Android Application Question

Marc Boorshtein mboorshtein at gmail.com
Wed Jan 4 16:20:03 EST 2017


>
>
> The hard part is actually clustering, though I grant that historically
> using port 8443 was a firewall issue, yes.
>
>
Thats what i was implying.  HA/Clustered state management is hard


>
> Except I can't authenticate that call as an IdP. SAML artifact usage
> assumes authentication of the request because to do otherwise is just wrong.
>
>
 So OIDC lets you have a public endpoint that does not require
authentication.  This is how the mobile app schemes all work.  Otherwise
you need to have a secret on every app deployed, which means its not a
secret at all.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170104/5cdff5c9/attachment.html>


More information about the users mailing list