Federation
11 articles tagged Federation.
OpenID Federation Spec: Because Exchanging Metadata Spreadsheets Was Apparently Not a Great…
Or: How the Identity Industry Invented a Cryptographically Signed Phone Book
Read article: OpenID Federation Spec: Because Exchanging Metadata Spreadsheets Was Apparently Not a Great…Identity Protocols, Hosted Login UIs, and Custom Login UIs
There are many ways to implement user authentication in a modern application (mobile, desktop, tablet, web, etc). I have previously explored Authentication, Federation, and SSO; that post introduces several key concepts that are assumed here. At the intersection of user experience, authentication,…
Read article: Identity Protocols, Hosted Login UIs, and Custom Login UIsActive Directory Federation Services (ADFS) and Kerberos
While researching an upcoming blog post about Kerberos and Mobile, I needed to understand how Identity Providers (like ADFS or Ping Federate) use Kerberos (and possibly Kerberos Delegation) to perform authentication via username and password. This blog post captures what I found for ADFS.
Read article: Active Directory Federation Services (ADFS) and KerberosThe Common Identity Protocols
I’ve written blog posts on the following identity protocols. I’m creating this post to have a central place to refer to “identity protocols”. I will periodically update this list as I publish new posts with related material.
Read article: The Common Identity ProtocolsKerberos and Windows Security: History
In previous posts, we explored various identity protocols including OAuth2, OpenID Connect, SAML2 profiles, WS-Trust, and WS-Federation. This post continues our exploration of identity protocols by looking at the Kerberos v5 authentication protocol and its use in Microsoft Windows authentication. I…
Read article: Kerberos and Windows Security: HistoryIdentity Broker: An SSO Protocol Transition From OpenID Connect To WS-Federation
I’ve been building up to more complex federation use cases over the past year. In previous posts, we explored the details of OpenID Connect(OIDC) and WS-Federation (WS-Fed). In those posts, we covered basic scenarios of how to use each protocol to integrate one Relying Party (Service Provider,…
Read article: Identity Broker: An SSO Protocol Transition From OpenID Connect To WS-FederationUnderstanding WS-Federation — Passive Requestor Profile
There are several identity protocols that are commonly supported by Identity Providers today — OAuth2, OAuth2 Token Exchange, OIDC, SAML2 Browser Profile, WS-Trust, WS-Federation, etc. The OAuth2 and OIDC protocols are relative newcomers. The other protocols have been around longer — and, tend to…
Read article: Understanding WS-Federation — Passive Requestor ProfileAuthentication vs. Federation vs. SSO
Authentication. Federation. Single Sign On (SSO). I’ve mentioned these concepts many times. I haven’t actually formally defined what each of these terms mean even though I’ve used these many times throughout my writing — these concepts are closely related.
Read article: Authentication vs. Federation vs. SSOSAML v2.0 vs. JWT Series
This is a list of all the SAML2 vs JWT related posts I have written. This series explores SAML2 use cases, JWT use cases, the relevant specifications, and explores how the two technologies differ. The reader will see how identity federation technology has evolved over the past fifteen years.
Read article: SAML v2.0 vs. JWT Series








