OpenID authentication context

Peter Schober peter.schober at univie.ac.at
Wed May 30 21:59:40 BST 2012


* Russell Beall <beall at usc.edu> [2012-05-30 20:55]:
> With OpenID at the IdP level, we will be able to enrich the user
> login experience with additional data and entitlements registered in
> our directory.

As that seems to be the only reason you'd involve your IdP in any of
that (instead of just letting the RP implement an OpenID RP themselfs):
How do you link whatever data you might get back from some OpenID
provider to your campus directory (i.e., how do you identify OpenID
URLs as specific local users)? Do you know the unique identifier
(whatever that may be) that Google or Yahoo or whoever will release to
your OpenIP RP (the one protecting the RemoteUser handler of your SAML
IdP)? How do you come to know of it? I'm assumingn people don't know
their own OpenID and possibly cannot know whatever other identifier
the IdP will issue.
-peter


More information about the users mailing list