[OpenID] experimental namespace for openid.net

Santosh Rajan santrajan at gmail.com
Sun Jul 12 02:05:50 UTC 2009


xmldsig works fine in proprietary systems where both signing and verification
is done by software from the same vendor, or at least where the vendor has
solved the interop problems on a case to case basis. Otherwise xmldsig as
far as I can read all over the web is plagued with interop problems. For a
case like OpenID with a multitude of vendors and platforms I dont think it
would be possible to solve all the interop probs on a case to case basis. I
am looking for someone who has successfully implemented xmldsig with XRDS
and I have not been able to find even one! Because if there was one, they
would be the best people to tell you. Unfortunately there isnt (or I havent
found them, let me know if you know of anyone).


Peter Williams wrote:
> 
> (a) since all major programming platforms already have an xmldsig library
> that is well settled in terms of functionality, interoperability and
> access to crypto hardware, I'm really not sure what we gain in openid-land
> by using the Google/TC canonicalization method. 
> 



-----

Santosh Rajan
http://santrajan.blogspot.com http://santrajan.blogspot.com 
-- 
View this message in context: http://www.nabble.com/Re%3A-experimental-namespace-for-openid.net-tp24432471p24445325.html
Sent from the OpenID - General mailing list archive at Nabble.com.




More information about the general mailing list