Shibboleth authentication to a RESTful API from mobile, curl, etc.

Cantor, Scott cantor.2 at osu.edu
Tue Apr 28 13:43:41 EDT 2015


On 4/28/15, 1:39 PM, "Philip Durbin" <philip_durbin at harvard.edu> wrote:
>
>It look like the OSU wiki got updated to say "The current OSU Mobile application supported on iOS and Android includes native implementations of ECP client code, but I have been unable to get that code released." It's a bummer but completely understandable and defensible. :)

I don't know about either, but I updated it after you asked so there's no false promise.

>I'm curious about Scott's comment "commercial TLS is broken, so relying on that is a disservice to all of your users" but maybe that belongs in a new thread!

As I told somebody that asked offlist, if I have to convince somebody in 2015 that the way browsers authenticate web servers today is broken, I probably can't really convince you.

There's no third party trust broker for TLS worth anything, so I'm suggesting that establishing trust the same way SAML servers do in this sector (but not others) is better than any of the alternatives (which is a low bar to meet).

-- Scott



More information about the users mailing list