oidc extension design question - oidc relying party

Greg Haverkamp gahaverkamp at lbl.gov
Fri Dec 15 01:25:49 EST 2017


On Thu, Dec 14, 2017 at 6:46 AM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > Until now we have used in shib oidc extension saml2 entity id value also
> as
> > oidc issuer value. That is a shortcut that will not work for all
> deployments,
> > specially if you are not creating a new deployment having possiblity to
> > choose the entity id to match oidc issuer value.
>
> I imagine that might happen but is it likely to be common? We already
> allow overriding of the entityID, particularly if it's a static sort of
> override to a fixed value, so I'm not sure this is a big problem really.


Anyone using one of the urn:mace:incommon entity IDs will have to
override.  How common it is probably comes down to how common non-
https://hostname conventions are for IdPs.  Probably uncommon beyond that,
given the limited OIDC usage at present.

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20171215/a1b1687b/attachment.html>


More information about the dev mailing list