<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    There is an OIDC extension for Shibboleth [1] that allows the IdP to
    also act as an OIDC provider.<br>
    You could also use any OAuth2/OIDC software and protect the
    Authorization Endpoint with a SAML (Shibboleth) SP and use your IdP
    for authentication.<br>
    <h2 style="margin: 24px 0px 0px; color: rgb(0, 0, 0); font-family:
      "Fira Sans", "Helvetica Neue", Helvetica,
      Arial, sans-serif; font-style: normal; font-variant-ligatures:
      normal; font-variant-caps: normal; letter-spacing: normal;
      orphans: 2; text-align: start; text-indent: 0px; text-transform:
      none; white-space: normal; widows: 2; word-spacing: 0px;
      -webkit-text-stroke-width: 0px; background-color: rgb(255, 255,
      255); text-decoration-style: initial; text-decoration-color:
      initial;">Authorization Endpoint</h2>
    <br class="Apple-interchange-newline">
    <pre class="moz-signature" cols="72">
</pre>
    <div class="moz-cite-prefix">On 03.05.2017 21:24, Liam Hoekenga
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAH4ZtKTrLZDs+YmbOmUkXPUFkTQKOkok7KL6Wfw6D0BZ=uXY-g@mail.gmail.com">
      <div dir="ltr">
        <div>slightly off topic..</div>
        <div><br>
        </div>
        We're getting an increasing number of requests for OAuth2 /
        OIDC.
        <div>We want something that can be Shibboleth protected such
          that it stays in our current login ecosystem.</div>
        <div><br>
        </div>
        <div>What are other people doing?</div>
        <div><br>
        </div>
        <div>Liam</div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
  </body>
</html>