Google ID as sort of the IDP?

Tom Scavo trscavo at gmail.com
Tue Oct 9 17:08:49 EDT 2012


On Tue, Oct 9, 2012 at 4:55 PM, Oleg Chaikovsky
<oleg.chaikovsky at aegisusa.net> wrote:
> I have seen the large amounts of information about connecting Google
> Apps via Shib which is fairly straightforward at this point. Google Apps
> as an SP.
>
> So - now - if a group wanted to make their Google Apps domain to be the
> primary identifier for all of their other apps - would that simply be
> using external auth through the IdP? Simple as that? I keep thinking
> there must be more to it but all info I have read on the Wiki points to
> that model. (there are no additional attributes to consider in this idea).

I'm not sure what you're driving at, but if your IdP works with Google
Apps, it can certainly be made to work with other SAML-enabled apps.
Actually, here's a fun experiment. Log into Google Apps as usual. Now
try to log into an OpenID-enabled app. Since you have a session with
Google Apps, you will immediately be prompted with the Google user
consent page. Done.

Tom


More information about the users mailing list