Ex: Re: multiple "virtual" idp entity ids
Paul Henson
henson at signet.id
Fri Mar 4 03:04:43 UTC 2022
> My opinion is that's not adequate separation for safely operating
If everything on the Internet ran per my opinion, it would be a wildly
different place ;), I'm sure the same is true in your case :).
> I can't speak for others' opinions, but mine is that it's not an
> acceptable deployment model unless it's really just one organization,
> in which case I'd share the key to avoid adding attack surface.
This scenario is more of a hosted services environment where a single
organization is providing authentication services for a number of
different customers. Keycloak also supports such a deployment model
using multiple realms, but it's a bit more heavyweight than this
deployment warrants.
> them based on request vhost is perfectly possible I suppose.
> Generating the necessary security wiring and then plugging in
> functions to automate deriving them is doable.
Heh. Your doable and my doable when it comes to making the idp do fancy
tricks is like a virtuoso compared to a kid taking piano lessons :).
Thanks again for the input…
--
Signet - The Art of Access
https://www.signet.id/
More information about the users
mailing list