openid plugin and attributes

Walter Forbes Hoehn (wassa) wassa at memphis.edu
Wed Mar 2 17:29:09 EST 2016


In what sense would the metadata be fake?

-WFH


> On Mar 2, 2016, at 4:22 PM, Misagh Moayyed <mmoayyed at unicon.net> wrote:
> 
> I would say so, yes. Ideally, you want the former and not the latter. You want shib to resolve/release attributes, without having to maintain fake metadata. 
> 
> -- 
> Misagh
> 
> From: Paul Hethmon <paul.hethmon at clareitysecurity.com>
> Reply: Shib Dev <dev at shibboleth.net>
> Date: March 2, 2016 at 11:50:37 PM
> To: Shibboleth Dev <dev at shibboleth.net>
> Subject:  openid plugin and attributes 
> 
>> I’m close to finishing up my OpenID Connect plug-in for Shib and have some choices relating to releasing attributes. My philosophy has been to maintain minimal configuration for OpenID, instead pulling what I can from the Shib configuration. So one thought on managing attribute release is to represent each OIDC RP as a SAML RP. So from a configuration viewpoint, you would add a metadata file for each OIDC RP and configure attribute release as normal. The OIDC plugin would request authentication as that SAML RP when it received the corresponding OIDC authentication request. The win would be the Shib attribute engine controlling the attribute release. The loss would be maintaining a fake/proxy metadata file for each OIDC RP. 
>> 
>> Thoughts? Am I going to far down this path of relying on Shib configuration? 
>> 
>> thanks, 
>> 
>> Paul 
>> 
>> ----- 
>> Paul Hethmon 
>> Chief Software Architect 
>> paul.hethmon at clareitysecurity.com 
>> 
>> 
>> -- 
>> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
> -- 
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net



More information about the dev mailing list