<div dir="ltr"><br><br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br><br class="gmail_msg">
<br class="gmail_msg">
The hard part is actually clustering, though I grant that historically using port 8443 was a firewall issue, yes.<br class="gmail_msg">
<br class="gmail_msg"></blockquote><div><br></div><div>Thats what i was implying.  HA/Clustered state management is hard</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br class="gmail_msg">
Except I can't authenticate that call as an IdP. SAML artifact usage assumes authentication of the request because to do otherwise is just wrong.<br class="gmail_msg"><br class="gmail_msg"></blockquote><div><br></div><div> So OIDC lets you have a public endpoint that does not require authentication.  This is how the mobile app schemes all work.  Otherwise you need to have a secret on every app deployed, which means its not a secret at all.</div></div></div>