Ex: Re: multiple "virtual" idp entity ids

Paul Henson henson at signet.id
Fri Mar 4 03:04:43 UTC 2022


> My opinion is that's not adequate separation for safely operating

If everything on the Internet ran per my opinion, it would be a wildly 
different place ;), I'm sure the same is true in your case :).

> I can't speak for others' opinions, but mine is that it's not an
> acceptable deployment model unless it's really just one organization,
> in which case I'd share the key to avoid adding attack surface.

This scenario is more of a hosted services environment where a single 
organization is providing authentication services for a number of 
different customers. Keycloak also supports such a deployment model 
using multiple realms, but it's a bit more heavyweight than this 
deployment warrants.

> them based on request vhost is perfectly possible I suppose.
> Generating the necessary security wiring and then plugging in
> functions to automate deriving them is doable.

Heh. Your doable and my doable when it comes to making the idp do fancy 
tricks is like a virtuoso compared to a kid taking piano lessons :).

Thanks again for the input…

-- 
Signet - The Art of Access
https://www.signet.id/



More information about the users mailing list