Android Application Question
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 4 16:32:20 EST 2017
On 1/4/17, 4:21 PM, "users on behalf of Marc Boorshtein" <users-bounces at shibboleth.net on behalf of mboorshtein at gmail.com> wrote:
> Really? I'm using OIDC now with google for a multi-lateral federation and it works great. What design decisions in OIDC
> stop that?
The problem is that scaling RPs without giving up authenticating them requires public keys and trust management. They have not accepted that and the RPs will never support it. Thus, no scaling. Of course, if you eliminate authentication of the RP, yes, you can do it. Lots of people, probably most, are fine with that.
-- Scott
More information about the users
mailing list