Shibboleth IDP Google Authentication

Klingenstein, Nate nklingenstein at calstate.edu
Sat Feb 25 16:56:19 EST 2017


Vipin,

> So you say SimpleSAMLPHP as IDP and Shibboleth SP is a better
> combination than for Shibboleth as IDP and as IDP for all simple and
> complex use cases.

Identity doesn't have the luxury of absolute truth.


There are a lot of interoperability comments and maintainability
comments that can be made in any direction.  I wouldn't make any broad
statement like that.


There are running conversations about whether the software itself is a
specification layer.  Ideally, you would only know about protocols. 
Obviously, you've had to learn more.


But the lesson is relative and ongoing.  There are only patterns, use
cases, and tools.  Solutions are built and maintained.  Standards need
at least one more pass at interop, but even from that, the lesson will
never be an algorithm.


Identity hits the gooey layer between technology and people.  It will
never be truly simple, and that's ultimately why this is frozen.  Too
many special cases and too crucial to change.


I think it can get easier in implementation, but in concept, not a whole
lot has changed in the 17 years I've worked on it.


Hope this helps,

Nate.



More information about the users mailing list