XRI confusion

Martin Atkins mart at degeneration.co.uk
Thu Oct 19 07:44:30 UTC 2006


Dick Hardt wrote:
> 
> How would a user ever learn what their CanonicalID is?

The user doesn't need to know his i-number. The system discovers that 
for him.

> If there Portable Identifier (i-name) is reassigned, then they will  
> be sent to an IdP for the new Canonical ID is, expecting credentials  
> from the new owner. The user will never make it back to the RP, and  
> they will have no easy way of proving they are the owner of the  
> CanonicalID.

I don't really understand this paragraph, but when the i-name is 
reassigned it'll cease to point at the same XRDS and will thus not point 
at the IdP anymore — unless the new owner also has an account with that 
IdP, of course. But they have a different i-number, so the IdP can 
distinguish them.

> Additionally, in the proposal, the i-name is not sent from the RP to  
> the IdP, so how does the IdP know which i-name to address the user  
> as?

I would hope that an IdP, given that I've already established a 
relationship with it, can find something better to address me with than 
a URI. It should be calling me "Martin".





More information about the specs mailing list