Google ID as sort of the IDP?

Mike Flynn shibbolethlynda at yahoo.com
Fri Oct 12 15:23:18 EDT 2012


FYI, we integrate to Google via SAML (ADFS Idp on our side) but Google has recently told us that they are moving off of SAML and on to openID.  They stated this to us when they asked to integrate to our products:

"we no longer support SAML for authentication on vendor websites. For security purposes we ask our vendors to support Single-Sign-On (SSO) using OpenID for authentication"

Not sure what the ramifications are on this going forward yet as that indicates that connecting to them as a consumer of their services still supports SAML but going the reverse, openID is what they want...  Anyway, just a heads up.


________________________________
 From: Oleg Chaikovsky <oleg.chaikovsky at aegisusa.net>
To: users at shibboleth.net 
Sent: Tuesday, October 9, 2012 1:55 PM
Subject: Google ID as sort of the IDP?
 
I have seen the large amounts of information about connecting Google 
Apps via Shib which is fairly straightforward at this point. Google Apps 
as an SP.

So - now - if a group wanted to make their Google Apps domain to be the 
primary identifier for all of their other apps - would that simply be 
using external auth through the IdP? Simple as that? I keep thinking 
there must be more to it but all info I have read on the Wiki points to 
that model. (there are no additional attributes to consider in this idea).

-- 
Oleg Chaikovsky

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121012/3cac89ed/attachment.html 


More information about the users mailing list