MIICpTCCAkugAwIBAgIUE8EgGPP5OJoBKk14BSpUx5AnW/0wCgYIKoZIzj0EAwIwgZIxCzAJBgNVBAYTAkJSMRcwFQYDVQQIEw5SaW8gZGUgSmFuZWlybzEXMBUGA1UEBxMOUmlvIGRlIEphbmVpcm8xFDASBgNVBAoTC0NsdXN0ZXIgSFBDMQswCQYDVQQLEwJDQTEuMCwGA1UEAxMlQ2xvdWRmbGFyZSBSb290IENlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjA4MDgwNDA3MDBaFw0zMjA4MDUwNDA3MDBaMH4xCzAJBgNVBAYTAkJSMRcwFQYDVQQIEw5SaW8gZGUgSmFuZWlybzEXMBUGA1UEBxMOUmlvIGRlIEphbmVpcm8xFDASBgNVBAoTC0NsdXN0ZXIgSFBDMRcwFQYDVQQLEw5DbG91ZGZsYXJlIFNTTDEOMAwGA1UEAxMFY2Zzc2wwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQU/GNl15NedHjk6e3T+ExnVVPo9bRBq05q7FQKxNPSVbiwC6PZijc0zI0tvovGYfFE0w3v1J8fgpmMsijzSTmmo4GRMIGOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUjQtfxjAWtz0ngXV4sIYJtQuVebEwHwYDVR0jBBgwFoAUEmgNfBT64HbI20iDALzZsXyTAqcwDwYDVR0RBAgwBocEfwAAATAKBggqhkjOPQQDAgNIADBFAiAK4akkV78dUN+2a+Zp+yBivumA/NxPULJ50f1kF5J6sQIhAJUvlx0IO6Tq+D4iSI+/uYy29CgQsg+yXwDEPcLJqtoC",
"oidc.ciba.grant.enabled" : "false",
"backchannel.logout.session.required" : "false",
"saml.signature.algorithm" : "RSA_SHA256",
"client_credentials.use_refresh_token" : "false",
"require.pushed.authorization.requests" : "false",
"saml.client.signature" : "false",
"saml.allow.ecp.flow" : "false",
"saml.assertion.signature" : "false",
"id.token.as.detached.signature" : "false",
"client.secret.creation.time" : "1667705384",
"saml.encrypt" : "true",
"saml_assertion_consumer_url_post" : "https://xdmod.exacta.eu.org/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp",
"saml.server.signature" : "true",
"exclude.session.state.from.auth.response" : "false",
"saml.artifact.binding.identifier" : "ZBVKrNNNSqJHVJm80zuYAOaKzJE=",
"saml_single_logout_service_url_redirect" : "https://xdmod.exacta.eu.org/simplesaml/module.php/saml/sp/saml2-logout.php/default-sp",
"saml.artifact.binding" : "false",
"saml_force_name_id_format" : "true",
"saml.encryption.certificate" : "MIICpTCCAkugAwIBAgIUE8EgGPP5OJoBKk14BSpUx5AnW/0wCgYIKoZIzj0EAwIwgZIxCzAJBgNVBAYTAkJSMRcwFQYDVQQIEw5SaW8gZGUgSmFuZWlybzEXMBUGA1UEBxMOUmlvIGRlIEphbmVpcm8xFDASBgNVBAoTC0NsdXN0ZXIgSFBDMQswCQYDVQQLEwJDQTEuMCwGA1UEAxMlQ2xvdWRmbGFyZSBSb290IENlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0yMjA4MDgwNDA3MDBaFw0zMjA4MDUwNDA3MDBaMH4xCzAJBgNVBAYTAkJSMRcwFQYDVQQIEw5SaW8gZGUgSmFuZWlybzEXMBUGA1UEBxMOUmlvIGRlIEphbmVpcm8xFDASBgNVBAoTC0NsdXN0ZXIgSFBDMRcwFQYDVQQLEw5DbG91ZGZsYXJlIFNTTDEOMAwGA1UEAxMFY2Zzc2wwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAQU/GNl15NedHjk6e3T+ExnVVPo9bRBq05q7FQKxNPSVbiwC6PZijc0zI0tvovGYfFE0w3v1J8fgpmMsijzSTmmo4GRMIGOMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUjQtfxjAWtz0ngXV4sIYJtQuVebEwHwYDVR0jBBgwFoAUEmgNfBT64HbI20iDALzZsXyTAqcwDwYDVR0RBAgwBocEfwAAATAKBggqhkjOPQQDAgNIADBFAiAK4akkV78dUN+2a+Zp+yBivumA/NxPULJ50f1kF5J6sQIhAJUvlx0IO6Tq+D4iSI+/uYy29CgQsg+yXwDEPcLJqtoC",
"tls.client.certificate.bound.access.tokens" : "false",
"acr.loa.map" : "{}",
"saml.authnstatement" : "true",
"display.on.consent.screen" : "false",
"saml_name_id_format" : "username",
"token.response.type.bearer.lower-case" : "false",
"saml_artifact_binding_url" : "https://xdmod.exacta.eu.org/simplesaml/module.php/saml/sp/saml2-acs.php/default-sp",
"saml_signature_canonicalization_method" : "http://www.w3.org/2001/10/xml-exc-c14n#",
"saml.onetimeuse.condition" : "false"
},
"authenticationFlowBindingOverrides" : { },
"fullScopeAllowed" : true,
"nodeReRegistrationTimeout" : -1,
"defaultClientScopes" : [ "osc-saml-clients", "role_list" ],
"optionalClientScopes" : [ ],
"access" : {
"view" : true,
"configure" : true,
"manage" : true
}
} ]
When I access xdmod url, after I create the /etc/xdmod/simplesamlphp/config/authsources.php
file page returns blank
Without the authsources.php file the page works, but not the login.