
(Figure 1) OpenID Certified logo
On the 22nd local time, the U.S.-based OpenID® Foundation announced its self-certification program for the conformance of OpenID Connect implementations. Under this program, an implementation that passes the online tests provided by the OpenID Foundation may use the OpenID Certified mark (Figure 1) by submitting evidence of the test results to the OpenID Foundation and declaring its conformance.
The tests currently available comprise 5 profiles: OP Basic, OP Inplicit, OP Hybrid, OP Config, and OP Dynamic. As the first group, implementations from Google, Nomura Research Institute, ForgeRock, PayPal, and Microsoft have passed as shown in the table below.
(Table 1) First Group of Implementations to Pass OpenID Certification
| Company / Organization | Implementation Name | OP Basic | OP Implicit | OP Hybrid | OP Config | OP Dynamic |
|---|---|---|---|---|---|---|
| ForgeRock | OpenAM 13 | 13-Apr-2015 | 13-Apr-2015 | 13-Apr-2015 | 13-Apr-2015 | |
| Google Federated Identity | 20-Apr-2015 | 21-Apr-2015 | 15-Apr-2015 | |||
| Microsoft | ADFS for Windows 10 | 7-Apr-2015 | ||||
| Microsoft | Azure Active Directory | 8-Apr-2015 | ||||
| Nomura Research Institute[1] | phpOIDC | 10-Apr-2015 | 10-Apr-2015 | 10-Apr-2015 | 10-Apr-2015 | 10-Apr-2015 |
| Nomura Research Institute (NRI SecureTechnologies) |
Uni-ID | 10-Apr-2015 | ||||
| PayPal | Login with PayPal | 15-Apr-2015 | ||||
| Ping Identity | PingFederate | 10-Apr-2015 | 10-Apr-2015 | 10-Apr-2015 | 9-Apr-2015 |
Through this program, providers that have implemented OpenID Connect can declare that their implementations conform to the OpenID Connect standard. Participation in the Certification program should help make interoperability among different implementations more reliable.
The OpenID Certification test suite was developed as open-source software, with the cooperation of Umeå University in Sweden and the EU’s GÉANT project, to promote interoperability among systems related to digital identity.
OpenID Connect is an open standard for identity technology that is secure, mobile-friendly, and privacy-conscious. Since the specification was finalized at RSA Conference 2014 last year, it has been adopted by many services, including Google Sign-in and Microsoft Azure AD. Now that implementations can be tested for conformance in practice, easier interconnection can be expected.
Only certifications for OpenID Provider implementations were announced this time, but certification for Relying Parties is scheduled to begin in May 2015.
These certification results have also been registered with OIXNet, announced on the same day, and can be viewed by anyone.
[1] This open-source implementation was developed through joint research by Nomura Research Institute and Umeå University under the Ministry of Internal Affairs and Communications’ Strategic International Collaborative Research and Development Promotion Project for fiscal year Heisei 24.
Related posts

OpenID Certification Program Wins the 2018 EIC Award
Munich, May 17 — The OpenID Certification Program, a tool for verifying whether implementations of OpenID Connect conform to the specification, has received the “Best Innovation…

OpenID Workshop: Quick Report
Today, from 4 thirty to 8 in the morning Japan time, an OpenID Foundation workshop was held at the Google campus in California. Video and slides…

A Christmas Present from the OpenID Foundation
And so, here is a Christmas present for everyone from the OpenID AB+Connect WG. As of today, the OpenID Connect specifications have entered an Implementer's Draft…

You must be logged in to post a comment.