[Openid-specs-heart] The Number and Ownership of Authorization Servers.

Glen Marshall [SRS] gfm at securityrs.com
Mon Dec 14 21:24:47 UTC 2015


I strongly prefer that the number and ownership of authorization servers 
be declared out of scope, and that the HEART profiles be agnostic about it.

The choice of authorization servers is subject to business/economic 
decisions, trust relationships, risk management, technology limitations, 
and legal/regulatory constraints.   To assume unbounded cases or patient 
ownership, absent the factors that enable or inhibit such choices, 
unnecessarily complicates our discussions

*Glen F. Marshall*
Consultant
Security Risk Solutions, Inc.
698 Fishermans Bend
Mount Pleasant, SC 29464
Tel: (610) 644-2452
Mobile: (610) 613-3084
gfm at securityrs.com
www.SecurityRiskSolutions.com


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-specs-heart/attachments/20151214/9438e61f/attachment.html>


More information about the Openid-specs-heart mailing list