use of JWT and / or STS with Shibboleth IDP?
Liam Hoekenga
liamr at umich.edu
Thu Oct 20 11:36:08 EDT 2016
WRT the IBM API Manager..
> If you care about the content, then you better care about the content.
> You can't care about part of the token(uniqname:token) and not the rest.
>
The token validation web services needs to care about the content of the
token. Our thinking is that it would be better to implement a reusable
standard (i.e. JWT) than create an arbitrary, single purpose token creator
/ validator.
> If all you want is "IS IT YES?" "YES"/"NO", that's the most degenerative
> case of not caring about the contents. 200 is yes, anything else is no.
> Shim, proxy, direct, whatever.
>
The only thing the API Manager is interested is a YES / NO answer.
Our current plan is to pursue a RapidConnect like JWT creation / validation
service.
While we could script the creation of the token value, we'd rather not have
multiple copies of the creation code, so we'd rather pull it from the web
service.
Any suggestions on accessing a SAML protected web service via a scripted
attribute in the Shib IDP?
LIam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161020/48be211b/attachment.html>
More information about the users
mailing list