Integration of OIDC/OAuth 2.0 Application with Shibboleth IdP/SP
Dan McLaughlin
dmclaughlin at tech-consortium.com
Sat Aug 19 15:38:10 UTC 2023
We currently utilize the Shibboleth IdP and SP for our authentication
and application protection needs. We have encountered a new challenge:
integrating with a third-party application that does not support SAML
but only OpenID and OAuth 2.0.
Though I've reviewed the OIDC-related documentation available for the
Shibboleth IdP, I'm finding it challenging to visualize the flow,
especially since the Shibboleth SP seems only to support SAML.
A few specific queries:
1. Does the Shibboleth IdP act as a bridge between the OIDC/OAuth
authentication from the third-party application and our SAML-based
applications? In essence, does it "translate" OIDC/OAuth tokens and
claims to SAML assertions and attributes?
2. In a scenario where a user is authenticated in the third-party
application via OpenID and then tries to access one of our
applications protected by the Shibboleth SP, how does the SP recognize
the need to redirect to the Shibboleth IdP OIDC proxy if there isn't a
SAML token present?
I would greatly appreciate it if anyone could point me to a detailed
diagram, video, or any other resource that might help illustrate this
flow more comprehensively.
Thank you in advance for your insights and guidance.
--
Thanks,
Dan
More information about the users
mailing list