<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=Content-Type content="text/html; charset=utf-8">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";
        color:black;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;
        color:black;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor=white lang=EN-US link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>As we go from evangelism to adoption, we’d be well served in addressing
in our own showcases the realities that others will encounter. Of course we
know what they are (the spec is WELL written, on the topic of https), but can
we demonstrate that those mechanisms WORK EFFECTIVELY in public networks,
ourselves?<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I do remember someone asserting that (https) trust in the UCI
space was intended to be “sorted out by market forces” – i.e. by the “highest
common denominator” function. That is: consumers will naturally migrate to
OPs/CAs that “work” (ie. are accepted). Others (that have some or other hurdle)
will be avoided. It’s not as if the consumer could really care less about CA’s
and OPs and https, till there is an actual fraud and thus a finger has to get pointed
somewhere, to collect the cash.<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>We can ask: it the choice of the relying party to “accept” one
or other CAs for https openids (and deny others)? Well, surely it is! Who else
who do it? The user cannot, do it as the claimant, and the OP cannot do it, as
the asserting party. That leaves the Relying party (“consumer”).<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>The Foundation is obviously the relying party when delivering 2 services
as member benefits. And in that role i) the vendor “CAcert” has been evidently
been designated as perfectly acceptable for the https openid used for (rather legalistic)
membership transactions (including vote casting, it seems), and ii) a member’s use
of the https openid may or may not now work with the own Foundation’s wiki
(once outsourced to pbwiki).<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Now, I really don’t know if pbwiki makes any use of Debian
products. But even if it does, surely it’s the Foundation (as customer of the
outsourced wiki) that determines what the pbwiki -enforced reliance policy is?
Using the wiki is a member benefit, and surely pbwiki ( the contractor) should
be enforcing the Foundations happenstance “all inclusive” decision policies (any
CA will do for openid discovery, even the ones’ whose SSL certifications are allegedly
worth less than the e-paper they are written on).<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Now, let me try to think like pbwiki. At Rapattoni, we too have
300+ customers each running THEIR sets of committees, posting THEIR courses,
holding events, doing non-profit elections (~1 a day on average), maintaining records
so professional flows can fine members who tend to be unhappy about that act, constantly
orchestrating donations for local/state/national political campaigns, running accounting
day books and reconciliations, posting merchant e-stores, handling recurring credit
cards transactions etc.. And, doing all that, I really expect to run a trust
model (concerning https openid) for each of those 300 customer, rather than
impose some Rapattoni criteria. <o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>As those (pbwiki-like) customers also procure SAAS services from
our peers, and 1 member will inevitably visit multiple providers of SAAS
service, I’d expect us all (as outsourcers related to a single community) to
harmonize with the customer’s trust model (per membership group). <o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I have not yet reviewed any of the OpenID’s WG’s proposed trust discovery/negotiation/reliance
protocols. But I’d hope that it might adopt some of what SAML2 got right - in
its “SP-affiliation” model. This would help make a leap forward here, in handling
the REALITY of trust models in the SAAS area, when multiple providers are involved.
Then, what one dominant SP relies on, other SPs in the specific affiliation
group may be required to similarly rely on.<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>(The IPR issues are well pretty settled on sp-affiliations, too!)<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<div style='border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'>
<p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif";
color:windowtext'>From:</span></b><span style='font-size:10.0pt;font-family:
"Tahoma","sans-serif";color:windowtext'> general-bounces@openid.net
[mailto:general-bounces@openid.net] <b>On Behalf Of </b>Eddy Nigg (StartCom
Ltd.)<br>
<b>Sent:</b> Friday, December 19, 2008 12:05 PM<br>
<b>To:</b> OpenID List<br>
<b>Subject:</b> Re: [OpenID] [OpenID board] wiki.openid.net is now set up<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal>On 12/19/2008 09:34 PM, Peter Williams:<br>
<br>
<o:p></o:p></p>
<pre>I'm going to attempt join my client's (CAcert-endorsed) https Openid membership account, for voting purposes.<o:p></o:p></pre><pre><o:p> </o:p></pre><pre>(Though Eddy might protest that the Foundation is not served by agreeing to that business partners legal terms)<o:p></o:p></pre>
<p class=MsoNormal><br>
I explained what it means, provided the necessary information for the
foundation to judge it. Not going to protest, but will make note.<br>
<br>
<br>
<o:p></o:p></p>
<pre> As a user, I'd want the CA-cert endorsed https OpeniD viable for the membership.voting site to also work on the Foundation's wiki.<o:p></o:p></pre>
<p class=MsoNormal style='margin-bottom:12.0pt'>Perhaps it isn't your choice
which CA your OpenID provider uses, maybe it is. In the former case I'd suggest
to start a dialog with the provider to have that changed, in the later case
you'd surprise and disappoint me.<br>
<br>
<o:p></o:p></p>
<div>
<table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0>
<tr>
<td colspan=2 style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Regards <o:p></o:p></p>
</td>
</tr>
<tr>
<td colspan=2 style='padding:0in 0in 0in 0in'>
<p class=MsoNormal> <o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Signer: <o:p></o:p></p>
</td>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Eddy Nigg, <a href="http://www.startcom.org">StartCom Ltd.</a><o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Jabber: <o:p></o:p></p>
</td>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal><a href="xmpp:startcom@startcom.org">startcom@startcom.org</a><o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Blog: <o:p></o:p></p>
</td>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal><a href="http://blog.startcom.org">Join the Revolution!</a><o:p></o:p></p>
</td>
</tr>
<tr>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>Phone: <o:p></o:p></p>
</td>
<td style='padding:0in 0in 0in 0in'>
<p class=MsoNormal>+1.213.341.0390<o:p></o:p></p>
</td>
</tr>
<tr>
<td colspan=2 style='padding:0in 0in 0in 0in'>
<p class=MsoNormal> <o:p></o:p></p>
</td>
</tr>
</table>
</div>
<p class=MsoNormal><o:p> </o:p></p>
</div>
</div>
</body>
</html>