use of JWT and / or STS with Shibboleth IDP?
Liam Hoekenga
liamr at umich.edu
Thu Oct 6 14:57:40 EDT 2016
I got a chance to talk to the team asking for this, and it's not quite as
weird as I thought. Most of this is not stuff they're expecting the IDP to
do.
On Wed, Oct 5, 2016 at 4:13 PM, Klingenstein, Nate <
nklingenstein at calstate.edu> wrote:
>
> The other obvious answer is to actually implement a formal STS using a
> specification TBD. Personally, I would be concerned about building a
> custom solution that you will need to maintain.
>
Agreed. If we are going to stand something up, I'd rather it be something
reusable and that it require little maintenance. I came across this...
https://github.com/ausaccessfed/rapidconnect
It's a SAML protected JWT issuer / validator. It seems that something like
this might fill the immediate need and be generally useful in the long term.
Nate - you said you had reservations about JWT. Can you share your
thinking? It can be out of band if you'd rather.
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161006/88cb2cb1/attachment.html>
More information about the users
mailing list