SlideShare a Scribd company logo
OpenID Connect
vs. OpenID 1 & 2
3 important new features Connect
has that OpenID 1 & 2 didn’t.
What is OpenID?
● Open standard for authentication
● Developed by members of OpenID
Foundation
● Framework for the communication that
must take place between IDP & RP
Problems w/ OpenID 1 & 2
● URI’s as the identifier were too hard for
people to remember
● Not API & Mobile friendly
● No support for robust signing &
encryption
Enhancements to Connect
1) Discovery: provides a scalable way for
RP’s to allow people to authenticate via
any OpenID Connect Provider, not just
major IDP’s like Google & Facebook.
Enhancements to Connect
2) Email as the identifier: People never
have trouble remembering their email
addresses, and email is an intuitive way to
think about resource access (i.e. Am I
accessing business content? Ok, then I use
my business email creds).
Enhancements to Connect
3) Dynamic Client Registration: In order to
support the growing number of devices and
API’s using the web, Connect allows clients
to register dynamically, relieving admins of
the time-consuming task of explicitly
registering devices and websites.
Why Else is Connect Promising?
● Support from every major identity
provider including Google, MSFT, Yahoo
& Facebook.
● JSON / REST > XML
● OAuth2 already in use by 85%+ of
consumer social logins.
Gluu’s OpenID Connect Server
● oxAuth is the leading OpenID Connect
implementation in interop tests.
● 100% open source.
● Currently in production at large
organizations.
How to prepare for Connect
● People: Not much. Social login is already
ubiquitous on the net.
● Organizations: Launch an OpenID
Connect provider and discovery service.
● Developers: Add Connect to your
roadmap. Libraries already exist in Java,
Python, and other popular platforms.
More Resources
● Open ID Connect website: http:
//openid.net/connect/
● Open Source OX Wiki: http:
//ox.gluu.org
● Interop Test Results: http://osis.
idcommons.net/wiki/Category:
OC5_OP

More Related Content

PDF
Introduction to OpenID Connect
PDF
OpenID Connect Explained
PPTX
Intro to OAuth2 and OpenID Connect
PPTX
OpenID Connect: An Overview
PDF
OAuth 2.0 and OpenID Connect
PPT
OAuth 2.0 and OpenId Connect
PPTX
Blockchain Technology ppt project.pptx
PDF
OAuth 2.0
Introduction to OpenID Connect
OpenID Connect Explained
Intro to OAuth2 and OpenID Connect
OpenID Connect: An Overview
OAuth 2.0 and OpenID Connect
OAuth 2.0 and OpenId Connect
Blockchain Technology ppt project.pptx
OAuth 2.0

What's hot (20)

PPTX
An introduction to OAuth 2
PPTX
Tourists yatra guide (An android application)
PDF
Demystifying OAuth 2.0
PPTX
What's an api
PPTX
Secure your app with keycloak
PPTX
Ppt on blockchain technology
PPTX
module-1.pptx
PPTX
An Introduction to OAuth 2
PDF
Overview of blockchain technology and architecture
 
PPTX
Mit 2014 introduction to open id connect and o-auth 2
PDF
apidays LIVE Singapore - Next-generation microservice architecture based on A...
PDF
Okta docs
PPTX
Monetization: Unlock More Value from Your APIs
PPTX
BLOCKCHAIN
PPTX
Anatomy of an Enterprise Integration Architecture
PPTX
IBM APIc API security protection mechanism
PDF
What the Heck is OAuth and OpenID Connect - DOSUG 2018
PDF
Web 3.0 - A Detailed Guide
PPTX
Practical API Security - PyCon 2018
PPTX
OpenId Connect Protocol
An introduction to OAuth 2
Tourists yatra guide (An android application)
Demystifying OAuth 2.0
What's an api
Secure your app with keycloak
Ppt on blockchain technology
module-1.pptx
An Introduction to OAuth 2
Overview of blockchain technology and architecture
 
Mit 2014 introduction to open id connect and o-auth 2
apidays LIVE Singapore - Next-generation microservice architecture based on A...
Okta docs
Monetization: Unlock More Value from Your APIs
BLOCKCHAIN
Anatomy of an Enterprise Integration Architecture
IBM APIc API security protection mechanism
What the Heck is OAuth and OpenID Connect - DOSUG 2018
Web 3.0 - A Detailed Guide
Practical API Security - PyCon 2018
OpenId Connect Protocol
Ad

Viewers also liked (20)

PPTX
OpenID Connect and Single Sign-On for Beginners
PPT
Understanding OpenID
PPTX
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
PDF
OpenID Authentication by example
PPTX
BlueHat 2014 - The Attacker's View of Windows Authentication and Post Exploit...
PDF
OpenID Connect: The new standard for connecting to your Customers, Partners, ...
PPTX
Golden ticket, pass the ticket mi tm kerberos attacks explained
PDF
OpenID Bootcamp Tutorial
PPTX
Briforum 2011 Chicago
PDF
Cloud Identity: A Recipe for Higher Education
PPTX
RSA Europe: Future of Cloud Identity
PPTX
DaaS/IaaS Forum Moscow - Ivo Murris
PPT
ID Next 2013 Keynote Slides by Mike Schwartz
PPTX
RUCUG: 9. Sergey Khalyapin: Представляем XenDesktop 5
PDF
Who Are You? From Meat to Electrons - SXSW 2014
PPT
Mule security - saml
PPTX
BriForum 2013 Chicago - Citrix Troubleshooting - Denis Gundarev
PPTX
DaaS/IaaS Forum Moscow - Najat Messaoud
PPTX
DaaS/IaaS Forum Moscow - Chris Rogers
PPTX
The Tools I Use
OpenID Connect and Single Sign-On for Beginners
Understanding OpenID
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
OpenID Authentication by example
BlueHat 2014 - The Attacker's View of Windows Authentication and Post Exploit...
OpenID Connect: The new standard for connecting to your Customers, Partners, ...
Golden ticket, pass the ticket mi tm kerberos attacks explained
OpenID Bootcamp Tutorial
Briforum 2011 Chicago
Cloud Identity: A Recipe for Higher Education
RSA Europe: Future of Cloud Identity
DaaS/IaaS Forum Moscow - Ivo Murris
ID Next 2013 Keynote Slides by Mike Schwartz
RUCUG: 9. Sergey Khalyapin: Представляем XenDesktop 5
Who Are You? From Meat to Electrons - SXSW 2014
Mule security - saml
BriForum 2013 Chicago - Citrix Troubleshooting - Denis Gundarev
DaaS/IaaS Forum Moscow - Najat Messaoud
DaaS/IaaS Forum Moscow - Chris Rogers
The Tools I Use
Ad

Similar to OpenID Connect vs. OpenID 1 & 2 (20)

PDF
Improve identity management with open id
PDF
Review on OpenID Authentication Framework
PDF
Who’s Knocking? Identity for APIs, Web and Mobile
PDF
CIS13: Taking the Hyperspace Bypass: Controlling User Access to Other Worlds
PDF
LemonLDAP::NG - the New Generation WebSSO !, David Coutadeur, Linagora.
 
PPTX
Configuring Single Sign-On (SSO) via Identity Management | MuleSoft Mysore Me...
PPTX
OpenID Connect
PPTX
Unstoppable Domains Workshop
PDF
Implementing Microservices Security Patterns & Protocols with Spring
PDF
Managing micro services for your company
PDF
Optimizing your job apply pages with the LinkedIn profile API
PDF
CIS13: Identity at Scale
PDF
Open Banking beyond PSD2 in the EU
PPT
OpenID Progress EEMA Conference
PPTX
Achieving Predictable Success in Digital Transformation with the WSO2 Platform
PPTX
Blue Button 2.0
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
PDF
Api best practices
PDF
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
PPTX
Identity toolkit
Improve identity management with open id
Review on OpenID Authentication Framework
Who’s Knocking? Identity for APIs, Web and Mobile
CIS13: Taking the Hyperspace Bypass: Controlling User Access to Other Worlds
LemonLDAP::NG - the New Generation WebSSO !, David Coutadeur, Linagora.
 
Configuring Single Sign-On (SSO) via Identity Management | MuleSoft Mysore Me...
OpenID Connect
Unstoppable Domains Workshop
Implementing Microservices Security Patterns & Protocols with Spring
Managing micro services for your company
Optimizing your job apply pages with the LinkedIn profile API
CIS13: Identity at Scale
Open Banking beyond PSD2 in the EU
OpenID Progress EEMA Conference
Achieving Predictable Success in Digital Transformation with the WSO2 Platform
Blue Button 2.0
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Api best practices
EMFcamp2022 - What if apps logged into you, instead of you logging into apps?
Identity toolkit

More from Mike Schwartz (14)

PPTX
LASCON 2017: SAML v. OpenID v. Oauth
PPTX
OTTO - Internet2 TechX 2017
PPTX
The Client is not always right! How to secure OAuth authentication from your...
PPTX
LASCON: Three Profiels of OAuth2 for Identity and Access Management
PPTX
Kantara OTTO slides
PPTX
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
PPTX
RSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
PDF
Trust Elevation: Implementing an OAuth2 Infrastructure using OpenID Connect &...
PDF
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
PPTX
Federation registry
PPTX
Single Sign On 101
PPTX
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
PDF
Gluu EDU Webinar: Shibboleth/SAML SSO
PDF
SAML Protocol Overview
LASCON 2017: SAML v. OpenID v. Oauth
OTTO - Internet2 TechX 2017
The Client is not always right! How to secure OAuth authentication from your...
LASCON: Three Profiels of OAuth2 for Identity and Access Management
Kantara OTTO slides
RSA Conference 2016: Don't Use Two-Factor Authentication... Unless You Need It!
RSA Conference 2016: Who Are You? From Meat to Electrons and Back Again
Trust Elevation: Implementing an OAuth2 Infrastructure using OpenID Connect &...
OAuth2 for IoT Security: Why OpenID Connect & UMA Are They Key
Federation registry
Single Sign On 101
Requirements for Personal Clouds : Tech Ranch Talk 8/7/13
Gluu EDU Webinar: Shibboleth/SAML SSO
SAML Protocol Overview

Recently uploaded (20)

PDF
Advanced methodologies resolving dimensionality complications for autism neur...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
Cloud computing and distributed systems.
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Electronic commerce courselecture one. Pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PPT
Teaching material agriculture food technology
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
KodekX | Application Modernization Development
PDF
Encapsulation theory and applications.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Advanced methodologies resolving dimensionality complications for autism neur...
The AUB Centre for AI in Media Proposal.docx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Understanding_Digital_Forensics_Presentation.pptx
20250228 LYD VKU AI Blended-Learning.pptx
MYSQL Presentation for SQL database connectivity
Digital-Transformation-Roadmap-for-Companies.pptx
Cloud computing and distributed systems.
Network Security Unit 5.pdf for BCA BBA.
Electronic commerce courselecture one. Pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Teaching material agriculture food technology
Mobile App Security Testing_ A Comprehensive Guide.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
KodekX | Application Modernization Development
Encapsulation theory and applications.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...

OpenID Connect vs. OpenID 1 & 2

  • 1. OpenID Connect vs. OpenID 1 & 2 3 important new features Connect has that OpenID 1 & 2 didn’t.
  • 2. What is OpenID? ● Open standard for authentication ● Developed by members of OpenID Foundation ● Framework for the communication that must take place between IDP & RP
  • 3. Problems w/ OpenID 1 & 2 ● URI’s as the identifier were too hard for people to remember ● Not API & Mobile friendly ● No support for robust signing & encryption
  • 4. Enhancements to Connect 1) Discovery: provides a scalable way for RP’s to allow people to authenticate via any OpenID Connect Provider, not just major IDP’s like Google & Facebook.
  • 5. Enhancements to Connect 2) Email as the identifier: People never have trouble remembering their email addresses, and email is an intuitive way to think about resource access (i.e. Am I accessing business content? Ok, then I use my business email creds).
  • 6. Enhancements to Connect 3) Dynamic Client Registration: In order to support the growing number of devices and API’s using the web, Connect allows clients to register dynamically, relieving admins of the time-consuming task of explicitly registering devices and websites.
  • 7. Why Else is Connect Promising? ● Support from every major identity provider including Google, MSFT, Yahoo & Facebook. ● JSON / REST > XML ● OAuth2 already in use by 85%+ of consumer social logins.
  • 8. Gluu’s OpenID Connect Server ● oxAuth is the leading OpenID Connect implementation in interop tests. ● 100% open source. ● Currently in production at large organizations.
  • 9. How to prepare for Connect ● People: Not much. Social login is already ubiquitous on the net. ● Organizations: Launch an OpenID Connect provider and discovery service. ● Developers: Add Connect to your roadmap. Libraries already exist in Java, Python, and other popular platforms.
  • 10. More Resources ● Open ID Connect website: http: //openid.net/connect/ ● Open Source OX Wiki: http: //ox.gluu.org ● Interop Test Results: http://osis. idcommons.net/wiki/Category: OC5_OP