By: Sergio Plasencia user 02 Dec 2015 at 9:44 a.m. CST

4 Responses
Sergio Plasencia gravatar
Hi, I have registered an OpenID client and everything works fine so far except logout. I get the following error: {"error":"invalid_grant","error_description":"The provided access token is invalid, or was issued to another client."} The client is using the mod_auth_openidc module. We have followed this doc: http://www.gluu.org/docs/articles/mod-auth-oidc/ubuntu-installation/ We are using the latest gluu 2.4 version. The client was registered dynamically and then we changed it to static config: <VirtualHost *:443> ServerName test.lab.com DocumentRoot /var/www OIDCRedirectURI https://test.lab.com/fake_redirect_uri OIDCCryptoPassphrase newsecret OIDCProviderMetadataURL https://test-gluu-0.virdata.com/.well-known/openid-configuration OIDCClientID @!DC26.BE76.0A9B.522A!0001!A55A.4B79!0008!A416.63D6 OIDCClientSecret 9f63047a-f6e1-4fe7-a967-b8091828789d OIDCResponseType id_token OIDCProviderTokenEndpointAuth client_secret_basic OIDCScope "openid" OIDCProviderIssuer https://test-gluu-0.virdata.com OIDCSSLValidateServer Off OIDCProviderEndSessionEndpoint https://test-gluu-0.virdata.com/oxauth/seam/resource/restv1/oxauth/end_session OIDCProviderCheckSessionIFrame https://test-gluu-0.virdata.com/oxauth/opiframe OIDCClientName CRM SetEnvIf Request_URI "/test/logout.html" accessgranted=1 <Location /> Order deny,allow Satisfy any Deny from all Allow from env=accessgranted AuthType openid-connect Require valid-user </Location> SSLEngine On SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key </VirtualHost> We tried many times, registering the client again and always we get the same error.

By Michael Schwartz Account Admin 02 Dec 2015 at 9:55 a.m. CST

Michael Schwartz gravatar
I think this is a bug. We have an update coming next week that should fix logout: 2.4.1

By Sergio Plasencia user 02 Dec 2015 at 9:59 a.m. CST

Sergio Plasencia gravatar
Cool! Thank you very much for your quick answer. Let's wait for the update

By Antanas Sakalauskas user 04 Mar 2016 at 3:42 a.m. CST

Antanas Sakalauskas gravatar
Dear Michael, We have upgraded Gluu to 2.4.1-1, but still logout does not work. The following should terminate session and redirect to google.com: https://gluu-server.com/fakeurl?logout=https%3A%2F%2Fwww.google.com But we are getting back {"error":"invalid_grant","error_description":"The provided access token is invalid, or was issued to another client."} from https://gluu-server.com/oxauth/seam/resource/restv1/oxauth/end_session The token id is being provided as you can see below: id_token_hint=eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsImtpZCI6IjBjNzJmZTJlLTA3NWQtNDk1Yi1hZDBiLTljYmY1YWFjZjA1YyJ9.eyJpc3MiOiJodHRwczovL2RldmVsb3BtZW50LWRldm9wcy1nbHV1LTAudmlyZGF0YS5jb20iLCJhdWQiOiJAIURDMjYuQkU3Ni4wQTlCLjUyMkEhMDAwMSFBNTVBLjRCNzkhMDAwOCFFMDdFLjlERDIiLCJleHAiOjE0NTcwODYwMzAsImlhdCI6MTQ1NzA4MjQzMCwibm9uY2UiOiJIOFluZkZ2V09ZNWNKWm50bWhWZ3Bwd1g1OXZGXzMxbkliaEI2WlhLOXFrIiwiYXV0aF90aW1lIjoxNDU3MDExNzcxLCJveFZhbGlkYXRpb25VUkkiOiJodHRwczovL2RldmVsb3BtZW50LWRldm9wcy1nbHV1LTAudmlyZGF0YS5jb20vb3hhdXRoL29waWZyYW1lIiwib3hPcGVuSURDb25uZWN0VmVyc2lvbiI6Im9wZW5pZGNvbm5lY3QtMS4wIiwiUGxhdGZvcm1JRCI6ImU3ZDYzYjhhLWVjZGYtODM4YS1jNGNjLTU1MzEwYTViZjkxOSIsInVzZXJfbmFtZSI6ImFudGFuYXMuc2FrYWxhdXNrYXNAdmlyZGF0YS5jb20iLCJHcm91cE1lbWJlcnNoaXAiOiJcIk1DTS9PcGVyYXRvclwiLFwiQ1JNX1BvcnRhbC9TdXBlclwiLFwiQ1JNL0NvbnN1bHRhbnRcIiIsIm1lbWJlck9mIjoiY249Q1JNL3Rlc3Q0LG91PUdyb3VwcyxkYz12aXJkYXRhLGRjPWNvbSIsImludW0iOiJAIURDMjYuQkU3Ni4wQTlCLjUyMkEhMDAwMSFBNTVBLjRCNzkhMDAwMCE5RUI2LkYyOTUiLCJzdWIiOiJjYmJjY2JjYy04ZGQ3LTRmMWYtYjk3Mi1hYWUyY2ViYjI5MjQifQ.dUkFY2hvV7o_5nlSTjw1xY-pqUBTrdR3lK-qyyqUJZ0m7mnpUUrEd7An_yxkMkkHXwrWZGISES5NimFiO5SMlb8TPKrtq3u0t9VAiBdy044mtwKdGdzHOR5YumEi3Y9a_yJjk2QBJfuOQLOk2O1AHYCAESrErpKcbo28oNWMkcJNNMAbCiVgSziSSbWrVNA2xsQ4uFzPTknj10_-mMx82rq3tjl2Dt23_rcSPMVfUB4gSZ-t_dM5ofSfV6M0rU70BIqp5rzSXpbp5JHOfQP4XSi3Gys4uvPs600pb4zbm9K8NGTFhmgazWtcBYQ0kfHuIO03fqZBb3iiZYN7n55eSw&post_logout_redirect_uri=http%3A%2F%2Fwww.google.com

By Theodore Sands user 07 Oct 2016 at 12:47 p.m. CDT

Theodore Sands gravatar
Make sure you have added the Redirect Logout URI in the client's registration.