The CanonicalID Approach
Recordon, David
drecordon at verisign.com
Fri Jun 8 20:59:58 UTC 2007
Not really trying to avoid the canonical ID having an OpenID service
listed, just figured not listing one would make the example simpler
though as you point out you certainly can have one.
--David
-----Original Message-----
From: specs-bounces at openid.net [mailto:specs-bounces at openid.net] On
Behalf Of Martin Atkins
Sent: Friday, June 08, 2007 1:42 PM
Cc: specs at openid.net
Subject: Re: The CanonicalID Approach
Josh Hoyt wrote:
> On 6/7/07, Recordon, David <drecordon at verisign.com> wrote:
>> What I'd like to markup is that my three reassignable identifiers so
>> that they all use my LiveJournal userid URL as the persistent
>> identifier. It should be noted that also marking them as synonyms to
>> each other follows the same sort of process using the "<Ref/>" tag in
my
>> various XRDS files.
>
> -1 on requiring a whole extra round of discovery for every sign in. If
> you can come up with a way to verify that (a) the identifier in
> question points to the canonical ID and (b) the canonical ID has the
> appropriate information in it without doing twice the discovery, I'd
> like to hear it.
>
I figure that you could potentially use the same mechanism as delegation
to avoid the extra discovery iteration.
The problem, as with delegation, is that you need to duplicate the
endpoint URL in the source identifier's XRDS document. The canonical
identifier must also support OpenID, which I believe is something they
were trying to avoid.
_______________________________________________
specs mailing list
specs at openid.net
http://openid.net/mailman/listinfo/specs
More information about the specs
mailing list