OpenID authentication context

Russell Beall beall at usc.edu
Wed May 30 22:45:46 BST 2012


We can enrich the data by using our federated guest registration page.  That is where a remote user value from an OpenID provider could be registered with additional self-asserted data in our directory.

Then, additionally, our group membership tool can be used to put that user into select groups.

Currently this federated registration only applies to InCommon partners, but upon successful completion of this OpenID work, we would then be registering OpenID-based guests as well.

Regards,
Russ.

On May 30, 2012, at 1:59 PM, Peter Schober wrote:

> * Russell Beall <beall at usc.edu> [2012-05-30 20:55]:
>> With OpenID at the IdP level, we will be able to enrich the user
>> login experience with additional data and entitlements registered in
>> our directory.
> 
> As that seems to be the only reason you'd involve your IdP in any of
> that (instead of just letting the RP implement an OpenID RP themselfs):
> How do you link whatever data you might get back from some OpenID
> provider to your campus directory (i.e., how do you identify OpenID
> URLs as specific local users)? Do you know the unique identifier
> (whatever that may be) that Google or Yahoo or whoever will release to
> your OpenIP RP (the one protecting the RemoteUser handler of your SAML
> IdP)? How do you come to know of it? I'm assumingn people don't know
> their own OpenID and possibly cannot know whatever other identifier
> the IdP will issue.
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list