[OpenID] Too many providers... and here's one reason

SitG Admin sysadmin at shadowsinthegarden.com
Tue Sep 16 15:31:18 UTC 2008


>I wonder if Org could assert my membership with a signed, encoded 
>string, including my claimed id whatever that may be, and I take 
>that encoded string and AX-store it myself to my arbitrary OP.  Then 
>any AX-fetch (with my permission) would retrieve that and the RP 
>could check the signature.

Ahh . . . you are thinking of 3rd-party RP's, not the organization 
that would recognize such signatures. I missed that reading George 
Fletcher's post. Perhaps an XRDS file could contain public keys? Or 
would that stretch the "index" definition of their contents too far?

-Shade



More information about the general mailing list