3 ms·
> Oh yes, throw out OIDC and let's go back to SAML. Aside from tptacek's observation: What prohibits the development of an OpenID Connect PASETO variant? (This
by CiPHPerCoder 7y ago
> Oh yes, throw out OIDC and let's go back to SAML.
Aside from tptacek's observation: What prohibits the development of an OpenID Connect PASETO variant? (This is a rhetorical question.)
- sascha_sl 7y agoAdoption? Standardization? Not everything is a green field. Yes, I get to deal with SAML a lot, and with how quirky and incomplete and outright non-standard compliant some implementations, particularly for SaaS services are (and how there are always guides for Auth0, Otka and maybe ADFS, but never in plan SAML 2.0 terms), but we also use OIDC for a few more modern services, like Kubernetes and our own proxy and the amount of troubleshooting required has been essentially zero.
- CiPHPerCoder 7y ago> Adoption? Standardization? Working on that. One of the goals of the PASETO project is to eliminate the use of JWT in modern standards, not to eliminate the standards that currently (but hopefully, temporarily) use JWT.