Uploaded image for project: 'Shibboleth User Interface'
  1. Shibboleth User Interface
  2. SHIBUI-2380

Add support for creating and maintaining OIDC Metadata

    XMLWordPrintable

Details

    • Story
    • Resolution: Done
    • Minor
    • None
    • None
    • None

    Description

      MOIDC support will be part of the distributed IdP with v4.1

      Note:  You need to use the "profile of SAML metadata for OIDC", not the JSON format, if you want to take advantage of metadata-driven relying party overrides, embedded entity attributes to drive attribute release etc.

      Additional Information:

      • OIDC metadata:  OPMetadataClientRegistration
      • Many of the same overrides, and a similar approach to controlling attributes released, can apply to OIDC integrations.
      • University of Illinois is very interested in this functionality being included in SHIBUI.  They currently use OIDC metadata and have go generate the metadata by hand.

      Metadata Examples:

      https://shibboleth.atlassian.net/wiki/spaces/SC/pages/1912406916/OAuthRPMetadataProfile

      Attachments

        1.
        OIDC Research Sub-task Done Charles Hasegawa (unicon.net)

        0%

        Original Estimate - Not Specified Original Estimate - Not Specified
        Remaining Estimate - 4 hours
        2.
        UI - Add ability to Create OIDC Metadata Source Sub-task Done Ryan Mathis (unicon.net)  
        3.
        BACKEND Sub-task Done Charles Hasegawa (unicon.net)

        83%

        Original Estimate - Not Specified Original Estimate - Not Specified
        Time Spent - 4 days, 3 hours Remaining Estimate - 7 hours
        4.
        SET Sub-task Done Bill Smith (unicon.net)  
        5.
        QA Sub-task Done Doug Sonaty  
        6.
        Update tooltips on Metadata Source screens Sub-task Done Doug Sonaty  
        7.
        Authentication Protocol field is editable when editing an OIDC Metadata Source Sub-task Done Doug Sonaty  
        8.
        Undefined error being displayed when saving a metadata source with Element Type = clientSecretRef Sub-task Done Doug Sonaty  
        9.
        Error occurs when copying an OIDC metadata source Sub-task Done Doug Sonaty  
        10.
        Audience value not being saved for OIDC metadata sources Sub-task Done Doug Sonaty  
        11.
        Request Object Encryption Encoding field is misspelled Sub-task Done Doug Sonaty  
        12.
        Research overrides and controlling attributes for OIDC Sub-task Done Doug Sonaty  
        13.
        Remove Client Secret/Client Secret Ref Sub-task Done Doug Sonaty  
        14.
        Group's URL Validation Regex error message no longers displays Sub-task Done Bill Smith (unicon.net)  
        15.
        400 returned when attempting to compare Metadata Source versions with x509 certs Sub-task Done Bill Smith (unicon.net)  
        16.
        Previously created Metadata Sources' Protocols not appearing on Dashboard Sub-task Done Doug Sonaty  
        17.
        Fix tooltips for OIDC Relying Party Overrides Sub-task Done Doug Sonaty  
        18.
        OIDC Relying Party Overrides Booleans should have a default value of true Sub-task Done Doug Sonaty  
        19.
        Values for Security Configuration and Ignore any SP-Requested Authentication Method? are not being displayed on configuration screen Sub-task Done Doug Sonaty  
        20.
        Copying OIDC metadata sources shows SAML attributes before saving Sub-task Done Doug Sonaty  

        Activity

          People

            steven.erickson@at.internet2.edu Steven Erickson (unicon.net)
            steven.erickson@at.internet2.edu Steven Erickson (unicon.net)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Time Spent - 1 week, 1 day, 1 hour, 2 minutes Remaining Estimate - 2 days, 2 hours
                2d 2h
                Logged:
                Time Spent - 1 week, 1 day, 1 hour, 2 minutes Remaining Estimate - 2 days, 2 hours
                1w 1d 1h 2m