Shibboleth IdP and Support for SCIM?
Cantor, Scott
cantor.2 at osu.edu
Wed Aug 21 19:41:57 UTC 2024
> Does Shibboleth have any plans for supporting SCIM
> ("System for Cross-domain Identity Management"), a
> protocol for automating user provisioning to SP applications?
It would be a shim at best, as we hold none of the data that would make up the content. We're not an IDM system or a provisioning system (I wouldn't consider JIT a form of provisioning as much as a way to avoid the need for it, since provisioning doesn't scale well in a federated environment).
I don't think it would ultimately benefit, other than the fact that we probably write better code than a lot of other people, but that doesn't necessarily justify doing it.
> My understanding is that many/most of the commercial IdP
> solutions such as Microsoft Azure, Okta, Google,
> OneLogin, Auth0, and PingFederate all support SCIM.
Those aren't (just) IdPs, they are mostly product suites that include IDM as a function. In the Internet2 TAP products, Grouper and Midpoint serve those functions, and they both support SCIM.
If our members think it's worth doing, then we'll discuss It, but the updated roadmap was published and SCIM has not come up recently. But we would be a dumb pipe getting all of the data from somewhere else, ultimately.
> If there are no plans to add this functionality to Shibboleth,
> are there any suggestions for how to integrate it with
> Shibboleth through some plugin or third party functionality?
It's an IDM function, I would be looking at my IDM system to provide it, or as I said, Grouper has that feature.
I'm not aware of anyone having worked on a plugin (formal or otherwise) for the IdP to support it, but if something exists I'd be interested.
-- Scott
More information about the users
mailing list