-
Notifications
You must be signed in to change notification settings - Fork 13
2026‐07‐14
Date: 2026-07-14
- Aaron Parecki (Okta)
- Jeff Bounds (SailPoint)
- Dick Hardt (Hellō)
- Debayan Basu (Independent)
- Karl McGuinness
- George Fletcher
- Welcome and antitrust policy reminder https://openid.net/policies/
- Notes & Recording Policy https://openid.net/wp-content/uploads/2025/09/OIDF_Notes-Recordings-Policy_Final_2025-09-11.pdf
- OpenID Contributor Agreement reminder https://openid.net/intellectual-property
- Reminder about OpenID Slack
- Updates from recent events
- Upcoming Events
- SAML migration
- AOB
Notetaker: Aaron Parecki
Dick: Question from last week was about SAML migration for PQC, where should the work be done?
Karl:
SAML toolkits are unlikely to be udpated to use PQC algorithms, some profiles here to support migration from SAML to OIDC: https://github.com/mcguinness/connect-saml-profiles
Some options include new endpoints at the IDP to facilitate migration without doing a hard cutover of the federation.
Karl's framework proposes three migration profiles. The first keeps the SAML-initiated flow intact but adds an IDP endpoint that accepts the SAML assertion and returns an ID token plus refresh token — the app can run both in parallel, validating that the OIDC representation of the user is correct before cutting over. The second profile routes assertion processing through a centralized gateway that speaks SAML to the upstream IDP and OIDC to the app, enabling legacy apps with low-quality SAML implementations to benefit from a hardened centralized stack. The third involves direct OIDC initiation once confidence is established.
Aaron: Opportunity to migrate lots of apps at once by providing a clear migration path to the federation services that handle SSO for apps.
The post-quantum angle was raised as a forcing function for migration. SAML's XML DSig algorithms have no practical path to PQC support — there is no PQC algorithm defined for XML DSig, and the toolkit ecosystem (SimpleSAMLphp, etc.) is not being modernized. The JOSE stack, by contrast, already has a path forward with hybrid PQC key pairs in RFCs. This creates a regulatory-driven urgency: as PQC mandates from regulators approach (likely in the 3–10 year timeframe, with mandates already in force in some areas), SAML cannot comply, which means orgs on SAML must migrate or become non-compliant.
If IPSIE defines a gold-standard security level (e.g., SL3) that requires PQC algorithms, SAML would by definition fail to qualify. This makes the migration path discussion directly relevant to IPSIE's profiling work.
Next steps: Push for PQC defintions of OIDC in Connect WG, finish existing IPSIE scoped work.
Aaron: Curious to hear from Shannon about PQC in the SAML world
Shannon: Have been some casual exploration of what PQC would look like in SAML. Problem is not just the encryption, it's the trust fabrics. For something like OpenID Federation would require building a lot of new infra. InCommon has committed to developing OpenID Federation.
Aaron: Would that work benefit from this kind of SAML migration path?
Shannon: What we are likely to see is two separate federations operating in parallel until SAML is sunset.
Next 2 week's calls are cancelled for IETF. Resume August 4.
AOB
George: Still working on wrangling the SSF folks
Shannon: Refeds updated MFA profile to v2 to account for phishing resistant MFA. Have encouraged them to register the URI in IANA. https://refeds.org/profile/mfa