Currently the lightweight issuer responds at
- https://SCITOKENS_SERVER_ADDRESS/scitokens-server/.well-known/openid-configuration
- https://SCITOKENS_SERVER_ADDRESS/scitokens-server/.well-known/oauth-authorization-server
but not
- https://SCITOKENS_SERVER_ADDRESS/.well-known/openid-configuration/scitokens-server
- https://SCITOKENS_SERVER_ADDRESS/.well-known/oauth-authorization-server/scitokens-server
even though the latter is preferred according to https://datatracker.ietf.org/doc/html/rfc8414#section-5 .
@terrencegf knows the Tomcat configuration magic to add a rewrite rule for the latter URLs.