<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Fri, Nov 17, 2017 at 1:16 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-">> - OIDCfed (spec by Roland Hedberg et al.) compatibility under construction<br>
> now, need to be in testable shape before end of November:<br>
> <a href="https://wiki.geant.org/display/gn42jra3/OIDCfed+Hackathon" rel="noreferrer" target="_blank">https://wiki.geant.org/<wbr>display/gn42jra3/OIDCfed+<wbr>Hackathon</a><br>
<br>
</span>The latter doesn't have any useful content so I'm not sure I<br>
understand the point you're trying to make. In any case, just today<br>
the OpenID Foundation published FastFed 1.0:<br>
<a href="http://openid.net/specs/fastfed-1_0-00.html" rel="noreferrer" target="_blank">http://openid.net/specs/<wbr>fastfed-1_0-00.html</a><br>
<br>
I don't know if that's relevant (I'm still trying to get my head<br>
around FastFed) but I thought I'd mention it just in case.<br></blockquote><div><br></div><div> FastFed is mostly (maybe entirely?) focused on the manual configuration of a bilateral federation.  At least, that's how Dick Hardt tends to pitch it.  "IdP operator wants to federate with AWS, but figuring out what to put in the blanks is hard."  Where the intro says the goal is "to quickly connect two providers", I'm pretty sure that's just what they mean.</div><div><br></div><div>Roland's current draft for OpenID Connect multi-party federation is here:<br><a href="http://openid.net/specs/openid-connect-federation-1_0.html">http://openid.net/specs/openid-connect-federation-1_0.html</a><br></div><div><br></div><div>Greg</div></div></div></div>