The power of OKTA lies in its thousands of pre-configured SSO relationships. It's important to remember that each one was set up manually with a unique client ID and secret, metadata file, etc.
Application integration is the most difficult part of most identity and access management projects. That is why outsourcing identity to a SaaS provider like OKTA or OneLogin is so appealing--they have done all the hard work for you.
There are no open source projects like OKTA because if you're using open source software, you will inevitably have to integrate and test each application you want configured for SSO.
Keeping those thousands of predefined integrations aside, do you know of any good combination of user-management/access-management/federated-access system beside GLUU?
There's also the open source KeyCloak project from RedHat. [2]
Also I believe Connect2ID is FOSS. [3]
Friends don't let friends OpenAM though, don't bother with WSO2 either. I'd do everything possible to make this someone else's problem, and if you absolutely have to do it in house then ping's the easiest I've worked with thus far.
Making a SSO, even with nice friendly software (hint: none of it is, it's really really complex and easy to fuck up, and the stakes are pretty high) is a horrible, horrible, experience and if you've been through it you'll probably never want to do it again.
I've done it twice, perhaps I was just unlucky but it'll take a lot to convince me that the smarter plan isn't just to outsource that whole requirement instead of trying to build it / OSS it in house. It's pretty generic and can be a 'black box' on your arch diagram, your time is probably better spent building business specific things instead...
If I was absolutely forced to pick something to run on prem for IDP/Fed/Entitlement, I'd get the pingidentity onsite and have them build it for me (trust me, this will be cheaper than trying to do it yourself even if their day rate makes your eyes bleed).
I'd quit before seeing the OpenAM mgt console again.
An IAM platform is many products integrated together, and operationally scalable to meet mission critical requirements. An OpenID Provider is just one element of an IAM platform!
https://massive.bag.of.dicks.pinterest.onelogin.com
Is www.pt.ol.com linked from anywhere?
This is totally common and used in a lot of places..
I mean:
The fact that you can create that domain name to resolve is funny. I can think of a few phishing schemes I could use with this, if I were so inclined.
How could you phish github or aws by using their dns/cert setup as they intended it to be used?
If I'm wrong on the last point, please let me know, as I know a lot of people that will be very happy to find out!
also, you can use https://pintrest.onelogin.com ;)
You would need to host it somewhere, but does full OIDC if you so choose and can integrate with your AD (or multiple).