Building identity on top of OAuth 2.0?

SitG Admin sysadmin at shadowsinthegarden.com
Thu May 20 15:43:18 UTC 2010


>and optionally, iii) That this same "someone" has recently supplied 
>a shared secret indicating that he or she is "logged in" to his or 
>her account at the IdP.

Alternatively, that the same "someone" has recently demonstrated 
their possession of a non-shared secret (some OP's support the use of 
private/public key pairs for authentication).

-Shade


More information about the specs mailing list