Intended identity switch
Prog
programmierstudi at gmx.de
Tue Aug 23 16:57:03 EDT 2016
Dear people,
recently the idea came up, that people who have accounts at different
organizations of our IdM could possibly switch identity (principals)
without performing logout/login manually. I can't imagine how that would
work without performing global logout from all sessions involved, but it
might well be that i just have never heard (read about) alternatives.
However, assuming the global logout succeeds the idea is to use
REMOTE_USER authentication (or x509 or something) behind the scenes
(server to server) and then delegate the new session back to the client
somehow. ECP might help us to initiate the new session. I've read about
delegating sessions from client to application (uportal...more?) but not
the other way around. Are these mechanism suitable or are there better
ones? Do additional mechanisms exist to fill in the gaps? How could we
delegate the new session to the users client?
Please note that we use IdP2 in that case with NIIF slo and have a
working global logout setup, so a possible flow can involve redirecting
the client to global logout in the first step. We possibly could also
switch to IdP3 if that is a better option (already on the roadmap but we
still are working on optimization of our IdP3 setup). I know that
changes to our IdM might raise the proposed mechanism obsolete and in
fact we are reworking the IdM but this is still in the early days.
Thanks you for reading.
All the best,
Michael
More information about the users
mailing list