GEANT OIDC plugin

Janne Lauros janne.lauros at csc.fi
Mon Sep 10 02:27:12 EDT 2018


Hi Jim,

>>It's a bit involved, partly because it requires shib vers 3.4, which I didn't have. So I had to install a 3.4 idp.
>>They also use jetty, which we don't.  So I had to install jetty.

 Our last release from June tagged as v0.7.0a is based on 3.3 IdP, it is only the head that requires 3.4. About the ansible, we are using now ansible for installation but that is mainly for development purposes. The target is to have something much simpler in the next release that is based on 3.4. Something you can unpack over existing installation.

>> As far as I can tell it only supports implicit flow.  At least that's all my instance supports.

 All response types are supported. Having only implicit flow may be result of misconfiguration or missing something in the installation like token and userinfo endpoints.

 Br Janne  

----- Original Message -----
From: "Jim Fox" <fox at washington.edu>
To: "dev" <dev at shibboleth.net>
Sent: Saturday, 8 September, 2018 00:33:22
Subject: GEANT OIDC plugin

I had some time and installed the latest geant oidc plugin (https://github.com/CSCfi/shibboleth-idp-oidc-extension) 
on one of our test idps, using our kerberos authn and our real attribute resolvers.

It's a bit involved, partly because it requires shib vers 3.4, which I didn't have. So I had to install a 3.4 idp.
They also use jetty, which we don't.  So I had to install jetty.

However, after all that, it wasn't overly difficult.  They install with ansible, and one of their 
scripts mostly installed the extension on our test system.   After that there's a few additions to 
the relying-party, attribute-resolver and attribute filter configs.

As far as I can tell it only supports implicit flow.  At least that's all my instance supports.

I'd like to send them some comments on my experience.  Does any know a mailing list they work with?

Thanks,

Jim

-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list