openid plugin and attributes
Martin Haase
Martin.Haase at DAASI.de
Mon May 2 12:12:18 EDT 2016
Hi Paul,
are you open-sourceing your code in the near future? We might be
interested in doing some analysis, along with the UChicago one.
Thanks,
Martin
Am 02.03.2016 um 22:50 schrieb Paul Hethmon:
> I’m close to finishing up my OpenID Connect plug-in for Shib and have some choices relating to releasing attributes. My philosophy has been to maintain minimal configuration for OpenID, instead pulling what I can from the Shib configuration. So one thought on managing attribute release is to represent each OIDC RP as a SAML RP. So from a configuration viewpoint, you would add a metadata file for each OIDC RP and configure attribute release as normal. The OIDC plugin would request authentication as that SAML RP when it received the corresponding OIDC authentication request. The win would be the Shib attribute engine controlling the attribute release. The loss would be maintaining a fake/proxy metadata file for each OIDC RP.
>
> Thoughts? Am I going to far down this path of relying on Shib configuration?
>
> thanks,
>
> Paul
>
> -----
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com
>
>
--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-6
fax: +49 7071 407109-9
email: martin.haase at daasi.de
web: www.daasi.de
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
More information about the dev
mailing list