[OpenID] One-Click OpenID: A Solution to the NASCAR Problem

SitG Admin sysadmin at shadowsinthegarden.com
Thu Feb 16 17:31:29 UTC 2012


>3 things are different - and not just the same old war horse 
>arguments, repeated over and over and over again. There are 
>different types of certs, and IDPs can issue them too (for 
>"management/discovery purposes").

Modern browsers have solved the "common CA pool" problem? IDPs can 
sign these different cert types (below them in that special type's 
own hierarchy) without necessarily being granted the authority to 
sign ANY cert, say of the common SSL type?

-Shade


More information about the general mailing list