OpenID authentication context

Kevin P. Foote kpfoote at iup.edu
Wed May 30 21:57:33 BST 2012


-> It is likely we will stick to the model of having the SP request the authentication type, because OpenID authentication will only be offered for select SPs .... 

I believe Duke had something like this being shown and during a web demo
last fall(ish). 


The IdP would be able to field the SP requesting an auth-type that was 'allowed'
to show the OpenID option. Which would throw up a slightly different
login page with the OpenID link/option.

------
thanks
  kevin.foote

On Wed, 30 May 2012, Russell Beall wrote:

-> I wouldn't mind selecting the authentication method at the IdP and having the SP configuration remain unchanged.  Is it possible to have an SP initiate a normal request that ends up at the login.jsp form, but then I have a "Login with OpenID" button that then has the IdP switch to RemoteUser-based authentication?
-> 
-> I see that the SP could tell what authentication type was used by the Shib_Authentication_Method header.
-> 
-> It is likely we will stick to the model of having the SP request the authentication type, because OpenID authentication will only be offered for select SPs and we wouldn't want to confuse the entire campus population with a "Login with OpenID" button on the main page.
-> 
-> Regards,
-> Russ.
-> 
-> On May 30, 2012, at 12:06 PM, Cantor, Scott wrote:
-> 
-> > I think my opinion is that it's a matter for the IdP to offer this choice
-> > of authentication, and up to the attributes you assert to give the SP the
-> > means to distinguish cases, not something you want an SP requesting
-> > explicitly. Even if I disagree with 800-63 about, well, a lot, I do think
-> 
-> --
-> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-> 


More information about the users mailing list