Went Through it With Brad

Recordon, David drecordon at verisign.com
Thu Nov 9 04:32:59 UTC 2006


So I spent tonight running through the spec with Brad Fitzpatrick.
Checked in the changes as revision 97, though mainly wording changes.

Few open issues:

1) 9.1 in the openid.ns parameter talks about using this value in
regards to compare with a lower version number of the protocol.  Looking
at things such as Jabber, it is nearly impossible to deal with version
comparisons in any sane way.  I'm not sure what the best way is to
resolve this.

2) 7.3.3 basically deprecates HTML-based discovery, saying that it is a
way to know that the IdP is using Auth 1.1.  While I know we believe
Yadis will be used in most applications, I hypothesize that the
simplicity of HTML-based discovery will have it continue to prevail.  I
thus would propose we remove the sentence saying that this is a way to
know that an IdP is running version 1.1.

3) Also in 7.3.3, we describe "<LINK>" tags for use in HTML-based
discovery.  The PingBack spec
(http://hixie.ch/specs/pingback/pingback#TOC2.2) is more stringent in
its requirements than ours.  It seems we quote parts of the spec, but it
would be good to look at it again in terms of if we can be more verbose.

--David



More information about the specs mailing list