Skip to main content
OpenID

OpenID

Search complete. 14 mentions across 10 episodes found for "OpenID".

Sep 22, 2026

Tomas KirnakGUEST
40:04
So we actually don't have it yet, but it will be there soon.
Tomas KirnakGUEST
40:08
In actually the next major release, we are adding full OAuth, you know, OpenID, OEDC, SAML into Unimus as well.
Tomas KirnakGUEST
40:18
So, yeah.
Drew Connery-MurrayHOST
40:23
Now, it sounds like because you support MCP, I, as a customer, could bring my own model or agents.
Tomas KirnakGUEST
40:02
Uh, we...
Tomas KirnakGUEST
40:04
So, so we actually don't have it yet, but it, it will be there soon in actually the next major release we are adding full, uh, O- OAuth, uh, you know, OpenID, uh, OIDC-
Drew Connery-MurrayHOST
40:16
Mm-hmm
Tomas KirnakGUEST
40:16
... uh, SAML into Unimus as well.
Tomas KirnakGUEST
40:04
So we actually don't have it yet, but it will be there soon.
Tomas KirnakGUEST
40:08
In actually the next major release, we are adding full OAuth, you know, OpenID, OEDC, SAML into Unimus as well.
Tomas KirnakGUEST
40:18
So, yeah.
Drew Conry-MurrayHOST
40:23
Now, it sounds like because you support MCP, I, as a customer, could bring my own model or agents.
George FletcherGUEST
3:30
And then probably in 2005, I got pulled into the Liberty Alliance, which was building identity web services frameworks on top of SAML and WSTAR, sort of in response to an effort Microsoft had going on at the time to sort of like assign every person a single identifier and they would manage it for you, which the privacy people decided was not the greatest solution.
George FletcherGUEST
4:00
And it sort of just snowballed from there, getting involved in OpenID 1, OAuth 1, OAuth 2, OpenID 2, OpenID Connect, and many follow-on specs after that.
Jeff SteadmanHOST
4:12
So that's a pretty good history of kind of how things got into it, I guess.
Jeff SteadmanHOST
4:17
What was the thing that's like, oh my gosh, we have to do something about this?
Marcos Allende LopezGUEST
9:17
You have European regulation called ADAS in Europe.
Marcos Allende LopezGUEST
9:21
You have OpenID.
Marcos Allende LopezGUEST
9:22
So basically kind of, and W3C, like all of the organizations that develop standards either for identity or for the internet have kind of... worked together for the past decade to enable a new generation of standards for digital IDs that you can use to prove who you are on the internet.
Marcos Allende LopezGUEST
9:39
So that's something that is happening.
AndreHOST
3:07
There is a better way to do that.
AndreHOST
3:10
It's called OIDC, OpenID Connect.
AndreHOST
3:15
And the idea here is that you would do like web federation.
AndreHOST
3:21
So you could create a role that will have a trust policy that would allow GitHub to present its credentials, like I'm GitHub.
AndreHOST
3:50
So that's like, it's very simple explanation, but that allows you to avoid static credentials.
AndreHOST
3:59
So your workers will be able not to have any secrets that you share with them.
AndreHOST
4:05
They just need to be running on GitHub, and then the GitHub's identity, this is what allows AWS to establish trust through OpenID.
AndreHOST
4:17
Nice and dandy.
Arunansu PattanayakHOST
14:48
Can you double click on, you know, your core of the idea? Because you're talking about a global standard, right? Like you by yourself, like you can come up with a way to do it.
Arunansu PattanayakHOST
15:07
But you cannot set the standard, right? So is there a global standard being set, just like we had for OpenID and SSL authentication? There are authentication standards, right? So is there a governing body that is global, that is accepted? So is there now a global standard for agent trust and authentication? And, you know, are you a contributor? Who else is there as a contributor? And how good is it that it can now officially become a global standard?
Ravi BijlaniGUEST
15:48
And, you know, that's the billion dollar question, right? Because it is actually, I take that back.
Ravi BijlaniGUEST
15:54
That's a multi-trillion dollar question.
Ryan BurleyGUEST
7:56
A node on security, same thing, there we go.
Ryan BurleyGUEST
8:00
A node on security, GeoNode integrates with OAuth and OpenID and your own security system's already in place.
Ryan BurleyGUEST
8:06
There's also GeoFence, which adds on to allow for granular data access and permission settings between jurisdictions are based on data sensitivity.
Ryan BurleyGUEST
8:17
A note on GeoSolutions, we've been building, maintaining, and developing applications for open source for over 20 years now.
Andrew CameronGUEST
3:33
how to enable access securely between the LDAP-connected applications and the Active Directory-connected applications.
Andrew CameronGUEST
3:40
And so things like SAML and OpenID Connect came along, and we ended up standardizing those across the enterprise.
Andrew CameronGUEST
3:47
And, you know, it just kind of things took off from there, really.
Andrew CameronGUEST
3:51
And it just, identity itself in the industry, in the security industry, ended up being elevated in importance.

28 MINS LATER

Andrew CameronGUEST
32:08
And we, again, we've been consolidating a lot of authentication activity into Entra over the past couple of years.
Andrew CameronGUEST
32:16
And So there was a lot of that interaction where we had to work with app teams and ease them off of dependencies of weaker auth methods, even just transitioning from on-premise based auth.
Andrew CameronGUEST
32:29
They were still doing binds to the directory and things like that, that we had to ease them off of that and get them using cloud auth methods, you know, using OpenID connected SAML.
Merill FernandoHOST
32:38
Nice.
Ashay RautGUEST
10:10
And then you have to think about, you know, what transaction tokens which help you in securing the call chain.
Ashay RautGUEST
10:15
And then look at OpenID's Authzwork for policy specification.
Ashay RautGUEST
10:20
And then there's more around agent control plane, which is agent control standard that's coming up now soon.
Ashay RautGUEST
10:25
So all of this c- as an enterprise owner, you have to look at all of these standards together, and all of these are trying to address those gaps which are not in the current code.

19 MINS LATER

Ashay RautGUEST
29:21
I would, um-- But if you haven't read the IETF draft on AI agent authentication and authorization, I would highly recommend reading that one because it just tries to cover everything at once.
Ashay RautGUEST
29:31
That's a really good starting point.
Ashay RautGUEST
29:33
And then you should definitely look at OpenID's AuthZ work and Shared Signals Framework work for continuous access evaluation protocol.
Ashay RautGUEST
29:41
I'm throwing a lot of words here.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.