This entry was posted in Gluu and tagged 2fa, api, api access management, api gateway, fido, FOSS, free open source, IAM, OAuth, open source, openid, openid connect, otp, saml, sso, uma on .
From time to time we are asked how Gluu compares to other open source projects. Keycloak is coming up more and more these days, so it’s expedient to just publish our thoughts. 2FA flexibility Currently, Keycloak is limited to using Google Authenticator or FreeOTP as two-factor authentication mechanisms. Gluu ships with out-of-the-box support for many … Read more >>
This entry was posted in Gluu and tagged 2fa, blockchain, did, evernym, fido, free, Identity, open source, openid, openid connect, sovrin, u2f, uaf, w3c on .
I just got back from the Know Identity conference, where I moderated a panel on decentralized identity. Before I forget what happened, I thought it would be a good idea to write down some observations and notes. The conference is attended by quite a number of identity gurus. Dave Birch and Steve Wilson did a … Read more >>
This entry was posted in Gluu and tagged IAM, oauth2, open source, openid connect, saml, sso on .
The Gluu Server is a free open source platform that has both SAML and OAuth2 components. I have been trying to help educate the community for some time on the pro’s and con’s of both infrastructures. Here is a quick overview to help get you oriented! OAuth 2.0 is an authorization framework, not an authentication … Read more >>
This entry was posted in Gluu and tagged AppAuth, authentication, Google, Mobile, mobile SSO, OAuth, oauth2, Okta, openid connect, Ping, PKCE, security, sso on .
In a WebView, any malicious code in the page has the same rights as the application. This means you need to make sure to only load trusted content. But there is another risk–a malicious app may also have access to browser content (like cookies) and may snoop passwords or intercept OAuth codes. So if you … Read more >>
This entry was posted in Gluu and tagged 2fa, authentication, IOT, oauth2, openid connect, uma on .
Today, consumers have no way to centrally manage access to all their Web stuff and IOT devices are threatening to create a whole new silo of security problems. This is one of the reasons I’ve been participating in the Open InterConnect Consortium Security Task Group. People can’t individually manage every IOT device in their house. … Read more >>
This entry was posted in Gluu and tagged authentication, oauth2, openid connect, Single Sign-On, sso, uma on .
10 Reasons Why OpenID Connect will be ubiquitous for domain authentication “The difficult… I’ll do right now. The impossible may take a little while…” Bob Russell lyrics for Jazz standard “Crazy She Calls Me” OpenID Connect has reached the quorum of votes needed for approval! Check out the launch press release. This under-appreciated event will … Read more >>