What entails the "reasonable UI/UX" probably depends on the jurisdiction, so we let the implimentation decide it. For example, it seems in the U.S., the agreement shown by clicking the link is acceptable while in Japan, it is not according to the METI guideline, etc. <br>
<br>Workflow is separate from the UI. Whatever is the appropriate UI in the jurisdiction, the proof of the consent and the wrokflow (such as, if proxy signing is done, the proxy agreement must precedes the signing etc.) will probably stay the same most of the time. <br>
<br>=nat<br><br><div class="gmail_quote">On Fri, Jan 23, 2009 at 11:03 AM, Allen Tom <span dir="ltr"><<a href="mailto:atom@yahoo-inc.com">atom@yahoo-inc.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div bgcolor="#ffffff" text="#000000">
Hi Nat, <br>
<br>
How will the WG define workflow and proof of user consent if the
charter says that UI and UX are out of scope?<br><font color="#888888">
<br>
Allen</font><div><div></div><div class="Wj3C7c"><br>
<br>
<br>
Nat wrote:
<blockquote type="cite">
<div>Whether it really is legally binding depends on what
jurisdiction you are in, but typically there are some minimal set of
info that has to be included to be considered to be a good one. Namely,
sufficiently unique identifiers for all the parties involved, term,
date, expiry, renewal privision, termination clause, jurisdiction, and
signatures. Signature sometimes is of not the subject but of a proxy
agent. </div>
<div>CX is going to define how these should be represented. </div>
<div><br>
</div>
<div>These "contracts" typically lives long, and there are
readability requirement as well. (I.e. it should not require a special
software to read and understand what it means.) Cryptographically, it
requires provisioning against algorithm getting compromised such as
time stamping. </div>
<div><br>
</div>
<div>We also have to define the verification procedure for all the
above. </div>
<div><br>
</div>
<div>Then, there is an issue of what entails the reasonable action
and workflow etc. as a proof of user consent. </div>
<div><br>
</div>
<div>So, in summary, while we intend to use AX (and/or OAuth hybrid)
as the undelying protocol, it is a little more than merely defining
another set of attributes. </div>
<div><br>
=nat<span>@TOKYO via iPhone</span></div>
<div><br>
On 2009/01/23, at 5:43, Allen Tom <<a href="mailto:atom@yahoo-inc.com" target="_blank">atom@yahoo-inc.com</a>> wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>Hi Nat,<br>
<br>
Can you define the term "contract"? Is it legally binding? It is just a
signed set of attributes? Who are the parties involved with signing the
contract? The RP, OP, and user? Instead of defining a new CX extension,
would it just be sufficient to define new attributes using AX?<br>
<br>
Would it make more sense to use OAuth instead of defining a new OpenID
extension? OAuth is designed to allow a user to authorize an RP (aka
Consumer) to access protected resources hosted by the user's OP (aka
Service Provider). It might make more sense to use the OpenID+OAuth
hybrid protocol along with an OAuth protected web service to exchange
contract information.<br>
<br>
Thanks<br>
Allen<br>
<br>
<br>
<br>
<br>
Nat Sakimura wrote:
<blockquote type="cite">I have edited the Contract Exchange Proposal on the wiki. <br>
<br>
<a href="http://wiki.openid.net/Working_Groups%3AContract_Exchange_1" target="_blank">http://wiki.openid.net/Working_Groups%3AContract_Exchange_1</a><br>
<br>
It is substantially shorter and easier to parse, hopefully. <br>
<br>
Please discuss. <br clear="all">
<br>
-- <br>
Nat Sakimura (=nat)<br>
<a href="http://www.sakimura.org/en/" target="_blank">http://www.sakimura.org/en/</a><br>
<pre><hr size="4" width="90%">
_______________________________________________
specs mailing list
<a href="mailto:specs@openid.net" target="_blank">specs@openid.net</a>
<a href="http://openid.net/mailman/listinfo/specs" target="_blank">http://openid.net/mailman/listinfo/specs</a>
</pre>
</blockquote>
<br>
</div>
</blockquote>
</blockquote>
<br>
</div></div></div>
</blockquote></div><br><br clear="all"><br>-- <br>Nat Sakimura (=nat)<br><a href="http://www.sakimura.org/en/">http://www.sakimura.org/en/</a><br>