[OpenID] Reconsidering http://openid different from https://openid
Jack
jack at jackpot.uk.net
Fri Sep 28 14:48:31 UTC 2007
George Fletcher wrote:
> So, just to make sure I've got the best practices from this thread...
>
>
> 1. OPs: Support HTTPS and always redirect the http version to the
> https version
From what I've read, that particular practice would be inconsistent with
some RPs, which apparently don't support HTTPS. This is such a nuisance;
surely a better way of putting it is that such RPs are inconsistent with
secure OpenID?
--
Jack Cleaver.
More information about the general
mailing list