[OpenID] Requiring Pseudonymous Identifier
SitG Admin
sysadmin at shadowsinthegarden.com
Wed May 13 16:17:16 UTC 2009
>> Then, am I out of spec for offering a dedicated OP where the
>>*users* do NOT control the identifier; they merely use
>>'shadowsinthegarden.com/everyone' to log in with the ACL permitted
>>to everyone?
>>
>
>You are not out of spec, but that violates assumptions that are made
>by many relying parties.
I probably should have made that more clear: by "dedicated", I meant
that the OP works exclusively with my RP; it does NOT provide login
to other sites.
So, assumptions made by other RP's should not be intruded upon by
this OP; it will never send an assertion to them.
-Shade
More information about the general
mailing list