On 12/01/2017 05:43 AM, Pieter Lukasse wrote:
Thanks for your reply John.
One question regarding your workflow: with IdP do you mean Keycloak or
the brokered IdP?
I'm not sure I understand the question because when you authenticate
against an IdP that is the only IdP you're aware of. If the IdP brokers
(delegates) to another IdP to satisfy your request that process is
invisible to you (with the possible exception the response may indicate
who the ultimate authority was, I can't recall off the top of my head if
the protocol includes this information or not). But from a protocol
point of view you're only ever talking to one IdP.
--
John