<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">Right, there are alternatives. I just
      wanted to make sure that the removal of this mechanism was
      deliberate and not an omission.<br>
      <br>
       -- Justin<br>
      <br>
      On 11/26/2012 04:03 PM, Mike Jones wrote:<br>
    </div>
    <blockquote
cite="mid:4E1F6AAD24975D4BA5B168042967394366901383@TK5EX14MBXC283.redmond.corp.microsoft.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <style>
<!--
@font-face
        {font-family:Wingdings}
@font-face
        {font-family:SimSun}
@font-face
        {font-family:SimSun}
@font-face
        {font-family:Calibri}
@font-face
        {font-family:Tahoma}
@font-face
        {font-family:Consolas}
@font-face
        {font-family:"\@SimSun"}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        color:black}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
pre
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";
        color:black}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";
        color:black}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        color:black}
span.EmailStyle18
        {font-family:"Calibri","sans-serif";
        color:windowtext}
span.EmailStyle19
        {font-family:"Calibri","sans-serif";
        color:#1F497D}
span.HTMLPreformattedChar
        {font-family:Consolas;
        color:black}
span.EmailStyle22
        {font-family:"Calibri","sans-serif";
        color:#1F497D}
span.BalloonTextChar
        {font-family:"Tahoma","sans-serif";
        color:black}
.MsoChpDefault
        {font-size:10.0pt}
@page WordSection1
        {margin:1.0in 1.0in 1.0in 1.0in}
div.WordSection1
        {}
ol
        {margin-bottom:0in}
ul
        {margin-bottom:0in}
-->
</style>
      <div>
        <div style="font-family:Calibri,sans-serif; font-size:11pt">Or
          you can do the "redirect" with the "webfinger." DNS prefix.<br>
          <br>
        </div>
      </div>
      <hr>
      <span style="font-family:Tahoma,sans-serif; font-size:10pt;
        font-weight:bold">From:
      </span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Mike
        Jones</span><br>
      <span style="font-family:Tahoma,sans-serif; font-size:10pt;
        font-weight:bold">Sent:
      </span><span style="font-family:Tahoma,sans-serif; font-size:10pt">11/26/2012
        1:00 PM</span><br>
      <span style="font-family:Tahoma,sans-serif; font-size:10pt;
        font-weight:bold">To:
      </span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Justin
        Richer</span><br>
      <span style="font-family:Tahoma,sans-serif; font-size:10pt;
        font-weight:bold">Cc:
      </span><span style="font-family:Tahoma,sans-serif; font-size:10pt"><a class="moz-txt-link-abbreviated" href="mailto:openid-specs-ab@lists.openid.net">openid-specs-ab@lists.openid.net</a></span><br>
      <span style="font-family:Tahoma,sans-serif; font-size:10pt;
        font-weight:bold">Subject:
      </span><span style="font-family:Tahoma,sans-serif; font-size:10pt">Re:
        [Openid-specs-ab] Please review this version of WebFinger</span><br>
      <br>
      <div>
        <div class="WordSection1">
          <p class="MsoNormal"><span style="color:#1F497D">Instead of
              static redirects or JSON-based redirects, this version of
              WebFinger supports 302 redirects, which I’m told can be
              done with a simple rule in Apache or IIS.</span></p>
          <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
          <p class="MsoNormal"><span style="color:#1F497D">                                                                          
              -- Mike</span></p>
          <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
          <div>
            <div style="border:none; border-top:solid #B5C4DF 1.0pt;
              padding:3.0pt 0in 0in 0in">
              <p class="MsoNormal"><b><span style="font-size:10.0pt;
                    font-family:"Tahoma","sans-serif";
                    color:windowtext">From:</span></b><span
                  style="font-size:10.0pt;
                  font-family:"Tahoma","sans-serif";
                  color:windowtext"> Justin Richer
                  [<a class="moz-txt-link-freetext" href="mailto:jricher@mitre.org">mailto:jricher@mitre.org</a>]
                  <br>
                  <b>Sent:</b> Monday, November 26, 2012 7:27 AM<br>
                  <b>To:</b> Mike Jones<br>
                  <b>Cc:</b> <a class="moz-txt-link-abbreviated" href="mailto:openid-specs-ab@lists.openid.net">openid-specs-ab@lists.openid.net</a><br>
                  <b>Subject:</b> Re: [Openid-specs-ab] Please review
                  this version of WebFinger</span></p>
            </div>
          </div>
          <p class="MsoNormal"> </p>
          <div>
            <p class="MsoNormal">Should the "aliases" list always
              contain the subject if it's present? Can it?<br>
              <br>
              From my read, this is now missing the static redirect
              functionality that earlier versions of SWD and Webfinger
              made possible: drop a static file into the right place, it
              gets served back with a 200 and the client can follow the
              redirection. This might be accomplished somewhat cleanly
              by defining a "webfinger" rel/link pairing, right?<br>
              <br>
               -- Justin<br>
              <br>
              On 11/22/2012 03:34 AM, Mike Jones wrote:</p>
          </div>
          <blockquote style="margin-top:5.0pt; margin-bottom:5.0pt">
            <p class="MsoNormal"><span style="color:#1F497D">This
                version is JSON-only, no longer uses host-meta, uses
                query parameters instead of templates, and uses a domain
                prefix to enable hosted deployments.  Are there other
                changes we would want in this draft to use it for OpenID
                Connect?</span></p>
            <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
            <p class="MsoNormal"><span style="color:#1F497D">                                                           
                -- Mike</span></p>
            <p class="MsoNormal"><span style="color:#1F497D"> </span></p>
            <div>
              <div style="border:none; border-top:solid #B5C4DF 1.0pt;
                padding:3.0pt 0in 0in 0in">
                <p class="MsoNormal"><b><span style="font-size:10.0pt;
                      font-family:"Tahoma","sans-serif"">From:</span></b><span
                    style="font-size:10.0pt;
                    font-family:"Tahoma","sans-serif"">
                    <a moz-do-not-send="true"
                      href="mailto:apps-discuss-bounces@ietf.org">apps-discuss-bounces@ietf.org</a>
                    [<a moz-do-not-send="true"
                      href="mailto:apps-discuss-bounces@ietf.org">mailto:apps-discuss-bounces@ietf.org</a>]
                    <b>On Behalf Of </b>Paul E. Jones<br>
                    <b>Sent:</b> Wednesday, November 21, 2012 8:14 PM<br>
                    <b>To:</b> <a moz-do-not-send="true"
                      href="mailto:apps-discuss@ietf.org">apps-discuss@ietf.org</a>;
                    <a moz-do-not-send="true"
                      href="mailto:webfinger@googlegroups.com">
                      webfinger@googlegroups.com</a><br>
                    <b>Subject:</b> [apps-discuss]
                    draft-ietf-appsawg-webfinger-04</span></p>
              </div>
            </div>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">Folks,</p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">I just posted a new draft that takes
              into consideration the input I received on -03 and adds
              the “webfinger” subdomain that was discussed on the list
              this past week.  Specifically, here’s what changed:</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Mention in section 2 that
              WebFinger uses the “rel” attribute and provide a reference
              to the IANA registry for link relations</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Deleted the second paragraph
              from  section 3 that expands on link relations</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Changed the link relation value
              for “blog” to be just the token “blog”</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Corrected a syntax error in the
              example in 4.1</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Clarified in section 4.1 what is
              meant by a “valid alias”</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Introduced a new section 4.2 that
              shows an example for OpenID Connect</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Changed the rel types in 4.3 and
              4.4 to be URI-based (on example.net)</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Corrected syntax in 5.3 and added
              two clarifying sentences</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Introduced a new section 5.5 that
              describes the “webfinger” subdomain</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Changed the name of section 7</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Added language to section 8 to
              support section 5.5</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Added language to section 9 to
              support section 5.5</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Spells out Mike’s name as he
              prefers it</p>
            <p class="MsoListParagraph" style="text-indent:-.25in"><span
                style="font-family:Symbol"><span style="">·<span
                    style="font:7.0pt "Times New Roman"">       
                  </span></span></span>Added a couple of informational
              references</p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">The new draft is here:</p>
            <p class="MsoNormal"><a moz-do-not-send="true"
                href="http://tools.ietf.org/html/draft-ietf-appsawg-webfinger-04">http://tools.ietf.org/html/draft-ietf-appsawg-webfinger-04</a></p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">I think we’re getting closer, though I
              know the “webfinger” subdomain might be a bit
              controversial.  I’m on the fence on this one, myself.  I
              can see the pros and cons of having it.  I’d prefer to
              stay out of the debate, though.  I’ll put into the
              document whatever the group says to put into the documents
              :-)  That said, I think Mike made a valid argument with
              respect to the fact that some domain owners have no
              ability to do anything more than insert an A record for a
              subdomain.</p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">I do want to highlight the fact that
              the current language says that if there is any response
              from a web server at the host, that means the host does
              have the capability of providing WF services and the
              “webfinger” subdomain should not be consulted.  Thus, the
              webfinger subdomain would only be consulted if there is no
              web server running at the host at all.  It’s not a
              fallback for domain owners who have a web server, but just
              didn’t install a WF server.  For that case, they should
              use 3xx redirection for hosting the WF server elsewhere.</p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal">Paul</p>
            <p class="MsoNormal"> </p>
            <p class="MsoNormal"><span style="font-size:12.0pt;
                font-family:"Times New
                Roman","serif""><br>
                <br>
                <br>
              </span></p>
            <pre>_______________________________________________</pre>
            <pre>Openid-specs-ab mailing list</pre>
            <pre><a moz-do-not-send="true" href="mailto:Openid-specs-ab@lists.openid.net">Openid-specs-ab@lists.openid.net</a></pre>
            <pre><a moz-do-not-send="true" href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a></pre>
          </blockquote>
          <p class="MsoNormal"><span style="font-size:12.0pt;
              font-family:"Times New Roman","serif""> </span></p>
        </div>
      </div>
    </blockquote>
    <br>
  </body>
</html>