use of JWT and / or STS with Shibboleth IDP?

David Langenberg davel at uchicago.edu
Thu Oct 6 10:02:43 EDT 2016


Sounds like what you’re really looking for here is OAuth/OIDC implicit profile?


Dave

 

 

-- 

David Langenberg

Asst. Director, Identity Management

The University of Chicago

 

From: users <users-bounces at shibboleth.net> on behalf of Liam Hoekenga <liamr at umich.edu>
Reply-To: Shib Users <users at shibboleth.net>
Date: Wednesday, October 5, 2016 at 3:06 PM
To: Shib Users <users at shibboleth.net>
Subject: use of JWT and / or STS with Shibboleth IDP?

 

We're working to deploy IBM's API Manager.  The API manager integration team has asked if the IDP can provide an authentication token... 

 

>From our meeting notes..

- After successful shibboleth authentication, pass a token back to the APIm for use during the session

- After successful shibboleth authentication, generate a token and display it on a web page so that the token can be used on the command line.

- Create a URI that will take as input a base 64-encoded uniqname:token pair, and tell whether the token is still valid.

 

Based on their request, it feels a lot like they're asking for us to provide a security token service, or for for the IDP to produce JWT.

 

Am I reading this right? How have others in the community provided this functionality?

 

Liam

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161006/8b50fa08/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6181 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20161006/8b50fa08/attachment.p7s>


More information about the users mailing list