[security] HTTP and HTTPS URL issue (was RE: security)
Eddy Nigg (StartCom Ltd.)
eddy_nigg at startcom.org
Fri Oct 27 18:57:17 UTC 2006
Dan Lyke wrote:
> Thus I was wrong in my earlier assertion and, in fact, it's the IdP
> Endpoint URL that needs to be authenticated to both the User and the
> Relying Party.
>
> Dan
Yes!
--
Regards
Signer: Eddy Nigg, StartCom Ltd.
Phone: +1.213.341.0390
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-security/attachments/20061027/89107a1d/attachment-0002.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: eddy_nigg.vcf
Type: text/x-vcard
Size: 636 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-security/attachments/20061027/89107a1d/attachment-0002.vcf>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 7282 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.openid.net/pipermail/openid-security/attachments/20061027/89107a1d/attachment-0002.bin>
More information about the security
mailing list