Shibboleth SP support for OpenID implementation

Cantor, Scott cantor.2 at osu.edu
Fri Feb 10 21:11:22 GMT 2012


> 5) It would be great if login could enable the generation of both a SAML
> session, and an OpenID connect session. But this will probably never be a
> feature of Shibboleth. The Trust Models are quite different.

Neither spec set includes a trust model at all, and implementing OpenID without one is, well, a toy. There's nothing fundamentally different about them, which is not surprising since Connect couldn't copy SAML more if it called itself SAML 3.0.

The scope of work is very large to implement it, but in terms of conceptual fit, it's nothing very different now. Which is why there's plenty of complaining going on about its complexity vs. the original.

> With that said, I thinkg OpenID Connect 1.0 will be a big improvement. It
> allows user to login with their email address, which was one of the big
> usability problems with the previous version of OpenID (i.e. no one could
> remember their OpenID URI).

Wonder which IdPs will benefit from that feature.

-- Scott



More information about the dev mailing list