[security] HTTP vs HTTPS based OpenIDs

Jacob Bellamy toarms at gmail.com
Wed Dec 9 23:25:57 UTC 2009


The problem seems to occur during the Discovery phase. Usually the site will
complain that it cannot find an OpenID endpoint at the target location.
Using the examples/discover.php  example from OpenIDEnabled I seem to always
run into this issue. I also tried with the HTTPS OpenID from Verisign and it
had the same problem. Detect.php seems to be happy with all the settings. 
-- 
View this message in context: http://old.nabble.com/HTTP-vs-HTTPS-based-OpenIDs-tp26685482p26719550.html
Sent from the OpenID - Security mailing list archive at Nabble.com.



More information about the security mailing list