<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="text-align:left; direction:ltr;">
<div>Joshua,</div>
<div><br>
</div>
<div>Each host that connects to the load balancer will get its own sticky session. The back channel request will be independent of the front channel and thus may be to a different server.</div>
<div>When session data needs to be persisted, it needs to be shared/clustered.</div>
<div><br>
</div>
<div>Ray</div>
<div><br>
</div>
<div>On Fri, 2021-06-04 at 13:01 -0700, Joshua Brodie wrote:</div>
<blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex">
<div style="font-size:8pt; color:#f58442 ; font-family: sans-serif; font-style:normal; font-weight:bold; padding:.2em">
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.
</div>
<br>
<div>
<div dir="ltr">Thank you Henri.
<div><br>
</div>
<div>It took me a while to research OpenID Connect to understand all the options (still learning).</div>
<div><br>
</div>
<div>To support OpenID backchannel transactions, for profiles where it is required, do the IDP nodes have to be clustered? We run 4 IDP nodes behind a sticky session load balancer (the IDP servers are standalone -- in the backend on the same DB, AD etc).</div>
<div><br>
</div>
<div><br>
</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Mon, 31 May 2021 at 22:17, Henri Mikkonen <<a href="mailto:henri.mikkonen@csc.fi">henri.mikkonen@csc.fi</a>> wrote:<br>
</div>
<blockquote type="cite" style="margin:0 0 0 .8ex; border-left:2px #729fcf solid;padding-left:1ex">
Hi Joshua,<br>
<br>
> On 31. May 2021, at 0.17, Joshua Brodie <<a href="mailto:josbrodie@gmail.com" target="_blank">josbrodie@gmail.com</a>> wrote:<br>
> <br>
> Does the OIDC plugin for IdP4.1 support both ‘Implicit’ and ‘Authentication/Basic’ flows?<br>
> <br>
> On my super preliminary dipping toe in water, appears to be ‘Implicit’ only - which happens to be what we require.<br>
<br>
The OIDC OP plugin supports all the OIDC conformance profiles defined in section 2.1 of [1].<br>
<br>
BR,<br>
Henri.<br>
<br>
[1] <a href="https://openid.net/wordpress-content/uploads/2018/06/OpenID-Connect-Conformance-Profiles.pdf" rel="noreferrer" target="_blank">
https://openid.net/wordpress-content/uploads/2018/06/OpenID-Connect-Conformance-Profiles.pdf</a><br>
</blockquote>
</div>
</div>
</blockquote>
</body>
</html>