Intended identity switch

Prog programmierstudi at gmx.de
Tue Aug 23 16:57:03 EDT 2016


Dear people,

recently the idea came up, that people who have accounts at different 
organizations of our IdM could possibly switch identity (principals) 
without performing logout/login manually. I can't imagine how that would 
work without performing global logout from all sessions involved, but it 
might well be that i just have never heard (read about) alternatives. 
However, assuming the global logout succeeds the idea is to use 
REMOTE_USER authentication (or x509 or something) behind the scenes 
(server to server) and then delegate the new session back to the client 
somehow. ECP might help us to initiate the new session. I've read about 
delegating sessions from client to application (uportal...more?) but not 
the other way around. Are these mechanism suitable or are there better 
ones? Do additional mechanisms exist to fill in the gaps? How could we 
delegate the new session to the users client?

Please note that we use IdP2 in that case with NIIF slo and have a 
working global logout setup, so a possible flow can involve redirecting 
the client to global logout in the first step. We possibly could also 
switch to IdP3 if that is a better option (already on the roadmap but we 
still are working on optimization of our IdP3 setup). I know that 
changes to our IdM might raise the proposed mechanism obsolete and in 
fact we are reworking the IdM but this is still in the early days.

Thanks you for reading.

All the best,

Michael


More information about the users mailing list