Skip to Content.
Sympa Menu

oidc-survey - Re: Quick notes from today's OIDC Survey meeting

Subject: OIDC Survey Working Group

List archive

Re: Quick notes from today's OIDC Survey meeting


Chronological Thread 
  • From: Patrick Radtke <>
  • To: Eric Goodman <>
  • Cc: "" <>
  • Subject: Re: Quick notes from today's OIDC Survey meeting
  • Date: Fri, 30 Sep 2016 10:32:41 -0700
  • Ironport-phdr: 9a23:inYuJxQzZmYw7QcjJQSSQrdxJ9psv+yvbD5Q0YIujvd0So/mwa64ZByN2/xhgRfzUJnB7Loc0qyN7PCmBDdLuMvJmUtBWaIPfidNsd8RkQ0kDZzNImzAB9muURYHGt9fXkRu5XCxPBsdMs//Y1rPvi/6tmZKSV3XfDB4LeXtG4PUk9//l6Xro8WSME10g2+Qe7J5ZDqxqgnUv89e1aZ4K6135RzOrn5BfcxLzmRwY1+fgkCvyN23+ctb+jhKuvkiv/RJXbn5cuxsVbVEFjUtMEg+5dfxqALCQQaJ+noAQyMdlR8eUFuN1w3zQpqk6niyjeF6wiTPeJSuFb0=

On Fri, Sep 30, 2016 at 10:12 AM, Eric Goodman
<>
wrote:
> Maybe beyond the scope of this survey, but I’m wondering if the AAF approach
> presented is a good model: standardize the communication between the proxy
> and the application and put support for that layer of communication in the
> various application libraries, but still leave the protocol handling outside
> of the application.

I was expecting the majority of use cases to be driven by mobile apps
and API access. For mobile - proxying and REMOTE_USER aren't going to
be available as options. For API access, there may be some
possibilities - similar to how people off load token validation to an
API gateway - however fine grain access decisions need knowledge of
both the data being acted on, the user, and the scopes present in the
token and that is only exists within the app, and not at the api
gateway or proxy level.

I wonder, if the proxy approach *is* suitable then why are certain
groups wanting OIDC? From their application's perspective REMOTE_USER
is getting set whether it was a SAML authentication or OIDC. Is it
that the SAML SP on boarding process for their institution is
cumbersome/hard to understand/not cool/takes weeks/etc? Or is there
something fundamental about what they want to do that makes the proxy
not suitable?

-Patrick



Archive powered by MHonArc 2.6.19.

Top of Page