Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Add items for discussion here

Attendees:

Brent

Daniel

  • Merging ldaptive v2 into IDP v5

    • waiting until v5 main branch work settles down

Henri

The current non-resolved issues for OP 3.2:

  • Regarding refresh tokens:

    • Jira Legacy
      serverSystem JIRA
      serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
      keyJOIDC-90

    • Jira Legacy
      serverSystem JIRA
      serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
      keyJOIDC-92

    • Almost there, some final polishings / documentation to do

  • Jira Legacy
    serverSystem JIRA
    serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
    keyJOIDC-6

    • Helper-function for scripts and example via attribute resolver service now exists

  • Jira Legacy
    serverSystem JIRA
    serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
    keyJOIDC-112

    • Technically not complicated, but still needs some thoughtswill probably use PROTOCOL_MESSAGE.OAUTH2

  • Jira Legacy
    serverSystem JIRA
    serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
    keyJOIDC-7

    • No known issues, I’ve run some tests for both OAUTH2.Token and OAUTH2.TokenAudience profiles

The plan is to release OP 3.2 and common 2.1 during the last week of June.

Ian

John

  • Rocky Linux 9 forecast: “ready for general release in the June - July 2022 timeframe”

  • Vanishingly little progress on cpp-linbuild for Fargate since last time due to competing demands on my time

Marvin

Phil

  • Jira Legacy
    serverSystem JIRA
    serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
    keyJCOMOIDC-41
    RP updated to support Brent’s JOSE Header JWK resolver

  • Jira Legacy
    serverSystem JIRA
    serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506
    keyJCOMOIDC-45
    Added JWT decryption and signature validation support to UserInfo JWT (which could just be a plain JSON object)

    • Test certain modes against the OIDC certification OP

  • Improved the response_mode and response_type lookup from RP config

  • Added scopes to RP config, default obviously openid.

  • Added OIDC ACR proxy pass-through function from upstream SAML request (similar to SAML proxy)

  • Flow XML cleanups

  • More tests

...