OpenID Client Auth Secret

6 views
Skip to first unread message

cklin...@gmail.com

unread,
Dec 24, 2025, 11:38:18 AM (24 hours ago) Dec 24
to RCDevs Security
In trying to setup OAUTH to  WebADM, my client device requires a "Client Secret" to be established between Device and Server. 

I cant seem to find anywhere in the client config, or App config for OpenID to establish this secret. Where can I enter a secret password for each client that uses OpenID?

Error:
[2025-12-24 11:27:53] [192.168.1.100:15532] [OpenID:3G7QEVS1] Invalid OpenID secret for client 'TestClient-OAUTH'

Spyridon Gouliarmis (RCDevs)

unread,
Dec 24, 2025, 11:44:13 AM (24 hours ago) Dec 24
to RCDevs Security
That's done in a Client Policy (Admin tab). When configuring the policy, -> Application Settings -> OpenID -> set at least Aliases and Client Secret, so that, respectively, WebADM/OpenID knows to apply this particular policy when it receives a request from that particular client, and knows what client secret to use for the JWT.

cklin...@gmail.com

unread,
Dec 24, 2025, 11:55:43 AM (23 hours ago) Dec 24
to RCDevs Security
I can see there is a section for ALIAS, but there is no "client secret" section. I tried going to the App settings within the client and I didnt see an OpenID section, just the usual stuff you can do like force OTP and other items specific to that client. 

Spyridon Gouliarmis (RCDevs)

unread,
Dec 24, 2025, 11:58:14 AM (23 hours ago) Dec 24
to RCDevs Security
In you Client Policy, clicking Edit next to the textbox for Application Settings should show the right page. You'll see OpenID in the small boxed list to the left, select it and Client Secret will appear near the bottom of the page. OpenID appears there only if you Register'd it in the Applications tab.
Screenshot 2025-12-24 at 17.54.26.png

cklin...@gmail.com

unread,
Dec 24, 2025, 12:45:11 PM (23 hours ago) Dec 24
to RCDevs Security
Confirmed.....I have Man eyes..... Ty very much!
Reply all
Reply to author
Forward
0 new messages