Impersonation details - New feature request

Mike Schwartz mike at gluu.org
Tue Oct 10 10:38:18 EDT 2017


Yes agreed... impersonation is a trust model / workflow challenge.

I think UMA does a nice job of handling the explicit consent.

- Mike


On 2017-10-10 09:24, Cantor, Scott wrote:
>> I've always pushed back on the idea of impersonation using SAML or
>> OpenID Connect. Doesn't it undermine the integrity of the system if
>> someone else can login as you?
> 
> There is nothing stopping anybody from configuring an IdP to do this
> today, it took me all of 8 hours work to create a relatively polished
> way to do it that took no system changes. What deployers choose to do
> or not do is a local policy question, I just want it done safely and
> not by mucking around with the authentication code. I think you're
> asking a deployment/trust/federation sort of question, it's not a
> software question.
> 
>> I think it's possible with a user-initiated UMA claims gathering flow.
> 
> Any solution involving the app is dead on arrival for most of the
> testing scenarios where this gets used. That's really a totally
> different use case.
> 
> Note that Kerberos has had impersonation for most of its life.
> 
> -- Scott


More information about the dev mailing list