<html>
<head>
<style>
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 10pt;
font-family:Verdana
}
</style>
</head>
<body class='hmmessage'>I recently had this issue and decided to drop http and use https exclusively.<br><br>Inconvenience for some but solves a lot of potential pain. In addition I allow 'linking' of other OpenID's so you can use others if you wish. On my site it is now all SSL.<br><br>BUT I'm not AOL and appreciate your pain given the pain I went through.<br><br>steven<br>http://livz.org<br><br>> Date: Thu, 17 Sep 2009 11:52:19 -0400<br>> From: gffletch@aol.com<br>> To: peterw@tux.org<br>> CC: openid-general@lists.openid.net<br>> Subject: Re: [OpenID] https discovery & login for AOL at long last?<br>> <br>> Hi Peter,<br>> <br>> A couple of things:) We are working on supporting https identifiers and <br>> from a directed-identity perspective, all pair-wise pseudonymous <br>> "OpenIDs" will be SSL. We are also working on resolving the SSL issue <br>> for openid.aol.com, so that you can use <br>> https://openid.aol.com/identifier as a valid OpenID. I can't promise any <br>> time lines (normal big company stuff) but this is a goal of our ongoing <br>> OpenID work.<br>> <br>> We do have a "unique" problem (shared by a few other OPs) in that we <br>> have active users using http based OpenIDs at Relying Parties across the <br>> web. So we can't move to SSL only OpenIDs without breaking those <br>> customer's experience. I suspect that if you force all OpenIDs to be <br>> SSL, then a user's interaction with your site will work just fine.<br>> <br>> I have heard a couple reasonable suggestions (notably Breno from Google) <br>> for helping to connect an https OpenID to an http one by leveraging the <br>> OpenID XRDS file retrievable over SSL. There are currently no <br>> "standards" around this, but I believe it is worth exploring. However, <br>> it would mean that RPs would need to do some extra work which is <br>> questionable.<br>> <br>> Again, I can't promise dates, but this is on our roadmap:)<br>> <br>> Thanks,<br>> George<br>> <br>> <br>> John Bradley wrote:<br>> > Expect positive news from AOL.<br>> ><br>> > They have been working very hard behind the scenes.<br>> ><br>> > They have openID 2.0 RP support enabled on some of there sites.<br>> > They don't get proper credit for that.<br>> ><br>> > I can confirm that they are in testing for the GSA pilot as a openID <br>> > 2.0 OP.<br>> ><br>> > John B.<br>> > On 2009-09-16, at 5:27 PM, Peter Watkins wrote:<br>> ><br>> >> Wired says that the US federal governmment will soon let people<br>> >> log in to government Web sites with OpenID identifiers from a select<br>> >> few RPs, including AOL<br>> >> http://www.wired.com/epicenter/2009/09/feds-embrace-openid/<br>> >><br>> >> The Wired article implies that AOL has https-only authentication <br>> >> enabled:<br>> >><br>> >> "These companies have undergone a certification process designed by the<br>> >> Information Card Foundation, the OpenID Foundation and the federal<br>> >> government that guarantees certain privacy safeguards. For instance,<br>> >> the sites have to use SSL to handle logins"<br>> >><br>> >> Does AOL finally have https-secured OpenID authentication? Perhaps with<br>> >> directed identity? The only way I know to use directed identity with AOL<br>> >> is via http://openid.aol.com/. That server does have a certificate <br>> >> installed,<br>> >> but the cert is for api.screenname.aol.com, and <br>> >> https://api.screenname.aol.com/<br>> >> is not a valid URL for OpenID discovery.<br>> >><br>> >> Does this .gov news release herald a rebirth of AOL as an OpenID RP?<br>> >><br>> >> Thanks,<br>> >><br>> >> Peter<br>> >><br>> >> _______________________________________________<br>> >> general mailing list<br>> >> general@lists.openid.net<br>> >> http://lists.openid.net/mailman/listinfo/openid-general<br>> ><br>> > _______________________________________________<br>> > general mailing list<br>> > general@lists.openid.net<br>> > http://lists.openid.net/mailman/listinfo/openid-general<br>> ><br>> <br>> -- <br>> Chief Architect<br>> Identity Services, AOL<br>> Blog: http://practicalid.blogspot.com<br>> <br>> <br>> _______________________________________________<br>> general mailing list<br>> general@lists.openid.net<br>> http://lists.openid.net/mailman/listinfo/openid-general<br><br /><hr />Ready for Fall shows? Use Bing to find helpful ratings and reviews on digital tv's. <a href='http://www.bing.com/shopping/search?q=digital+tv's&form=MSHNCB&publ=WLHMTAG&crea=TEXT_MSHNCB_Vertical_Shopping_DigitalTVs_1x1' target='_new'>Click here.</a></body>
</html>