Reused usernames and persistentIds

Cantor, Scott cantor.2 at osu.edu
Fri Oct 24 10:17:20 EDT 2014


On 10/24/14, 6:24 AM, "Ramon Pfeiffer" <ramon.pfeiffer at uni-tuebingen.de>
wrote:
>
>Is there any documentation of the upcoming changes between v2 and v3?
>Also, I heard it told that  IdP v3 will have it's own user consent
>capabilities?

Yes, it will. I guess the main feature additions that aren't focused on
extensibility would be:

- consent and post-login attribute checking for broken apps like Google
- built-in client-side sessions for those wise enough to give up on single
logout
- built-in memcache and Hibernate session options
- native LDAP, Kerberos, and X.509 authentication along with JAAS
- reuse of a single login config for browser and ECP clients
- arbitrary classification of relying parties into categories using
pluggable conditions
- support for all SAML authn context comparison types
- multi-tab login support, assuming webflow works as advertised
- support for on-demand metadata lookup
- a CAS server implementation built by a CAS developer who's joined the
project
- direct configuration of NameID generation instead of indirectly using
attribute config
- GCM encryption for SPs that support it
- per-RP and metadata-based algorithm selection
- decryption support for Encrypted NameIDs in a request

That's off the top of my head. I was going to say the list wasn't all that
long, but in fact it's not really that short.

-- Scott



More information about the users mailing list