<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> OIDC with no trust (only web PKIX) and self-registration is probably<br>
> closest to what you have right now?<br>
<br>
</span>Given that Liam has asked about OIDC before, that was my first thought<br>
as well, FWIW.<br></blockquote><div><br></div><div>I think OIDC's dynamic registration might be the closest match to what's going on in Cosign, and it /is/ supported by the GEANT OIDC provider.  Running an open SAML IDP or enabling OIDC dynamic registration creates a similar problem that we're having with Cosign - we don't have a good idea of who's using our service or how to get in touch with them.</div><div><br></div><div>Liam</div></div></div></div>