[Openid-specs-ab] Add openid_configuration to basic profile

Justin Richer jricher at mit.edu
Mon Apr 6 23:07:37 UTC 2015


I think it makes sense for it to be mandatory for the server to support it (so any client can count on it), optional for clients to use it overall (because there will always be constrained clients that don’t want to do another network call), and mandatory in the Basic Client profile.

 — Justin

> On Apr 6, 2015, at 3:44 PM, Torsten Lodderstedt <torsten at lodderstedt.net> wrote:
> 
> Hi all,
> 
> during the OpenID workshop at IIW it became apparent that most OPs expect RPs to use the openid configuration to dynamically determine the OPs endpoints and properties. In my opinion this makes a lot of sense as it allows the OP to easier manage changes to those aspects.
> 
> I therefore would like to propose to add an explanation of the way this part of OIDC discovery works to the basic client profile document and potentially also make use of the OpenID configuration mandatory for RPs.
> 
> kind regards,
> Torsten.
> 
> 
> _______________________________________________
> Openid-specs-ab mailing list
> Openid-specs-ab at lists.openid.net
> http://lists.openid.net/mailman/listinfo/openid-specs-ab

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 455 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://lists.openid.net/pipermail/openid-specs-ab/attachments/20150406/8f248244/attachment.asc>


More information about the Openid-specs-ab mailing list