<div dir="ltr">Under <a href="http://openid.net/specs/openid-authentication-2_0.html#negative_assertions">http://openid.net/specs/openid-authentication-2_0.html#negative_assertions</a><br><h3><a href="http://14.2.1.">14.2.1.</a>
Relying Parties</h3>When responding with a negative assertion to a
"checkid_immediate" mode authentication request, the
"user_setup_url" parameter MUST be returned. This is a
URL that the end user may visit to complete the
request. The <b><i>OP</i> </b>MAY redirect the end user to
this URL, or provide the end user with a link that
points to this URL.<br><br>Shouldn't this say "The <i><b>RP</b></i> MAY redirect the end user..." ???<br><br>Surely the OP shouldn't ever redirect an immediate request to a checkid_setup request without RP intervention?!<br>
</div>