5 ms·
> I don't get why OpenID was introduced in the first place then. Because the Internet needs standards to work. If all domains implement authentication differen
by willow9886 9y ago
> I don't get why OpenID was introduced in the first place then.
Because the Internet needs standards to work. If all domains implement authentication differently, we do not have an interoperable network.
As is customary, standards must evolve to keep up with requirements. OpenID 1 and 2 weren't built with the idea that smart phones would be in every persons pocket, or Internet connected devices in every home.
The latest iteration of OpenID--OpenID Connect--is essentially Google's playbook for authentication. It's of huge value to the rest of the world.
To put it simply: having your own OpenID Provider at your domain (e.g. idp.example.com) allows you to operate a similar authentication infrastructure as Google.
What does that mean?
- Single sign-on (SSO) across web and mobile applications
- Ability to support a variety of strong authentication mechanisms (a.k.a 2FA), like U2F security keys and OTP mobile apps, in one place for many apps
If all apps and services were to align with OpenID Connect, we would have a truly scalable and interoperable identity layer for the Internet.
- icebraining 9y agoBut what's the point of OpenID Connect being interoperable, if unlike in OpenID, the providers are statically defined by the site and not dynamically discovered from the user input? If you want to have your own provider for your own sites, then you don't need it to be interoperable.
- willow9886 9y agoOpenID Connect defines two important standards: Discovery [1] and Dynamic Registration [2]. All OpenID Providers publish their details at a publicly discoverable (and standard) domain: https://{hostname}/.well-known/openid-configuration https://{hostname}/.well-known/openid-configuration. For instance, you can see our OP meta data here [3]. This provides the foundation for using email as an identifier, i.e. in order to access protected resource at autonomous site, input email at a domain with an OP, and the RP can perform discovery to find where to send the user for authentication, and dynamic registration to register their client (app) with the OP to obtain user information ("claims"). [1] https://openid.net/specs/openid-connect-discovery-1_0.html https://openid.net/specs/openid-connect-discovery-1_0.html [2] https://openid.net/specs/openid-connect-registration-1_0.html https://openid.net/specs/openid-connect-registration-1_0.htm... [3] https://idp.gluu.org/.well-known/openid-configuration https://idp.gluu.org/.well-known/openid-configuration
- icebraining 9y agoIt's nice that the support is there, but are there any sites actually using it? My concern is that default matter - ie, if you make it easier to just support a few fixed servers, that's what will generally happen.
- willow9886 9y agoMany sites are doing identifier first authentication, incuding google. When you login to google, it prompts you for an email address first. If your email is associated with an organization that has configured Google Apps to use their OP for authentication, Google will redirect the user to their home domain based on the email.
- Promarged 9y ago> For instance, you can see our OP meta data here [3]. Do you e-mails end with @idp.gluu.org? Or how would the RP discover that the domain is not "gluu.org" but "idp.gluu.org"?
- willow9886 9y agono, but using my email adress @gluu.org, you can find the discovery endpoint because its a standard address for domains. For instance, here's Google's OP discovery endpoint: https://accounts.google.com/.well-known/openid-configuration https://accounts.google.com/.well-known/openid-configuration
- vertex-four 9y agoHow do I find that discovery endpoint, given your email address @gluu.org? https://gluu.org/.well-known/openid-configuration https://gluu.org/.well-known/openid-configuration doesn't exist. I don't even know that idp.gluu.org is a thing from your email address.
- vertex-four 9y ago> All OpenID Providers publish their details at a publicly discoverable (and standard) domain: https://{hostname}/.well-known/openid-configuration https://{hostname}/.well-known/openid-configuration. No, no they don’t. Not by far. Google, for example, doesn’t - and even if they did, it wouldn’t be useful, as they don’t support dynamic client registration either, as they want lock-in. Being able to type in my email address into a generic widget and get the Google auth dialog is specifically what they don’t want. Facebook has the same issue, as does Yahoo. I don’t think I know of a single implementer of OpenID Discovery and Dynamic Client Registration - the only purpose of OpenID Connect as deployed in the wild is to share development resources, not to create a system where people can type in their email address into a generic widget which works for every OpenID Connect supporting domain off the shelf with no RP-side configuration and get a login form.