Re: FAS password on 3rd party pages?

2013-04-28 Thread Patrick Uiterwijk
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Fri, Apr 26, 2013 at 01:57:17PM -0500, Bruno Wolff III wrote: If we used SAML, the IdP can provide group membership information which could be used by SPs for authz. Our OpenID implementation does this as well with the teams extension, and

Re: FAS password on 3rd party pages?

2013-04-26 Thread Vít Ondruch
Dne 25.4.2013 20:31, Kevin Fenzi napsal(a): On Thu, 25 Apr 2013 09:11:00 -0400 seth vidal skvi...@fedoraproject.org wrote: Well I think the idea is simple enough - if there is one, branded and obvious login page - and that page is openid then we're not training our users to type their

Re: FAS password on 3rd party pages?

2013-04-26 Thread Toshio Kuratomi
On Thu, Apr 25, 2013 at 11:31 AM, Kevin Fenzi ke...@scrye.com wrote: On Thu, 25 Apr 2013 09:11:00 -0400 seth vidal skvi...@fedoraproject.org wrote: Well I think the idea is simple enough - if there is one, branded and obvious login page - and that page is openid then we're not training

Re: FAS password on 3rd party pages?

2013-04-26 Thread Bruno Wolff III
On Fri, Apr 26, 2013 at 11:10:33 -0700, Toshio Kuratomi a.bad...@gmail.com wrote: On Thu, Apr 25, 2013 at 11:31 AM, Kevin Fenzi ke...@scrye.com wrote: Yeah, with emphasis on the once other things have moved over, I could probably agree with this. There are some bumpy spots though -- for

Re: FAS password on 3rd party pages?

2013-04-26 Thread Toshio Kuratomi
On Fri, Apr 26, 2013 at 01:57:17PM -0500, Bruno Wolff III wrote: On Fri, Apr 26, 2013 at 11:10:33 -0700, Toshio Kuratomi a.bad...@gmail.com wrote: On Thu, Apr 25, 2013 at 11:31 AM, Kevin Fenzi ke...@scrye.com wrote: Yeah, with emphasis on the once other things have moved over, I could

Re: FAS password on 3rd party pages?

2013-04-26 Thread Pierre-Yves Chibon
On Fri, 2013-04-26 at 13:57 -0500, Bruno Wolff III wrote: If we used SAML, the IdP can provide group membership information which could be used by SPs for authz. I didn't know what SAML was yesterday, so I checked out wiki which says: The single most important problem that SAML addresses is

Re: FAS password on 3rd party pages?

2013-04-25 Thread Pierre-Yves Chibon
On Thu, 2013-04-25 at 10:07 +0200, Vít Ondruch wrote: Hi guys, Since you want to push Fedocal and Blocker tracking into production, would you mind to change you login forms, that I don't have to enter my FAS password into your application dialog boxes? Although I understand that they are

Re: FAS password on 3rd party pages?

2013-04-25 Thread Vít Ondruch
Dne 25.4.2013 10:09, Pierre-Yves Chibon napsal(a): On Thu, 2013-04-25 at 10:07 +0200, Vít Ondruch wrote: Hi guys, Since you want to push Fedocal and Blocker tracking into production, would you mind to change you login forms, that I don't have to enter my FAS password into your application

Re: FAS password on 3rd party pages?

2013-04-25 Thread Pierre-Yves Chibon
On Thu, 2013-04-25 at 10:31 +0200, Vít Ondruch wrote: Dne 25.4.2013 10:09, Pierre-Yves Chibon napsal(a): On Thu, 2013-04-25 at 10:07 +0200, Vít Ondruch wrote: Hi guys, Since you want to push Fedocal and Blocker tracking into production, would you mind to change you login forms, that I

Re: FAS password on 3rd party pages?

2013-04-25 Thread Vít Ondruch
Dne 25.4.2013 10:57, Pierre-Yves Chibon napsal(a): On Thu, 2013-04-25 at 10:31 +0200, Vít Ondruch wrote: Dne 25.4.2013 10:09, Pierre-Yves Chibon napsal(a): On Thu, 2013-04-25 at 10:07 +0200, Vít Ondruch wrote: Hi guys, Since you want to push Fedocal and Blocker tracking into production,

Re: FAS password on 3rd party pages?

2013-04-25 Thread Tim Flink
On Thu, 25 Apr 2013 10:07:25 +0200 Vít Ondruch vondr...@redhat.com wrote: Hi guys, Since you want to push Fedocal and Blocker tracking into production, would you mind to change you login forms, that I don't have to enter my FAS password into your application dialog boxes? Although I

Re: FAS password on 3rd party pages?

2013-04-25 Thread seth vidal
On Thu, 25 Apr 2013 10:57:54 +0200 Pierre-Yves Chibon pin...@pingoured.fr wrote: On Thu, 2013-04-25 at 10:31 +0200, Vít Ondruch wrote: Dne 25.4.2013 10:09, Pierre-Yves Chibon napsal(a): On Thu, 2013-04-25 at 10:07 +0200, Vít Ondruch wrote: Hi guys, Since you want to push Fedocal

Re: FAS password on 3rd party pages?

2013-04-25 Thread Kevin Fenzi
On Thu, 25 Apr 2013 09:11:00 -0400 seth vidal skvi...@fedoraproject.org wrote: Well I think the idea is simple enough - if there is one, branded and obvious login page - and that page is openid then we're not training our users to type their passwords into random websites. Right. I think this

Re: FAS password on 3rd party pages?

2013-04-25 Thread Bruno Wolff III
On Thu, Apr 25, 2013 at 12:31:54 -0600, Kevin Fenzi ke...@scrye.com wrote: On Thu, 25 Apr 2013 09:11:00 -0400 seth vidal skvi...@fedoraproject.org wrote: Well I think the idea is simple enough - if there is one, branded and obvious login page - and that page is openid then we're not training

Re: FAS password on 3rd party pages?

2013-04-25 Thread Chris Dix
SAML is indeed one method of passing a secure token to another app/service. Implementing SSO would probably be a great move forward to consolidate your source of truth for Fedora users in one location. Whatever mechanism you choose to use to implement SSO, you need to consider the ease to