AW: Should OIDC subs be globally unique?
Bergmann, Clemens
clemens.bergmann at tu-darmstadt.de
Sun Mar 27 05:35:19 UTC 2022
Hi,
I just recently configured OIDC on our IdP and decided to follow the spec and make the sub claim not scoped.
On the other hand don't share any attributes by default to any SP/RP so I have to explicitly allow sharing of the subject. If such a RP would come along I could define a second AttributeDefinition that would also OIDCStringTranscode to "sub" and be scoped and share that instead of the unscoped one.
I deliberately did not prepare this AttributeDefinition beforehand because I want to first try to convince the RP otherwise and not have me or a colleague "just do it because it is less discussion".
Viele Grüße
Clemens (Bergmann)
--
Clemens Bergmann
Gruppe Nutzermanagement und Entwicklung
Technische Universität Darmstadt
Hochschulrechenzentrum, Alexanderstraße 2, 64289 Darmstadt
Tel. +49 6151 16 71184
http://www.hrz.tu-darmstadt.de/
> -----Ursprüngliche Nachricht-----
> Von: users <users-bounces at shibboleth.net> Im Auftrag von Wessel, Keith
> via users
> Gesendet: Freitag, 25. März 2022 15:48
> An: Shib Users <users at shibboleth.net>
> Cc: Wessel, Keith <kwessel at illinois.edu>
> Betreff: RE: Should OIDC subs be globally unique?
>
> I agree, but I believe Scott's point is what if the RP doesn't do what they
> "must" do. It's not much more work to scope the sub claim, thus saving
> headache later when you encounter an RP who (1) doesn't play by the rules
> and (2) doesn't care.
>
> I'd be interested in hearing what others are doing, though. Are many making
> the sub claim globally unique, or are more just trusting in the spec?
>
> Keith
>
>
> -----Original Message-----
> From: Alan Buxey <alan.buxey at myunidays.com>
> Sent: Friday, March 25, 2022 9:44 AM
> To: Shib Users <users at shibboleth.net>
> Cc: Wessel, Keith <kwessel at illinois.edu>
> Subject: Re: Should OIDC subs be globally unique?
>
> hi,
>
> If a relying party consumes identities from multiple operators, then it must
> combine the sub and iss claim to create a globally unique identifier. ie scoping
> isnt in the role of the Identity Provider (their role is just to ensure the subs
> are unique and don't change :).
> - obviously this brings into play issues such as what happens
> if/(when!) the ISS changes.....
>
> alan
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6377 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20220327/65b9c2e5/attachment.p7s>
More information about the users
mailing list