Android Application Question
Marc Boorshtein
mboorshtein at gmail.com
Wed Jan 4 16:20:03 EST 2017
>
>
> The hard part is actually clustering, though I grant that historically
> using port 8443 was a firewall issue, yes.
>
>
Thats what i was implying. HA/Clustered state management is hard
>
> Except I can't authenticate that call as an IdP. SAML artifact usage
> assumes authentication of the request because to do otherwise is just wrong.
>
>
So OIDC lets you have a public endpoint that does not require
authentication. This is how the mobile app schemes all work. Otherwise
you need to have a secret on every app deployed, which means its not a
secret at all.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170104/5cdff5c9/attachment.html>
More information about the users
mailing list