openid plugin and attributes

Martin Haase Martin.Haase at DAASI.de
Mon May 2 12:12:18 EDT 2016


Hi Paul,
are you open-sourceing your code in the near future? We might be
interested in doing some analysis, along with the UChicago one.
Thanks,
Martin

Am 02.03.2016 um 22:50 schrieb Paul Hethmon:
> I’m close to finishing up my OpenID Connect plug-in for Shib and have some choices relating to releasing attributes. My philosophy has been to maintain minimal configuration for OpenID, instead pulling what I can from the Shib configuration. So one thought on managing attribute release is to represent each OIDC RP as a SAML RP. So from a configuration viewpoint, you would add a metadata file for each OIDC RP and configure attribute release as normal. The OIDC plugin would request authentication as that SAML RP when it received the corresponding OIDC authentication request. The win would be the Shib attribute engine controlling the attribute release. The loss would be maintaining a fake/proxy metadata file for each OIDC RP.
>
> Thoughts? Am I going to far down this path of relying on Shib configuration?
>
> thanks,
>
> Paul
>
> -----
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com
>
>

-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-6
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz



More information about the dev mailing list