Encrypting OIDC secrets in static metadata
Cantor, Scott
cantor.2 at osu.edu
Wed Oct 2 12:18:02 UTC 2024
> On a more serious note: The key benefit for me/us is that
> with OIDC (welll OAuth2) we get centralized managed (so
> RPs don't have to invent the wheel over and over) Machine 2
> Machine auth[NZ] which we can use to finally replace
> GSSAPI/SPNEGO and custom authZ.
OAuth is certainly a different beast, and the policy for that tends to require more of the registration stuff I admit.
We do have the DPOP stuff coming which I think is a precondition. Bearer tokens are a joke for API access. I lost all hope when people actually saw that as a step forward.
-- Scott
More information about the users
mailing list