<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Personal Information cards did not support holder of key. &nbsp;They were signed bearer assertions. &nbsp;Mostly because of problems getting access to the TLS layer of the browser.<div><br></div><div>You would only use holder oƒ key if the RP requested it. &nbsp; The STORK project in the EU and others have been looking for a way to do tis for some time.</div><div><br></div><div>John B.<br><div><div>On 2011-04-28, at 4:41 PM, &lt;<a href="mailto:Axel.Nennker@telekom.de">Axel.Nennker@telekom.de</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
<div style="WORD-WRAP: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space">
<div><span class="475302720-28042011"></span><font face="Arial"><font color="#0000ff"><font size="2">I&nbsp;think&nbsp;the&nbsp;browser&nbsp;side&nbsp;of&nbsp;HoK&nbsp;is&nbsp;not&nbsp;problematic<span class="475302720-28042011"> compared to the RP side</span>.<span class="475302720-28042011"> How are we going to convince the RP to&nbsp;change 
their systems to accept the key?</span></font></font></font></div>
<div><span class="475302720-28042011"></span><font face="Arial"><font color="#0000ff"><font size="2"><span class="475302720-28042011">Well maybe the browser 
side isn't that simple.&nbsp;The current certificate related UIs&nbsp;are a 
pain.</span>&nbsp;<span class="475302720-28042011"></span></font></font></font><br></div>
<div><span class="475302720-28042011"><font color="#0000ff" size="2" face="Arial">Regarding your NASCAR comment: The openid input field does not have 
to be visible to be discoverable by the addon. This way the RP can have its 
layout and the addon will not interfere with it.</font></span></div>
<div><span class="475302720-28042011"><font color="#0000ff" size="2" face="Arial">This 
problem is that the RP site must work with our without the addon beeing there 
(at least for some time). Which was one of Information Cards problems. 
Self-Issued Information Cards without claims&nbsp;implement HoK but then the 
card metaphore is not the best one in this case.</font></span></div>
<div><span class="475302720-28042011"><font color="#0000ff" size="2" face="Arial"></font></span>&nbsp;</div><br>
<blockquote style="BORDER-LEFT: #0000ff 2px solid; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; MARGIN-RIGHT: 0px" dir="ltr">
  <div dir="ltr" lang="de" class="OutlookMessageHeader" align="left">
  <hr tabindex="-1">
  <font size="2" face="Tahoma"><b>From:</b> John Bradley [mailto:ve7jtb@ve7jtb.com] 
  <br><b>Sent:</b> Thursday, April 28, 2011 10:03 PM<br><b>To:</b> Nennker, 
  Axel<br><b>Cc:</b> <a href="mailto:openid-general@lists.openid.net">openid-general@lists.openid.net</a>; <a href="mailto:thunder@mozilla.com">thunder@mozilla.com</a>; 
  <a href="mailto:mhanson@mozilla.com">mhanson@mozilla.com</a><br><b>Subject:</b> Re: [OpenID] Verisign 
  Seatbelt<br></font><br></div>
  <div></div>There was a way for other openID providers to get added to 
  Seatbealt. &nbsp; On the other hand I don't know that it worked better than 
  the FF extension you just did. &nbsp; &nbsp;It also relied on RP tagging the 
  input box as I recall. &nbsp;With NASCAR type interfaces that is becoming less 
  and less common.
  <div><br></div>
  <div>From a security point of view I would like to be able to gat at a way to 
  do holder of Key in the browser. &nbsp;</div>
  <div><br></div>
  <div>John B.<br>
  <div>
  <div>On 2011-04-28, at 3:30 PM, &lt;<a href="mailto:Axel.Nennker@telekom.de">Axel.Nennker@telekom.de</a>&gt; &lt;<a href="mailto:Axel.Nennker@telekom.de">Axel.Nennker@telekom.de</a>&gt; 
  wrote:</div><br class="Apple-interchange-newline">
  <blockquote type="cite"><span style="WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium Helvetica; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px" class="Apple-style-span">
    <div lang="EN-US" vlink="purple" link="blue">
    <div><span class="721441919-28042011"><font size="2" face="Arial">Hi,</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial"></font></span>&nbsp;</div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">I just stumbled 
    over Verisign's Seatbelt browser extension again. Here is the HTML link to 
    the config from the source code of<span class="Apple-converted-space">&nbsp;</span><a style="COLOR: blue; TEXT-DECORATION: underline" href="https://pip.verisignlabs.com/">https://pip.verisignlabs.com/</a>.</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial"></font><pre id="line17"><font size="2" face="Arial">  &lt;<span class="start-tag">link</span><span class="attribute-name"> rel</span>=<span class="attribute-value">"seatbelt.config" </span><span class="attribute-name">type</span>=<span class="attribute-value">"application/xml" </span><span class="attribute-name">href</span><span>="</span><a style="COLOR: blue; TEXT-DECORATION: underline" href="view-source:https://pip.verisignlabs.com/web/brand/default/seatbelt/seatbeltcfg.xml">https://pip.verisignlabs.com/web/brand/default/seatbelt/seatbeltcfg.xml</a><span>" </span><span class="error"><span class="attribute-name">/</span></span>&gt;<br>
</font><span class="721441919-28042011"><font size="2" face="Arial"><br><br>I guess that Seatbelt is not very widely deployed today...</font></span></pre></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">In the light of 
    "Identity in the Browser": What would we do differently 
    today?</font></span></div>
    <div><span class="721441919-28042011"><font color="#0000ff" size="2" face="Arial"><a style="COLOR: blue; TEXT-DECORATION: underline" href="http://www.w3.org/2011/identity-ws/">http://www.w3.org/2011/identity-ws/</a></font></span></div>
    <div><span class="721441919-28042011"><font color="#0000ff" size="2" face="Arial"></font></span>&nbsp;</div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">Seatbelt has 
    similarities to Mozilla's AccountManager which is now dead (it 
    seems).</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">Seatbelt favored 
    Verisign's OpenID provider which I think was one reason others did not 
    accept it.</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial"></font></span>&nbsp;</div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">Does it make 
    sense to generalize Seatbelt and standardize it into 
    browsers?</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial"></font></span>&nbsp;</div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">regards</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial">Axel</font></span></div>
    <div><span class="721441919-28042011"><font size="2" face="Arial"></font></span>&nbsp;</div>
    <div><span class="721441919-28042011"><pre id="line1"><span class="pi">&lt;?xml version="1.0" encoding="utf-8"?&gt;</span>
&lt;<span class="start-tag">opConfig</span><span class="attribute-name"> version</span>=<span class="attribute-value">"1.0" 
           </span><span class="attribute-name">serverIdentifier</span>=<span class="attribute-value">"<a style="COLOR: blue; TEXT-DECORATION: underline" href="http://pip.verisignlabs.com/">pip.verisignlabs.com</a>"</span>&gt;
  &lt;<span class="start-tag">configRevision</span>&gt;1.1.02&lt;/<span class="end-tag">configRevision</span>&gt;
  &lt;<span class="start-tag">title</span>&gt;Symantec Personal Identity Provider&lt;/<span class="end-tag">title</span>&gt;
  &lt;<span class="start-tag">description</span>&gt;Manage your online identity without compromising your privacy.&lt;/<span class="end-tag">description</span>&gt;
  &lt;<span class="start-tag">loginUrl</span>&gt;https://pip.verisignlabs.com/login.do&lt;/<span class="end-tag">loginUrl</span>&gt;
  &lt;<span class="start-tag">welcomeUrl</span>&gt;https://pip.verisignlabs.com/home_page.do&lt;/<span class="end-tag">welcomeUrl</span>&gt;
</pre><pre id="line9">  &lt;<span class="start-tag">loginStateUrl</span>&gt;https://pip.verisignlabs.com/RPInterface&lt;/<span class="end-tag">loginStateUrl</span>&gt;
  &lt;<span class="start-tag">opDomain</span>&gt;pip.verisignlabs.com&lt;/<span class="end-tag">opDomain</span>&gt;
  &lt;<span class="start-tag">opCertSHA1Hash</span>&gt;99:FB:5C:4D:71:62:5F:1F:A8:D8:37:91:C2:AC:AE:53:86:DC:8B:12&lt;/<span class="end-tag">opCertSHA1Hash</span>&gt;
  &lt;<span class="start-tag">opCertCommonName</span>&gt;pip.verisignlabs.com&lt;/<span class="end-tag">opCertCommonName</span>&gt;
  &lt;<span class="start-tag">settingsIconUrl</span>&gt;https://pip.verisignlabs.com/web/brand/default/seatbelt/check30x30.png&lt;/<span class="end-tag">settingsIconUrl</span>&gt;
  &lt;<span class="start-tag">toolbarGrayIconUrl</span>&gt;https://pip.verisignlabs.com/web/brand/default/seatbelt/pip_logo_gray_16x16.jpg&lt;/<span class="end-tag">toolbarGrayIconUrl</span>&gt;
</pre><pre id="line15">  &lt;<span class="start-tag">toolbarHighIconUrl</span>&gt;https://pip.verisignlabs.com/web/brand/default/seatbelt/pip_logo_16x16.jpg&lt;/<span class="end-tag">toolbarHighIconUrl</span>&gt;
  &lt;<span class="start-tag">toolbarGrayBackground</span>&gt;#D6D6D6&lt;/<span class="end-tag">toolbarGrayBackground</span>&gt;
  &lt;<span class="start-tag">toolbarHighBackground</span>&gt;#FECF71&lt;/<span class="end-tag">toolbarHighBackground</span>&gt;
  &lt;<span class="start-tag">toolbarLoginBackground</span>&gt;#74D174&lt;/<span class="end-tag">toolbarLoginBackground</span>&gt;
  &lt;<span class="start-tag">toolbarGrayBorder</span>&gt;#7C7C7C&lt;/<span class="end-tag">toolbarGrayBorder</span>&gt;
  &lt;<span class="start-tag">toolbarHighBorder</span>&gt;#730027&lt;/<span class="end-tag">toolbarHighBorder</span>&gt;
</pre><pre id="line21">  &lt;<span class="start-tag">toolbarLoginBorder</span>&gt;#2B802B&lt;/<span class="end-tag">toolbarLoginBorder</span>&gt;
  &lt;<span class="start-tag">toolbarGrayText</span>&gt;#666666&lt;/<span class="end-tag">toolbarGrayText</span>&gt;
  &lt;<span class="start-tag">toolbarHighText</span>&gt;#730027&lt;/<span class="end-tag">toolbarHighText</span>&gt;
  &lt;<span class="start-tag">toolbarLoginText</span>&gt;#FFFFFF&lt;/<span class="end-tag">toolbarLoginText</span>&gt;
&lt;/<span class="end-tag">opConfig</span>&gt;
</pre></span></div>_______________________________________________<br>general 
    mailing list<br><a style="COLOR: blue; TEXT-DECORATION: underline" href="mailto:general@lists.openid.net">general@lists.openid.net</a><br><a style="COLOR: blue; TEXT-DECORATION: underline" href="http://lists.openid.net/mailman/listinfo/openid-general">http://lists.openid.net/mailman/listinfo/openid-general</a><br></div></span></blockquote></div><br></div></blockquote></div>
</blockquote></div><br></div></body></html>