is OpenID Connect on the roadmap?
Michael Schwartz
mike at gluu.org
Thu Nov 1 12:31:16 EDT 2012
Thanks Nicole for the info!
In response to Scott Cantor's comments :)
This is why I didn't want to comment... I hate adding fuel to a long
burning thread... I'll address a few things and try to be quiet:
1) Large IDPs now realize they are not alone. Even if you are Google, you
realize your customers may prefer a Microsoft or Yahoo account for
authentication. The OpenID Connect discovery mechanism is based on DNS
domain names, using a "webfinger-like" mechanism ("SWD - Simple Web
Discovery"). If you are "cantor.2 at osu.edu" I would query "osu.edu" to
figure out how to validate a token or send you for authentication. That's
not a bad solution, and its pretty fair to any kind of organization--not
just the big IDPs (DOWN WITH FACEBOOK!!!... oops , did I say that
online... nevermind...)
2) Regarding all things assertions, XML, and signing... listen to Scott!
But the core message was that we are one relatively mature IETF RFC away
from OpenID Connect going final.
3) Eve Maler had a slightly different assessment of Eran's decision to
leave. I don't think its black and white:
http://blogs.forrester.com/eve_maler/12-08-08-identity_protocol_gut_check
I don't know Eran personally, so I can't comment other than to say I think
its a really tragic result, that I can't fully understand.
thx,
Mike
More information about the dev
mailing list