Notes From Draft 10

Josh Hoyt josh at janrain.com
Mon Oct 16 21:44:47 UTC 2006


On 10/16/06, Recordon, David <drecordon at verisign.com> wrote:
> 6.1 Signed List Algorithm
[...]
> I'm thinking it would make sense to
> change this algorithm to first alphabetically sort the arguments to make
> it very clear in terms of ordering.

I think it's a good idea to say that the signed list MUST be generated
by the IdP in that order. Then signature *verification* is compatible
with OpenID 1's algorithm. Unless there is objection, I'll do this.

Josh



More information about the specs mailing list