is OpenID Connect on the roadmap?

Michael Schwartz mike at gluu.org
Thu Nov 1 12:31:16 EDT 2012


Thanks Nicole for the info!

In response to Scott Cantor's comments :)

This is why I didn't want to comment... I hate adding fuel to a long 
burning thread...  I'll address a few things and try to be quiet:

1) Large IDPs now realize they are not alone. Even if you are Google, you 
realize your customers may prefer a Microsoft or Yahoo account for 
authentication.  The OpenID Connect discovery mechanism is based on DNS 
domain names, using a "webfinger-like" mechanism ("SWD - Simple Web 
Discovery"). If you are "cantor.2 at osu.edu" I would query "osu.edu" to 
figure out how to validate a token or send you for authentication. That's 
not a bad solution, and its pretty fair to any kind of organization--not 
just the big IDPs (DOWN WITH FACEBOOK!!!... oops , did I say that 
online... nevermind...)

2) Regarding all things assertions, XML, and signing... listen to Scott! 
But the core message was that we are one relatively mature IETF RFC away 
from OpenID Connect going final.

3) Eve Maler had a slightly different assessment of Eran's decision to 
leave. I don't think its black and white: 
http://blogs.forrester.com/eve_maler/12-08-08-identity_protocol_gut_check
I don't know Eran personally, so I can't comment other than to say I think 
its a really tragic result, that I can't fully understand.

thx,

Mike


More information about the dev mailing list