8000 OpenID Federation implementation · Issue #40509 · keycloak/keycloak · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
OpenID Federation implementation #40509
Open
@cgeorgilakis

Description

@cgeorgilakis

Description

Implement OpenID Federation in Keycloak.
Documentation for implementation in Authlete is here.
Keycloak plugin for explicit registration based on older draft.

We propose realm admin being able to enable OpenID Federation (default false). When enabling, group admin could configure OpenID Federation (including required fields such as authority_hints. This will expose OpenID Federation metadata ( /.well-known/openid-federation ) and related functionality, fe explicit and automatic registration.

Our initial goal is supporting Keycloak being able to be OP and RP with both explicit and automatic registration.
However, epic is open for other OpenID Federation entities/ functionalities.

Discussion

#31027

Issues

Motivation

OpenID Federation enables participation in an identity federation of entities using OpenID Connect and OAuth 2.0 and offers a robust framework for establishing dynamic trust between OpenID Providers (OPs) and Relying Parties (RPs), significantly simplifying the management of large-scale identity federations. By leveraging this specification, Keycloak will enable the dynamic establishment of trust between OPs and RPs, facilitate secure interactions authenticated via Trust Anchors, and crucially, eliminate the need for cumbersome manual or bilateral trust agreements

< 5525 template>

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0