The CanonicalID Approach

Recordon, David drecordon at verisign.com
Fri Jun 8 20:59:58 UTC 2007


Not really trying to avoid the canonical ID having an OpenID service
listed, just figured not listing one would make the example simpler
though as you point out you certainly can have one.

--David

-----Original Message-----
From: specs-bounces at openid.net [mailto:specs-bounces at openid.net] On
Behalf Of Martin Atkins
Sent: Friday, June 08, 2007 1:42 PM
Cc: specs at openid.net
Subject: Re: The CanonicalID Approach

Josh Hoyt wrote:
> On 6/7/07, Recordon, David <drecordon at verisign.com> wrote:
>> What I'd like to markup is that my three reassignable identifiers so
>> that they all use my LiveJournal userid URL as the persistent
>> identifier.  It should be noted that also marking them as synonyms to
>> each other follows the same sort of process using the "<Ref/>" tag in
my
>> various XRDS files.
> 
> -1 on requiring a whole extra round of discovery for every sign in. If
> you can come up with a way to verify that (a) the identifier in
> question points to the canonical ID and (b) the canonical ID has the
> appropriate information in it without doing twice the discovery, I'd
> like to hear it.
> 

I figure that you could potentially use the same mechanism as delegation

to avoid the extra discovery iteration.

The problem, as with delegation, is that you need to duplicate the 
endpoint URL in the source identifier's XRDS document. The canonical 
identifier must also support OpenID, which I believe is something they 
were trying to avoid.

_______________________________________________
specs mailing list
specs at openid.net
http://openid.net/mailman/listinfo/specs



More information about the specs mailing list