Slides from yesterday's webinar
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 31 12:28:22 EDT 2017
On 3/31/17, 11:40 AM, "users on behalf of Marc Boorshtein" <users-bounces at shibboleth.net on behalf of mboorshtein at gmail.com> wrote:
> I noticed that OIDC is on your roadmap.
Only in the "obviously we would do this given more resources than we currently have" sense. All we have right now is some spare time from a couple of people to hopefully do some design and code review of the work being done by others.
> We've been using OpenSAML with great success in OpenUnison and would look forward to giving back.
Well, the point of wanting OIDC is to have it in the IdP, using the same Spring WebFlow design, configured with our mechanisms, etc. Otherwise there really is no point since it would be a separate software stack with no connection to what we have and it would be unwieldy to deploy. We don't have the capacity to deal with two separate pieces of code designed in different ways anyway.
CAS support slotted pretty painlessly into our design, so there's not any reason so far to believe that's a lot to ask.
> Our object model isn't as clean as OpenSAML but would be happy to work with the Shib project to do so. Here are the links to
> github:
The group that's working on this right now without official commitments, but with the understanding that it needs to fit our design, is in Finland, and they're working at least to this point with the Nimbus library. If you have a self-maintained JOSE/JWT/etc. library and would be willing to compare/contrast it with that one, that would be of interest on the dev list.
If you've done any work to extend the OpenSAML message handling model to OIDC that would also be of interest since that hasn't really been done yet.
Thx,
-- Scott
More information about the users
mailing list