[OpenID] Feedback from OpenID demo

Steven Livingstone-Perez weblivz at hotmail.com
Sat May 23 20:34:41 UTC 2009


I can imagine some kind of OP managed RP ruleset login/logout would be 
useful (based on how i typically log in/out of sites each day).

At its simplest could could say that logging out of RP1 should also log me 
in/out of a set of related RP's under Profile 1. Profile 2 may be a 
different set of RP's. This is actually pretty common - take for example how 
Windows Live logs you into a bunch of partner sites (but i'm not sure how 
they control SSO logout).

--
steven
http://livz.org

--------------------------------------------------
From: "SitG Admin" <sysadmin at shadowsinthegarden.com>
Sent: Saturday, May 23, 2009 9:15 PM
To: "Andrew Arnott" <andrewarnott at gmail.com>
Cc: <general at openid.net>
Subject: Re: [OpenID] Feedback from OpenID demo

>>If OpenID is to add single sign-out, it MUST be comprehensive.  That is, 
>>the OP must coordinate logging the user out of EVERY RP he logged into 
>>during that OP's session.
>
> But here's where I want granularity: SSO is supposed to make things 
> *easier*, not make some things IMPOSSIBLE.
>
> If the OP is like a proxy saying "I will automatically log you into 
> whatever RP you have previously approved.", it should logically be 
> possible for me to disable that SSO functionality so it STOPS 
> automatically logging me into those RP's, *without* completely terminating 
> my internet connection by turning off the proxy entirely (i.e., killing my 
> sessions at the RP's I *want* to continue interacting with).
>
> -Shade
> _______________________________________________
> general mailing list
> general at openid.net
> http://openid.net/mailman/listinfo/general
> 



More information about the general mailing list