"This is user's URI" for Assertion Quality Extension

SitG Admin sysadmin at shadowsinthegarden.com
Fri Sep 5 17:16:36 UTC 2008


>Hi Shade, AQE has long ago been deprecated in favour of PAPE

Hmm . . . looks like PAPE is more of *how* the user was authenticated 
than the *quality* of their authentication (the latter seemed 
appropriate for what quality of identity the RP should take the OP as 
asserting).

Looking at the specs list to find a more suitable spec to propose 
this for, I notice that AQE isn't even on it. It may be worth 
mentioning that I looked at AQE because someone suggested it to me 
during a discussion on the general mailing list.

I can't see this going with anything (currently on the list) but 
Attribute Exchange, which is freely extensible, so there wouldn't be 
any need to change the spec for such assertions to happen.

Thinking of how I might be able to set up examples of this, another 
possible use-case just occurred to me:

"This is me with my coder hat on."
"This is me with my manager hat on."
"This is me with my sales hat on."
All of these would be set with AX to indicate, per specific login, in 
what capacity I was acting at that particular time. It might be set 
automatically by the software, looking at what department I was 
working in at the moment and whether I was on my lunch break ("This 
is me as a regular person.") to let the OP remain solely responsible 
for OpenID's (and let the user not have to use their personal 
OpenID's at the surveilled company) but signal when an employee was 
not representing the company, but acting only of their own accord. 
The company wouldn't need to assign a different OpenID to that 
employee just to reflect a different stature.

-Shade



More information about the specs mailing list