Unsolicited SSO handler for OIDC?

admin at haecceity.org admin at haecceity.org
Wed Nov 20 05:24:30 UTC 2024


On the IPSIE OIDF WG call today, the claim was made that IdP initiated OIDC
logins are supported.  I don't know enough about OIDC to confirm or deny.

https://github.com/openid/ipsie/issues/2#issuecomment-2486248322

Minutes from the call today have not been posted yet.

On Tue, Nov 19, 2024 at 12:25 PM Cantor, Scott via users <
users at shibboleth.net> wrote:

> > Is there a way to send a user to the Shibboleth IdP for login
> > and  afterwards to an OpenID Connect RP?
>
> No, because the "standard" request format in OIDC is just a vanilla
> redirect anyway, so the only factor that would distguingish one would be
> whether a RP notices by means of a mechanism intended to prevent it to
> begin with.
>
> Among some odd reasons that had more to do with the astoundingly weird way
> vendors viewed SSO at the turn of the century, the main reason it exists
> for SAML is that the request message is XML and heavily encoded, not a
> simple redirect.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241120/67885139/attachment.htm>


More information about the users mailing list