Configure external JWT signers and authentication policies for the first time, add services to access HTTP web applications, associate/update identities with authorization policies, all passed, and finally prompt 'now go to': And see your brozac!, The login page for Auth0 is displayed. I used my registered Google email and obtained my identity. I logged in using Google to display a blank page and seemed to be constantly refreshing requests. I realized something was wrong and checked the controller,route, console, which displayed running. Then, I logged in to the controller and displayed Token,but Configure external JWT signers and authentication policies show error
ubuntu@ip-172-31-8-243:~$ ziti edge login -u $ZITI_USER -p $ZITI_PWD -y ${ZITI_CTRL_EDGE_ADVERTISED_ADDRESS}:${ZITI_CTRL_EDGE_ADVERTISED_PORT}
Token: ac921eb6-8ad7-41c9-801c-7aa5bc9c33f5
Saving identity 'default' to /home/ubuntu/.config/ziti/ziti-cli.json
ubuntu@ip-172-31-8-243:~$ echo "configuring OpenZiti for BrowZer..."
issuer=$(curl -s ${ZITI_BROWZER_OIDC_URL}/.well-known/openid-configuration | jq -r .issuer)
jwks=$(curl -s ${ZITI_BROWZER_OIDC_URL}/.well-known/openid-configuration | jq -r .jwks_uri)
echo "OIDC issuer : $issuer"
echo "OIDC jwks url : $jwks"
ext_jwt_signer=$(ziti edge create ext-jwt-signer "${ziti_object_prefix}-ext-jwt-signer" "${issuer}" --jwks-endpoint "${jwks}" --audience "${ZITI_BROWZER_CLIENT_ID}" --claims-property email)
echo "ext jwt signer id: $ext_jwt_signer"
auth_policy=$(ziti edge create auth-policy "${ziti_object_prefix}-auth-policy" --primary-ext-jwt-allowed --primary-ext-jwt-allowed-signers ${ext_jwt_signer})
echo "auth policy id: $auth_policy"
configuring OpenZiti for BrowZer...
OIDC issuer :
OIDC jwks url :
error: COULD_NOT_VALIDATE - The supplied request contains an invalid document or no valid accept content were available, see cause: INVALID_FIELD - name [browzer-auth0-ext-jwt-signer] duplicate value 'browzer-auth0-ext-jwt-signer' in unique index on externalJwtSigners store
ext jwt signer id:
Error: flag needs an argument: --primary-ext-jwt-allowed-signers
ziti edge create auth-policy [flags]
flag needs an argument: --primary-ext-jwt-allowed-signers
auth policy id: