use of JWT and / or STS with Shibboleth IDP?

Liam Hoekenga liamr at umich.edu
Thu Oct 6 14:57:40 EDT 2016


I got a chance to talk to the team asking for this, and it's not quite as
weird as I thought.  Most of this is not stuff they're expecting the IDP to
do.

On Wed, Oct 5, 2016 at 4:13 PM, Klingenstein, Nate <
nklingenstein at calstate.edu> wrote:

>
> The other obvious answer is to actually implement a formal STS using a
> specification TBD.  Personally, I would be concerned about building a
> custom solution that you will need to maintain.
>

Agreed.  If we are going to stand something up, I'd rather it be something
reusable and that it require little maintenance.  I came across this...

    https://github.com/ausaccessfed/rapidconnect

It's a SAML protected JWT issuer / validator.  It seems that something like
this might fill the immediate need and be generally useful in the long term.

Nate - you said you had reservations about JWT.  Can you share your
thinking?  It can be out of band if you'd rather.

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161006/88cb2cb1/attachment.html>


More information about the users mailing list