Comment by caust1c
Comment by caust1c 2 months ago
I know very little about XML and SAML, but from what little I do know it shocks me that it's still the de-facto standard for SSO.
Great analysis and thanks for sharing!
Comment by caust1c 2 months ago
I know very little about XML and SAML, but from what little I do know it shocks me that it's still the de-facto standard for SSO.
Great analysis and thanks for sharing!
I'm optimistic SAML will be dead soon. ActiveDirectory/EntraID/whatever Microsoft wants to call it now supports OpenID Connect. Okta, OneLogin, Google, and all the other post-turn-of-the-millenium IdPs support OIDC. Shibboleth is the last major IdP I know if that is SAML-only, and I haven't seen anyone using it in like 10 years. When I built enterprise SSO for my current company, we went OIDC-only and we haven't had a single customer who needed SAML.
> Shibboleth is the last major IdP I know if that is SAML-only, and I haven't seen anyone using it in like 10 years
Most universities are still using Shibboleth. And probably will be forever. I think Shibboleth influenced SAML, probably to it's detriment.
> Shibboleth is the last major IdP I know if that is SAML-only
Shibboleth has officially supported Plugins for OIDC for some time now.
As others said, Shiboleth is still rather pupular at Universities and higher Education, OIDC will have a hard time to set foot there without the OpenID Connect Federation Draft beeing finished and then Implemented by the different Metadata Federation that exist (most National Research Networks manage one)
Okta barely supports OIDC I'm afraid. We have to use SAML with them because they don't support a reusable app model for OIDC (a "marketplace app" that multiple customers can use).
I'd love to add FastFed support for OIDC and be done with it but SAML still rules the world.
Our app <https://www.okta.com/integrations/conductorone/> is in the Okta OIN ("marketplace") using OIDC? So not sure what you mean by that?
It should not be, and people should use OIDC in preference to it wherever they can.