[OpenID] Password age and password reset

SitG Admin sysadmin at shadowsinthegarden.com
Fri May 15 00:32:31 UTC 2009


>Peter, the claimed identifier which the RP associates with the local
>user account is the same for every login regardless of which OP in the
>xrds is selected to authenticate the user. You seemed to say that if
>OP #3 was selected the RP might not recognize the asserted user but
>the selected OP should be irrelevant. Or am I misunderstanding you?

My understanding (which may be wrong) is that, if an XRDS file lists 
several OP's, the RP might select one for logout that had not been 
aware the user was logged into that RP, because the user had been 
logged in with another.

-Shade



More information about the general mailing list