<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body dir="auto">
<div>
<div style="direction: inherit;">The OIDC add-on that we had written for Shib also provides OAuth2.0 support. </div>
<div style="direction: inherit;"><br>
</div>
<div style="direction: inherit;">Dave </div>
<br>
David Langenberg
<div>Asst. Director, Identity Management <br>
<div>The University of Chicago </div>
<div>Sent from my iPhone </div>
</div>
</div>
<div><br>
On Sep 21, 2016, at 7:40 PM, Klingenstein, Nate <<a href="mailto:nklingenstein@calstate.edu">nklingenstein@calstate.edu</a>> wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<blockquote type="cite"><span>A vendor's response to inquiry about SSO via SAML 2 is:</span><br>
</blockquote>
<blockquote type="cite"><span>"____ can integrate SAML through Open auth 2.0 if the service supports it."</span><br>
</blockquote>
<blockquote type="cite"><span></span><br>
</blockquote>
<blockquote type="cite"><span>Is that an arty "no" or does that offer the possibility of relying on Shibb IdP for authN?</span><br>
</blockquote>
<span></span><br>
<span>I think they meant OAuth 2.0, which is a sign.</span><br>
<span></span><br>
<span>Anyway, there's a binding for SAML tokens to OAuth 2.0 that went through the IETF. The IdP itself can't field OAuth requests as far as I know.</span><br>
<span></span><br>
<span>It would be pretty trivial to write a shim that could cache assertions sent by the IdP and expose those via OAuth.</span><br>
<span>-- </span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span><br>
</div>
</blockquote>
</body>
</html>