<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns:mv="http://macVmlSchemaUri" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Title" content="">
<meta name="Keywords" content="">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.msoIns
{mso-style-type:export-only;
mso-style-name:"";
text-decoration:underline;
color:teal;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">Anyone disagree with the tenet under discussion?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> # Tenet 4) Push Implementation Complexity onto IdPs<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">The discussion has been about the numbers and ratios, but returning to the main question: if we face a choice between pushing implementation complexity onto an IdP implementer
vs a SP implementer, does anyone disagree about pushing complexity onto the IdP implementer?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">The IdP _<i>administrator</i>_ (as opposed to the implementer) is also important. When using a hosted provider, the admin should see FastFed capabilities “just appear” when
the provider launches it. Admins running their own installation will upgrade to a newer release to get the capabilities. The heavy lifting has been done by their chosen vendor.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-family:"Calibri",sans-serif;color:black">From:
</span></b><span style="font-family:"Calibri",sans-serif;color:black">Openid-specs-fastfed <openid-specs-fastfed-bounces@lists.openid.net> on behalf of "openid-specs-fastfed@lists.openid.net" <openid-specs-fastfed@lists.openid.net><br>
<b>Organization: </b>Gluu<br>
<b>Reply-To: </b>Mike Schwartz <mike@gluu.org><br>
<b>Date: </b>Wednesday, June 7, 2017 at 1:48 PM<br>
<b>To: </b>"Hardt, Dick" <dick@amazon.com><br>
<b>Cc: </b>"openid-specs-fastfed@lists.openid.net" <openid-specs-fastfed@lists.openid.net><br>
<b>Subject: </b>Re: [Openid-specs-fastfed] FastFed Requirements<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">I agree that IdP vendors < SaaS providers; I don't agree that IdP's <
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">SaaS providers. But if we're talking about admins, why aren't we valuing
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">IdP admins?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Regarding the ratio... what we find is that the minority of SaaS
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">providers support inbound SAML (and almost none support inbound OpenID
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Connect). That's why so many SSO services are still pushing passwords.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Generally, SaaS providers get serious about supporting SAML when they
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">get a critical mass of requests from their customers. At that point,
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">they can justify the SAML investment. So it's mostly just the larger
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">SaaS providers. Even fewer support OpenID Connect (almost none, Amazon
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">being one of the exceptions).<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">- Mike<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">On 2017-06-07 15:06, Hardt, Dick wrote:<o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in" id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<p class="MsoNormal">On 6/7/17, 12:38 PM, someone claiming to be "Openid-specs-fastfed on<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">behalf of <a href="mailto:openid-specs-fastfed@lists.openid.net">
openid-specs-fastfed@lists.openid.net</a>"<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><<a href="mailto:openid-specs-fastfed-bounces@lists.openid.net">openid-specs-fastfed-bounces@lists.openid.net</a> on behalf of<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><a href="mailto:openid-specs-fastfed@lists.openid.net">openid-specs-fastfed@lists.openid.net</a>> wrote:<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> More organizations have IDPs then SaaS providers support federated<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> authentication. Frankly, SaaS providers only support federated
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">authn<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> when they get enough demand from customers, which sort of speaks to
<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">the<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> ratio I am positing.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Mike: I’m confused what ratio you are implying here. Would you clarify?<o:p></o:p></p>
</div>
</blockquote>
<div>
<p class="MsoNormal">_______________________________________________<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">Openid-specs-fastfed mailing list<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><a href="mailto:Openid-specs-fastfed@lists.openid.net">Openid-specs-fastfed@lists.openid.net</a><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><a href="http://lists.openid.net/mailman/listinfo/openid-specs-fastfed">http://lists.openid.net/mailman/listinfo/openid-specs-fastfed</a><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</body>
</html>