GEANT OIDC plugin
Janne Lauros
janne.lauros at csc.fi
Mon Sep 10 02:38:52 EDT 2018
Hi!
>> What about user identifiers?
Subject is generated by the same mechanisms as SAML2 nameid is generated with. The configuration is of course separate from SAML2 but the principle is the same.
https://github.com/CSCfi/shibboleth-idp-oidc-extension/wiki/SubjectIDConfiguration
BR Janne
----- Original Message -----
From: "Tom Scavo" <trscavo at gmail.com>
To: "dev" <dev at shibboleth.net>
Sent: Saturday, 8 September, 2018 23:19:54
Subject: Re: GEANT OIDC plugin
On Fri, Sep 7, 2018 at 5:56 PM Jim Fox <fox at washington.edu> wrote:
>
> >
> > Suppose I log into a SAML SP and then later log into an OIDC RP, both
> > with your IdP. Is there single sign-on between the two protocols?
> >
>
> Yes, it runs through the Password flow.
Okay, great, so the protocols share the same session.
What about user identifiers? Does your IdP support a long-lived,
non-reassigned identifier for SAML? Were you able to re-use that
identifier for the OIDC 'sub' claim?
Thanks Jim.
Tom
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
More information about the dev
mailing list