Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-07 Thread Roland Hedberg
Count me in ! > 7 apr. 2016 kl. 01:17 skrev Nov Matake : > > I'm interested in too. > > nov > > On Apr 7, 2016, at 07:14, Mike Jones wrote: > >> For the record, I’m interested. >> >> From: scim [mailto:scim-boun...@ietf.org] On Behalf Of

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Nov Matake
I'm interested in too. nov > On Apr 7, 2016, at 07:14, Mike Jones wrote: > > For the record, I’m interested. > > From: scim [mailto:scim-boun...@ietf.org] On Behalf Of Hardt, Dick > Sent: Tuesday, April 5, 2016 7:26 PM > To: Phil Hunt (IDM)

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Mike Jones
For the record, I’m interested. From: scim [mailto:scim-boun...@ietf.org] On Behalf Of Hardt, Dick Sent: Tuesday, April 5, 2016 7:26 PM To: Phil Hunt (IDM) Cc: s...@ietf.org; oauth@ietf.org Subject: Re: [scim] Simple Federation Deployment I’m talking about removing manual

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Ian Glazer
I'd be interested too On Tue, Apr 5, 2016 at 5:59 PM, Hardt, Dick wrote: > Use case: An admin for an organization would like to enable her users to > access a SaaS application at her IdP. > > User experience: > >1. Admin authenticates to IdP in browser >2. Admin selects

Re: [OAUTH-WG] [scim] Simple Federation Deployment server to server

2016-04-06 Thread Brian Campbell
g as well. Definitely interested. > > > > -gil > > > > *From:* OAuth [mailto:oauth-boun...@ietf.org <oauth-boun...@ietf.org>] *On > Behalf Of *Nat Sakimura > *Sent:* Wednesday, April 6, 2016 4:57 PM > *To:* 'Hardt, Dick' <d...@amazon.com>; 'Phil Hunt (IDM)' &

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Phil Hunt
, Dick' <d...@amazon.com <mailto:d...@amazon.com>>; 'Phil Hunt >> (IDM)' <phil.h...@oracle.com <mailto:phil.h...@oracle.com>> >> Cc: s...@ietf.org <mailto:s...@ietf.org>; oauth@ietf.org >> <mailto:oauth@ietf.org> >> Subject: Re: [OAU

Re: [OAUTH-WG] [scim] Simple Federation Deployment server to server

2016-04-06 Thread Anthony Nadalin
l Hunt (IDM)' <phil.h...@oracle.com<mailto:phil.h...@oracle.com>> Cc: s...@ietf.org<mailto:s...@ietf.org>; oauth@ietf.org<mailto:oauth@ietf.org> Subject: Re: [OAUTH-WG] [scim] Simple Federation Deployment +1 for removing the manual cut-n-pastes! Nat -- PLEASE READ

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Anthony Nadalin
at Sakimura Sent: Wednesday, April 6, 2016 4:57 PM To: 'Hardt, Dick' <d...@amazon.com>; 'Phil Hunt (IDM)' <phil.h...@oracle.com> Cc: s...@ietf.org; oauth@ietf.org Subject: Re: [OAUTH-WG] [scim] Simple Federation Deployment +1 for removing the manual cut-n-pastes! Nat -- PLEASE READ :This e

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Gil Kirkpatrick
uth@ietf.org Subject: Re: [OAUTH-WG] [scim] Simple Federation Deployment +1 for removing the manual cut-n-pastes! Nat -- PLEASE READ :This e-mail is confidential and intended for the named recipient only. If you are not an intended recipient, please notify the sender and delete this e-ma

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-06 Thread Nat Sakimura
+1 for removing the manual cut-n-pastes! Nat -- PLEASE READ :This e-mail is confidential and intended for the named recipient only. If you are not an intended recipient, please notify the sender and delete this e-mail. From: scim [mailto:scim-boun...@ietf.org] On Behalf Of Hardt,

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-05 Thread Phil Hunt (IDM)
There may be some similar concerns on our side. Lets talk more this week. Phil > On Apr 5, 2016, at 19:25, Hardt, Dick wrote: > > I’m talking about removing manual steps in what happens today where > configuring a SaaS app at an IdP (such as Google, Azure, Ping, Octa)

Re: [OAUTH-WG] [scim] Simple Federation Deployment

2016-04-05 Thread Phil Hunt (IDM)
Is the idp the center of all things for these users? Usually you have a provisioning system that coordinates state and uses things like scim connectors to do this. Another approach from today would be to pass a scim event to the remote provider which then decides what needs to be done to