...
- a trust anchor → https://trust-anchor.testbed.oidcfed.incubator.geant.org/
- embedded OP (SPID) → https://trust-anchor.testbed.oidcfed.incubator.geant.org/oidc/op/
- embedded RP → https://trust-anchor.testbed.oidcfed.incubator.geant.org/oidc/rp/
- an RP → https://relying-party.testbed.oidcfed.incubator.geant.org/
- an OP (CIE) → https://cie-provider.testbed.oidcfed.incubator.geant.org/
- a PHP RP → https://relying-party-php.testbed.oidcfed.incubator.geant.org/
The RP implemented in PHP is based on the implementation from https://github.com/italia/spid-cie-oidc-php.
Fedservice example
...
The trust relationships are depicted below.
Inter-federation logins
Establishing trust between entities from different federations is possible if a valid trust can be constructed between the two entities.
In the existing testbeds, the trust anchor in the Italian federation was added as a trust anchor for the OP in Roland's example federation, making it possible that all RPs in the Italian federation could authenticate users from OP.