[OpenID] RP Yadis Discovery and OpenID versions

Shane B Weeden sweeden at au1.ibm.com
Wed Aug 27 01:02:23 UTC 2008


I have a question about how an OpenID RP should behave when performing 
Yadis discovery. In this scenario, the OpenID RP supports both OpenID 2.0 
and 1.1 authentication protocols.

If the XRDS document contains services for both OpenID 2.0 and 1.1, and 
the 1.1 service has a higher priority (i.e. lower priority value), which 
service should the RP choose? Is this covered by any existing 
specification?

Perhaps the answer is that it comes down to the individual policy/choice 
of the RP - whether or not it prefers all OpenID 2.0 services over OpenID 
1.1 services, or supports both versions equally and chooses based solely 
on the service priority. Thoughts?

Some examples I've investigated so far:

1. Services that prefers OpenID 2.0 services over 1.1 regardless of 
priority:
www.plaxo.com
nerdbank.org/RP

2. Services that use the service priority rather than perferring OpenID 
2.0.
jyte.com 
openidenabled.com (php, python and ruby) 


I'm leaning toward #2....

Regards,
Shane.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-general/attachments/20080827/1f269e18/attachment-0001.htm>


More information about the general mailing list