Skip to Content.
Sympa Menu

oidc-deploy - Re: a start, OAuth2 use cases, thoughts on addressing each

Subject: OIDC Deployment Working Group

List archive

Re: a start, OAuth2 use cases, thoughts on addressing each


Chronological Thread 
  • From: Nick Roy <>
  • To: Eric Goodman <>, "" <>
  • Subject: Re: a start, OAuth2 use cases, thoughts on addressing each
  • Date: Thu, 9 Aug 2018 19:40:06 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:6vwisx9zXtOm3f9uRHKM819IXTAuvvDOBiVQ1KB+0+kVIJqq85mqBkHD//Il1AaPAd2Fraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HSbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDtU7s6RSqt4LtqSB/wiScIKTg58H3MisdtiK5XuQ+tqwBjz4LRZoyaM+dwfr7GfdMCW2VOQtpRWSJGAoO5dYQPDuwBNvtco4Tyo1YCqB2zDhSuCuzy0D9Fnn/407Mn3eQ9Hw/I3wIgH9MSv3rbo9r4L7sSUfmpwKXU0TnPc+1a1DHg44bIaBAhpvSMUKpof8rQ1UYvFB7OgEmXqY3lIjiY0eINs3Kc7+tgTu+vimgnqx1vrTi1wMcjlJXJipwPxl/a6Cp53Z84KNulQ0B1Zt6kFYFftyCcN4ZuTcMiRGZouCk+yrIYo5K0YC8KyJEhyhXCaPKHa5CF7x3/WOqLPDt0mHBodKi+ihux60Ss1/HwW82s3FtIoCdJiMTAu38X2xDO98SKSuFx8lqj1DqSzwzT5P9LLEMomafeLpMt37Awm5oWvEnCGiL7l1n5gaqXe0o5/uWn8OHqb7Hpq5CHOYJ5jBz1PL40lcylG+s4NxADX2iF9uS4073u5VX3TalNgPEqnaTVqY3XK9wVq6KgBA9ayZgs5wy4Dze7zNQXhn4HLE9DeB2alYTpI0vOIPfkDfihn1usjDZrx/fAPrH7BZXNM2TDkLPmfbZ66E5Q0hY8zdda555MC7EBJuz8WlPpudHXEhM1KRG4z/rlBdln144TWniDDrKFPK7WqVOI4/ggI+iIZI8bojb9LP0l6ubojX8jnl8cfbKk3ZoRaHCkAPtmOUOZbmTwgtsfC2sFoBcxTPHyhF2YTTFTf2qyX7475jwjCYKmC5vMRoeogLyE2ye7GIdaZmdcClCDCHvocISEVOoQZy6LP8BujCQEVbymS44hzhyusA76y6F7LurP5CEUr5Pj1N5p5+LNjxEy8yJ7D9iD322XUW57g34IFHcK2/VSu012gniE1qR9ivoQQfFJ5vgPfQA9OZvVycRnANfqHA/NY4HNAByhQ9mtRD08VtY20vcPZU16HtCliFbExSXgS+sSlrCAQZA56qbbzlDwIc16znPB0u8mlVZwEeVVMmjzoK909EDpAJ+Bx0ODkLeCdKIA0TTL+XvZi2eCoRcLA0ZLTazZUCVHNQPtptPj6xaHEub0U+YuLxdBxMieK6BDdtzuixBcSez+PMjFPTvjgH++UBCPwL7ELJHnfWkQxm38MAAFiEhSmBTOLg0iHmGkqmPaAiZpEAfpeUT92eh4tH6hSEIolUeHY1Ayn7c=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Somewhat off-topic (my apologies), but did anyone notice Andreas
Solberg's comment on openid-specs-ab that the Norwegian R&E federation
is now OpenID connect by default? I have not dug into this further with
Andreas, but might be interesting to chat with him. Let me know what you
think and if that would be something this group would be interested in.
If not, I can pursue it with him separately.

Best,

Nick


On 8/9/18 10:22 AM, Eric Goodman wrote:
> I separately sent a note to Nathan that I'm on the agenda for the UC-wide
> API "standards" workgroup to discuss what people are doing/looking with
> OIDC/OAuth. That meeting is a week from Friday, so hopefully I'll have some
> data points to provide after that meeting -- which is unfortunately after
> our next OIDC group meeting. Vaguely related, I'm at a conference next
> Tuesday, so may miss next week's call.
>
> --- Eric
>
> -----Original Message-----
> From:
>
>
> <>
> On Behalf Of Steven Carmody
> Sent: Thursday, August 9, 2018 8:43 AM
> To:
>
> Subject: a start, OAuth2 use cases, thoughts on addressing each
>
> Hi,
>
> On last week's call, Alan, Roland, and I volunteered to identify the
> most common OAuth2 use cases currently in place on campuses; step 2 was
> to identify best practice for addressing each; step 3 would be to see
> how much of the required support is already available in the
> Shibboleth-GEANT-Finish OIDC work.
>
> We had an email conversation, but it quickly became clear that this
> would benefit from participation by the broader group.
>
> I've created a new google doc:
>
> https://docs.google.com/document/d/15G_YRWisEa-5Kj5gU_D-i4MLMh-IJWl0Q5CAsqSy4ag/edit?usp=sharing
>
> everyone should be able to edit that doc. It includes large portions of
> the email that Alan and I exchanged.
>
> I'm on the way out the door to a family wedding (this won't be anywhere
> near as much fun as our daughter's wedding in Dublin this past June --
> that was five days of parties!), but fun nonetheless !
>
> As you'll quickly see, this doc needs a lot of editing. More than that,
> it needs people with more OAuth2 knowledge than me working on it. I'm
> also not completely sure that I may be operating with out-of-date
> assumptions. For instance, a couple of years ago most Native Apps were
> using OAuth2 to authenticate users -- is that still true ? The current
> recommendation for Native Apps seems to be to use "Authorization Code
> Grant Type with PKCE (Proof Key for Code Exchange)" -- do apps really
> use that ?
>
> The doc also leaves too many open questions hanging ... again, here's
> hoping that people with more knowledge and more current knowledge can
> improve the doc.
>
> Here's hoping people have a chance to review this, mark it up, improve
> it, and perhaps discuss it on the next call. Unfortunately, I'll miss
> the next call. Sorry.
>
>
>




Archive powered by MHonArc 2.6.19.

Top of Page