OAuth 2.0 Token Exchange: When One Token Isn’t the Token You Need
The original three-legged OAuth2 use case has been a well-understood use case for a long-time.
Read article: OAuth 2.0 Token Exchange: When One Token Isn’t the Token You Need6 articles tagged Delegation.
The original three-legged OAuth2 use case has been a well-understood use case for a long-time.
Read article: OAuth 2.0 Token Exchange: When One Token Isn’t the Token You NeedDelegation is a concept that has always fascinated me in the identity space. It enables secure identity propagation with tokens (assertions, tickets, etc) being properly scoped. As functionality in my Identity Protocol Debugger has continued to evolve, I wanted to add a feature that would make it…
Read article: OAuth2 + OIDC + Delegation: An exampleThis blog post expands on delegation and related concepts introduced in my Kerberos Delegation blog post. It also brings together two blog series I’ve been working on over the years: SAML2 vs. JWT Series and Kerberos and Windows Security Series. Delegation is a critical building block of end-to-end…
Read article: Delegation — A General DiscussionIn this next post in the Kerberos and Windows Security Series, we are going to explore a very useful, but abstract feature of the Kerberos Authentication Protocol: Delegation. In particular, we are going to focus on the Windows implementation of this feature. Delegation allows downstream actors to…
Read article: Kerberos and Windows Security: DelegationWhile researching an upcoming blog post about Kerberos and Mobile, I needed to understand how Identity Providers (like ADFS or Ping Federate) use Kerberos (and possibly Kerberos Delegation) to perform authentication via username and password. This blog post captures what I found for ADFS.
Read article: Active Directory Federation Services (ADFS) and KerberosExtending OAuth2 and OpenID Connect as the enterprise standard for API security
Read article: An Alternative to Delegated Access in the Enterprise