Difference between revisions of "Federation"
|Line 5:||Line 5:|
Revision as of 10:51, 10 April 2021
Full Title or Meme
Wherever a collection of Web Sites band together to create a common set of rules that all agree to be bound by.
- Most Identity Management systems are constructed to work with a range of publicly accessible sites that do not have all of the security protections that are required in high value transactions.
- OpenID Connect Federation 1.0 - draft 10
The OpenID Connect standard specifies how a Relying Party (RP) can discover metadata about an OpenID Provider (OP), and then register to obtain RP credentials. The Provider Discovery and registration process does not involve any mechanisms of dynamically establishing trust in the exchanged information, but instead rely on out-of-band trust establishment. In an identity federation context, this is not sufficient. The participants of the federation must be able to trust information provided about other participants in the federation. OpenID Connect Federations specifies how trust can be dynamically obtained by resolving trust from a common trusted third party.