[OpenID] Reconsidering http://openid different from https://openid

Jack jack at jackpot.uk.net
Fri Sep 28 14:48:31 UTC 2007


George Fletcher wrote:
> So, just to make sure I've got the best practices from this thread...
> 
> 
> 1. OPs: Support HTTPS and always redirect the http version to the
> https version

 From what I've read, that particular practice would be inconsistent with
some RPs, which apparently don't support HTTPS. This is such a nuisance;
surely a better way of putting it is that such RPs are inconsistent with
secure OpenID?

-- 
Jack Cleaver.




More information about the general mailing list