OpenID Provider Authentication Policy Extension

Recordon, David drecordon at verisign.com
Sat Jul 21 23:34:05 UTC 2007


Thanks, definitely am!  Just catching up on a lot of email now.

--David

-----Original Message-----
From: Johnny Bufu [mailto:johnny at sxip.com] 
Sent: Friday, July 13, 2007 11:05 AM
To: Recordon, David
Cc: specs at openid.net
Subject: Re: OpenID Provider Authentication Policy Extension

David,

On 22-Jun-07, at 9:46 AM, Recordon, David wrote:

> So please, check it out and let me know what you think...especially
> around the questions in the Editorial Comments section at the end.
>
> http://openid.net/specs/openid-provider-authentication-policy- 
> extension-
> 1_0-01.html

Hope you're still welcoming feedback on this..

While trying to explain what PAPE is/does, I noticed that the term  
'authentication policy' is not explicitly defined in the spec (and  
how a policy differentiates from a specific authentication  
mechanism). A clear definition could help eliminate confusion between  
the two.


Johnny




More information about the specs mailing list