openid plugin and attributes
Paul Hethmon
paul.hethmon at clareitysecurity.com
Wed Mar 2 16:50:05 EST 2016
I’m close to finishing up my OpenID Connect plug-in for Shib and have some choices relating to releasing attributes. My philosophy has been to maintain minimal configuration for OpenID, instead pulling what I can from the Shib configuration. So one thought on managing attribute release is to represent each OIDC RP as a SAML RP. So from a configuration viewpoint, you would add a metadata file for each OIDC RP and configure attribute release as normal. The OIDC plugin would request authentication as that SAML RP when it received the corresponding OIDC authentication request. The win would be the Shib attribute engine controlling the attribute release. The loss would be maintaining a fake/proxy metadata file for each OIDC RP.
Thoughts? Am I going to far down this path of relying on Shib configuration?
thanks,
Paul
-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com
More information about the dev
mailing list