IyaSec Blog

Notes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.

Identity Broker: An SSO Protocol Transition From OpenID Connect To WS-Federation

  • Federation
  • Identity Providers
  • OpenID Connect

I’ve been building up to more complex federation use cases over the past year. In previous posts, we explored the details of OpenID Connect(OIDC) and WS-Federation (WS-Fed). In those posts, we covered basic scenarios of how to use each protocol to integrate one Relying Party (Service Provider,…

Read article: Identity Broker: An SSO Protocol Transition From OpenID Connect To WS-Federation

The Tale of Thomas, Richard, and Karen — A Software Architecture Parable

  • War Stories
  • Integration

It so happened that one day, in a corporate IT department not unlike the one you are familiar with, three IT resources were preparing to design a software system. It doesn’t much matter what the system is or what it is supposed to do, for the results would be more-or-less the same. The assembled…

Read article: The Tale of Thomas, Richard, and Karen — A Software Architecture Parable

Differences Between Azure Active Directory and Red Hat SSO v7.1

  • 3Scale
  • Active Directory
  • API Management

I recently finished implementing OAuth2 and OIDC support for Azure Active Directory in my OAuth2 + OIDC Debugger. Previously, we implemented support for Red Hat SSO v7.1 and 3Scale. This post compares the two product’s implementations of these protocols (OAuth2 and OIDC). In particular, it looks at…

Read article: Differences Between Azure Active Directory and Red Hat SSO v7.1

Looking for something specific? Browse all 124 topics.