Impersonation details - New feature request

Cantor, Scott cantor.2 at osu.edu
Tue Oct 10 10:24:29 EDT 2017


> I've always pushed back on the idea of impersonation using SAML or
> OpenID Connect. Doesn't it undermine the integrity of the system if
> someone else can login as you?

There is nothing stopping anybody from configuring an IdP to do this today, it took me all of 8 hours work to create a relatively polished way to do it that took no system changes. What deployers choose to do or not do is a local policy question, I just want it done safely and not by mucking around with the authentication code. I think you're asking a deployment/trust/federation sort of question, it's not a software question.

> I think it's possible with a user-initiated UMA claims gathering flow.

Any solution involving the app is dead on arrival for most of the testing scenarios where this gets used. That's really a totally different use case.

Note that Kerberos has had impersonation for most of its life.
 
-- Scott



More information about the dev mailing list