[OpenID] Google OpenID IDP is now live

SitG Admin sysadmin at shadowsinthegarden.com
Thu Nov 6 16:44:09 UTC 2008


>>>  Are you suggesting that Google would serve an opaque ID in the user's
>>>  domain?
>>
>>  sure, why not?
>
>Well, no particular problem serving one, but migrating it seems a bit
>more problematic.

Migrating opaque (RP-unique) ID's is exactly the same process as for 
two entirely different OpenID's: they can't be associated 
automatically, but the user can authenticate to a RP with both of 
them in succession.

Would sites that host OpenID's *and* OP's, together, be able to 
accept a compressed multi-discovery request? Something like "Okay the 
user claims to be these 30 different (old) opaque ID's, and we don't 
want to perform discovery 30 times, so here are the claims and can 
you just verify them for us please? Thanks."

-Shade



More information about the general mailing list