Experience with OIDC plugin

Janne Lauros janne.lauros at csc.fi
Sat Nov 17 11:51:47 EST 2018


 The extension does not use entityID as issuer. It uses value set with property 'idp.oidc.issuer'. I hope that helps.

 BR Janne 

----- Original Message -----
From: "Tom Scavo" <trscavo at gmail.com>
To: "dev" <dev at shibboleth.net>
Sent: Saturday, 17 November, 2018 18:04:58
Subject: Re: Experience with OIDC plugin

On Sat, Nov 17, 2018 at 10:52 AM Janne Lauros <janne.lauros at csc.fi> wrote:
>
>  The extension does not validate the issuer value against any schema. Maybe it should. Not following the specification on the issuer value will lead to problems latest at when applying discovery specification, https://openid.net/specs/openid-connect-discovery-1_0.html. There the issuer value is used to resolve the location of the openid configuration,.

We've spent years helping deployers understand that the entityID is a
name, not a location. It would be a shame to reverse that trend now.

Perhaps the 'iss' claim could be derived from the endpoint locations?
Just a thought...

Tom
-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list