<div dir="ltr">Session Management is not about "logout", more about "state change" to trigger a re-auth and possibly get an error that will trigger a "logout at the RP" (or to put it differently, "end of session")<br>The section about logout in Session Management is RP-Initiated logout at the OP, whereas this spec is OP-Initiated logout (end of session) at the RPs.<div>So "HTML-Based Logout" (as you mistyped almost everywhere: here, on your blog, on twitter, on the <a href="http://openid.net">openid.net</a> web pages) would be much better than "HTTP-Based Logout" IMO (what part of OIDC is not HTTP to begin with?), or maybe "browser-based logout"? Or how about "OP-Initiated distributed logout", or something about "notifying RPs of logout at the OP".</div></div><br><div class="gmail_quote">On Mon, Mar 9, 2015 at 6:15 PM Mike Jones <<a href="mailto:Michael.Jones@microsoft.com">Michael.Jones@microsoft.com</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">The title is currently "OpenID Connect HTTP-Based Logout 1.0". It's HTTP, because it's HTTP methods such as GET that trigger the logouts. If anything, the Session Management spec is really the one that's HTML-based logout, because it's using HTML5 postMessage calls to do trigger the logouts. (We'd discussed that on the Thursday working group call, in fact.)<br>
<br>
People are encouraged to keep thinking about the naming. The current name is the best that the working group had come up with, to date, but a more compelling name would of course be great.<br>
<br>
-- Mike<br>
<br>
-----Original Message-----<br>
From: Openid-specs-ab [mailto:<a href="mailto:openid-specs-ab-bounces@lists.openid.net" target="_blank">openid-specs-ab-<u></u>bounces@lists.openid.net</a>] On Behalf Of <a href="mailto:mail@alfred-albrecht.net" target="_blank">mail@alfred-albrecht.net</a><br>
Sent: Saturday, March 07, 2015 12:32 AM<br>
To: <a href="mailto:openid-specs-ab@lists.openid.net" target="_blank">openid-specs-ab@lists.openid.<u></u>net</a><br>
Subject: Re: [Openid-specs-ab] First full HTML-based logout spec published<br>
<br>
Would it make sense to rename the spec to "HTML-based logout"? Or do you plan to define more logout techniques?<br>
<br>
Furthermore it seems that logout_supported is now http_logout_supported.<br>
Maybe a typo.<br>
<br>
--<br>
Alfred<br>
<br>
Am 06.03.2015 um 08:25 schrieb Mike Jones:<br>
> The first full version of the HTML-based logout spec is now published<br>
> at <a href="http://openid.net/specs/openid-connect-logout-1_0.html" target="_blank">http://openid.net/specs/<u></u>openid-connect-logout-1_0.html</a><u></u>. It's also<br>
> listed on the Connect page at <a href="http://openid.net/connect/" target="_blank">http://openid.net/connect/</a>, the working<br>
> group repository at <a href="http://openid.bitbucket.org/" target="_blank">http://openid.bitbucket.org/</a>, and the working<br>
> group page at <a href="http://openid.net/wg/connect/" target="_blank">http://openid.net/wg/connect/</a>.<br>
><br>
><br>
><br>
> Semantic changes based on feedback since the 24-Feb-15 version are:<br>
><br>
> * Removed the "iss" query parameter.<br>
><br>
> * Added an entropy requirement for "sid" values.<br>
><br>
> * Renamed "logout_supported" to "html_logout_supported".<br>
><br>
><br>
><br>
> -- Mike<br>
><br>
><br>
><br>
><br>
><br>
> ______________________________<u></u>_________________<br>
> Openid-specs-ab mailing list<br>
> <a href="mailto:Openid-specs-ab@lists.openid.net" target="_blank">Openid-specs-ab@lists.openid.<u></u>net</a><br>
> <a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab" target="_blank">http://lists.openid.net/<u></u>mailman/listinfo/openid-specs-<u></u>ab</a><br>
><br>
______________________________<u></u>_________________<br>
Openid-specs-ab mailing list<br>
<a href="mailto:Openid-specs-ab@lists.openid.net" target="_blank">Openid-specs-ab@lists.openid.<u></u>net</a><br>
<a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab" target="_blank">http://lists.openid.net/<u></u>mailman/listinfo/openid-specs-<u></u>ab</a><br>
______________________________<u></u>_________________<br>
Openid-specs-ab mailing list<br>
<a href="mailto:Openid-specs-ab@lists.openid.net" target="_blank">Openid-specs-ab@lists.openid.<u></u>net</a><br>
<a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab" target="_blank">http://lists.openid.net/<u></u>mailman/listinfo/openid-specs-<u></u>ab</a><br>
</blockquote></div>