OIDC certificate suppport

Cantor, Scott cantor.2 at osu.edu
Tue Jan 14 08:27:20 EST 2020


On 1/14/20, 3:32 AM, "users on behalf of Kicic Sakib" <users-bounces at shibboleth.net on behalf of Sakib.Kicic at smhi.se> wrote:

> Is there any c:classRef in “shibboleth.OIDCAuthnContextClassReference” bean pointing to x509Internal?

The relationship between login flows and supported principals of all the various types (SAML, OIDC, anything else) is arbitrary and under your control.
 
The X.509 flows come configured to recognize the SAML context class principals that are defined in the standard but nobody should ever use those anyway. Contexts should never be technology specific but abstracted to represent general levels of quality known to a deployment to avoid having to change them when technology changes.

So to the extent that OIDC as an equivalent acr to use, I wouldn't use it anyway, for the same reason.
 
-- Scott




More information about the users mailing list