Shibboleth.net discovery interface

Cantor, Scott cantor.2 at osu.edu
Mon Jan 6 13:02:40 EST 2014


On 1/6/14, 12:54 PM, "Michael Schwartz" <mike at gluu.org> wrote:

>Probably a dumb idea, but why not OFFER OpenID Connect Discovery also:
>  http://openid.net/specs/openid-connect-discovery-1_0.html

To the extent that it's based on discovery by e-mail address, the reasons
why that's inherently evil are pretty well known. That's just a Google
trojan horse.

There isn't anything I know of to ask a user to enter that's
understandable and compatible with a non-monopolist identity solution.
Once something exists, I'm happy to discuss it, but I have no idea what it
would be, which is why I haven't proposed anything.

-- Scott




More information about the dev mailing list