<div dir="ltr"><div><span style="font-size:12.8px">> There is an OIDC extension for Shibboleth [1] that allows the IdP to also act as an OIDC provider.</span><br style="font-size:12.8px"></div><div><br></div>We're looking into that, but it doesn't (currently) work with the RemoteUser authentication flow.<div><br></div><div><span style="font-size:12.8px">> You could also use any OAuth2/OIDC software and protect the Authorization Endpoint with a </span></div><div><span style="font-size:12.8px">> SAML (Shibboleth) SP and use your IdP for authentication.</span><br></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">Most of the ones that I've found have their own account / login mechanism.  I haven't found many solutions that want to get the user from REMOTE_USER.</span></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">UChicago has an overlay for MitreID that preceded the IDP+OIDC integration</span></div><div><span style="font-size:12.8px"><a href="https://github.com/uchicago-sg/shibboleth-mitreid-connect">https://github.com/uchicago-sg/shibboleth-mitreid-connect</a></span><br></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">SurfNet has a shib protected OAuth2 provider, but it doesn't do OIDC:</span></div><div><span style="font-size:12.8px"><a href="https://github.com/OAuth-Apis/apis">https://github.com/OAuth-Apis/apis</a></span><br></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">The AAF has something called "Rapid Connect", which provides JWTs to applications</span></div><div><span style="font-size:12.8px"><a href="https://github.com/ausaccessfed/rapidconnect">https://github.com/ausaccessfed/rapidconnect</a></span><br></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">Liam</span></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, May 4, 2017 at 2:59 AM, David Huebner <span dir="ltr"><<a href="mailto:david.huebner@daasi.de" target="_blank">david.huebner@daasi.de</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
  
    
  
  <div bgcolor="#FFFFFF" text="#000000">
    There is an OIDC extension for Shibboleth [1] that allows the IdP to
    also act as an OIDC provider.<br>
    You could also use any OAuth2/OIDC software and protect the
    Authorization Endpoint with a SAML (Shibboleth) SP and use your IdP
    for authentication.<br>
    <h2 style="margin:24px 0px 0px;color:rgb(0,0,0);font-family:"Fira Sans","Helvetica Neue",Helvetica,Arial,sans-serif;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial">Authorization Endpoint</h2><div><div class="h5">
    <br class="m_-2869995051191358185Apple-interchange-newline">
    <pre class="m_-2869995051191358185moz-signature" cols="72"></pre>
    <div class="m_-2869995051191358185moz-cite-prefix">On 03.05.2017 21:24, Liam Hoekenga
      wrote:<br>
    </div>
    <blockquote type="cite">
      <div dir="ltr">
        <div>slightly off topic..</div>
        <div><br>
        </div>
        We're getting an increasing number of requests for OAuth2 /
        OIDC.
        <div>We want something that can be Shibboleth protected such
          that it stays in our current login ecosystem.</div>
        <div><br>
        </div>
        <div>What are other people doing?</div>
        <div><br>
        </div>
        <div>Liam</div>
      </div>
      <br>
      <fieldset class="m_-2869995051191358185mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
  </div></div></div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>