Yearly Archives: 2013


Review of Proposed Final OpenID Connect Specifications and Implementer’s Drafts

The OpenID Connect Working Group recommends approval of the following specifications as Final OpenID Specifications: OpenID Connect Core – Defines the core OpenID Connect functionality: authentication built on top of OAuth 2.0 and the use of Claims to communicate information about the End-User. OpenID Connect Discovery – Defines how Relying […]


Login to Your Salesforce Org with OpenID Connect in Winter ’14

The Winter ’14 release includes OpenID Connect Authentication Providers, allowing your org to be an OpenID Connect Client, and leverage an Authorization Server for user login. Let’s take a look at how this works: If you want to walk through the protocol in detail, there’s an excellent, detailed description on Google’s […]


Vulnerability Alert – OpenID 2.0 Implementations Vulnerabilities found in some OPs 5

Please be advised a number of OpenID Authentication 2.0 server implementations were found to be vulnerable due to non-compliance to the normative requirements of the OpenID Authentication 2.0 specification. The nature of the vulnerability In section 11.4.2.1 of the OpenID Authentication 2.0, it is stated that “For verifying signatures an […]


Second OpenID Connect Implementer’s Drafts Approved 7

The OpenID membership has approved the following specifications as OpenID Implementer’s Drafts in the vote held from July 23 and July 30, 2013: Basic Client Profile – Simple, self-contained profile for a Web-based Relying Parties using the OAuth code flow. Implicit Client Profile – Simple, self-contained profile for a Web-based […]


Vote for Second OpenID Connect Implementer’s Drafts is Open

Please vote now at https://openid.net/foundation/members/polls/68. The vote is open between July 23 and July 30, 2013. The OpenID Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts: • Basic Client Profile – Simple, self-contained profile for a Web-based Relying Parties using the OAuth code flow. • […]


[seminar] Simplifying Enterprise IdM – OpenID Connect and SCIM

OpenID Foundation Japan’s Enterprise identity working group (EIWG) will host the following seminar. The working group is a joint working group with Japan Network Security Association’s Identity Management WG. Date: July 4, 2013 Time: 14:00-17:00 Venue: Nomura Research Institute, Marunouchi Centre 9F. (Tokyo) Entrance: Free Capacity: 100 Langauge: Japanese Cloud […]