[Ext] openid plugin and attributes
Paul Hethmon
paul.hethmon at clareitysecurity.com
Tue May 3 18:47:52 EDT 2016
The problem is that the front channel browser talks to one node with the info but the RP will make a direct connection itself which could go to any node.
I don't think it's possible to support OIDC in a cluster without session sharing. Its inherent in the protocol.
Paul
(Please enjoy the autocorrect features if this phone)
On May 3, 2016, at 6:34 PM, Nate Klingenstein <nate.klingenstein at utah.edu<mailto:nate.klingenstein at utah.edu>> wrote:
I’m piggy backing on my v2 db storage service. I have extended it to have direct support for storing OIDC sessions. With the direct back channel model of OIDC, I just didn’t see a way to support it without clustering the sessions.
Have you spent any time looking at serialization methods that would associate the OAuth token with the issuing node, limiting the need for storing sessions in a database? Is there any potential there, or is it just an idea not worth pursuing?
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net<mailto:dev-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160503/10f037e1/attachment.html>
More information about the dev
mailing list