GEANT OIDC plugin

Janne Lauros janne.lauros at csc.fi
Mon Sep 10 02:38:52 EDT 2018


Hi!


>> What about user identifiers?

 Subject is generated by the same mechanisms as SAML2 nameid is generated with. The configuration is of course separate from SAML2 but the principle is the same.
 
 https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/SubjectIDConfiguration

 BR Janne

----- Original Message -----
From: "Tom Scavo" <trscavo at gmail.com>
To: "dev" <dev at shibboleth.net>
Sent: Saturday, 8 September, 2018 23:19:54
Subject: Re: GEANT OIDC plugin

On Fri, Sep 7, 2018 at 5:56 PM Jim Fox <fox at washington.edu> wrote:
>
> >
> > Suppose I log into a SAML SP and then later log into an OIDC RP, both
> > with your IdP. Is there single sign-on between the two protocols?
> >
>
> Yes, it runs through the Password flow.

Okay, great, so the protocols share the same session.

What about user identifiers? Does your IdP support a long-lived,
non-reassigned identifier for SAML? Were you able to re-use that
identifier for the OIDC 'sub' claim?

Thanks Jim.

Tom
-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list