4 ms·
OpenID Connect defines two important standards: Discovery [1] and Dynamic Registration [2]. All OpenID Providers publish their details at a publicly discoverab
by willow9886 9y ago
OpenID Connect defines two important standards: Discovery [1] and Dynamic Registration [2].
All OpenID Providers publish their details at a publicly discoverable (and standard) domain: https://{hostname}/.well-known/openid-configuration https://{hostname}/.well-known/openid-configuration.
For instance, you can see our OP meta data here [3].
This provides the foundation for using email as an identifier, i.e. in order to access protected resource at autonomous site, input email at a domain with an OP, and the RP can perform discovery to find where to send the user for authentication, and dynamic registration to register their client (app) with the OP to obtain user information ("claims").
[1] https://openid.net/specs/openid-connect-discovery-1_0.html https://openid.net/specs/openid-connect-discovery-1_0.html
[2] https://openid.net/specs/openid-connect-registration-1_0.html https://openid.net/specs/openid-connect-registration-1_0.htm...
[3] https://idp.gluu.org/.well-known/openid-configuration https://idp.gluu.org/.well-known/openid-configuration
- icebraining 9y agoIt's nice that the support is there, but are there any sites actually using it? My concern is that default matter - ie, if you make it easier to just support a few fixed servers, that's what will generally happen.
- willow9886 9y agoMany sites are doing identifier first authentication, incuding google. When you login to google, it prompts you for an email address first. If your email is associated with an organization that has configured Google Apps to use their OP for authentication, Google will redirect the user to their home domain based on the email.
- Promarged 9y ago> For instance, you can see our OP meta data here [3]. Do you e-mails end with @idp.gluu.org? Or how would the RP discover that the domain is not "gluu.org" but "idp.gluu.org"?
- willow9886 9y agono, but using my email adress @gluu.org, you can find the discovery endpoint because its a standard address for domains. For instance, here's Google's OP discovery endpoint: https://accounts.google.com/.well-known/openid-configuration https://accounts.google.com/.well-known/openid-configuration
- vertex-four 9y agoHow do I find that discovery endpoint, given your email address @gluu.org? https://gluu.org/.well-known/openid-configuration https://gluu.org/.well-known/openid-configuration doesn't exist. I don't even know that idp.gluu.org is a thing from your email address.
- vertex-four 9y ago> All OpenID Providers publish their details at a publicly discoverable (and standard) domain: https://{hostname}/.well-known/openid-configuration https://{hostname}/.well-known/openid-configuration. No, no they don’t. Not by far. Google, for example, doesn’t - and even if they did, it wouldn’t be useful, as they don’t support dynamic client registration either, as they want lock-in. Being able to type in my email address into a generic widget and get the Google auth dialog is specifically what they don’t want. Facebook has the same issue, as does Yahoo. I don’t think I know of a single implementer of OpenID Discovery and Dynamic Client Registration - the only purpose of OpenID Connect as deployed in the wild is to share development resources, not to create a system where people can type in their email address into a generic widget which works for every OpenID Connect supporting domain off the shelf with no RP-side configuration and get a login form.
- willow9886 9y agoYes they do. See here: https://accounts.google.com/.well-known/openid-configuration https://accounts.google.com/.well-known/openid-configuration And as far as I know, Facebook doesn't support OpenID Connect. They still roll their own custom OAuth2 implementation.
- vertex-four 9y agoThat is, obviously, not on gmail.com. I cannot put in my email address into a generic widget and have that come up - the URL has to be hard-coded into the RP, and the RP additionally has to be configured with client authentication details. This document cannot be autodiscovered from a user identifier as per the spec, and provides absolutely nothing over hard-coding the configuration it contains.