<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-21806</id>
	<title>Nabble - OpenID - Specs</title>
	<updated>2009-11-18T16:57:04Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/OpenID---Specs-f21806.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID---Specs-f21806.html" />
	<subtitle type="html">Specifications Discussions about &lt;a href=&quot;http://openid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;OpenID&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26418626</id>
	<title>Re: Reputation</title>
	<published>2009-11-18T16:57:04Z</published>
	<updated>2009-11-18T16:57:04Z</updated>
	<author>
		<name>Chris Messina</name>
	</author>
	<content type="html">Very interesting!&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I&amp;#39;ve fleshed out some more details on the wiki page:&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;a href=&quot;https://activitystreams.pbworks.com/Stats&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://activitystreams.pbworks.com/Stats&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Please add more attributes as you think of them!&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Chris&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Tue, Nov 17, 2009 at 6:48 PM, Allen Tom &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26418626&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atom@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;


  

&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
On a closely related note, many sites have asked us to add &amp;quot;sign up
date&amp;quot; as well as other reputation attributes to our OpenID service,
mostly for anti-abuse purposes. This would be a useful AX attribute,
especially if OPs are willing to standardize on this.&lt;br&gt;
&lt;br&gt;
Allen&lt;br&gt;
&lt;br&gt;
Chris Messina wrote:
&lt;blockquote type=&quot;cite&quot;&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;On Tue, Nov 17, 2009 at 4:59 PM, Christian Crumlish &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26418626&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xian@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
    &lt;div&gt;
    &lt;div class=&quot;gmail_quote&quot;&gt;
    &lt;div&gt;
    &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;&lt;br&gt;
    &lt;/blockquote&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
it almost seems like its own namespace&lt;br&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;-x-&lt;/div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;p.s.: see also &lt;a href=&quot;http://developer.yahoo.com/ypatterns/social/people/reputation/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://developer.yahoo.com/ypatterns/social/people/reputation/&lt;/a&gt;&lt;/div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Well, I think what Monica is talking about are more like &amp;quot;stats&amp;quot;
than reputation.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Not all services count such things, but many could provide an
aggregate count as to the number of friends or contacts someone has, or
the number of fans or followers they&amp;#39;ve accrued. Twitter, Facebook, or
Amazon might also provide the number of lists they&amp;#39;ve made (for Amazon,
it&amp;#39;d be wishlists), or other stats.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;I wouldn&amp;#39;t call this &amp;quot;reputation&amp;quot; because of the weight (and
near impossibility) of the subject matter — especially when applying it
to two disjoint social contexts.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;I think this at least bears inspection as Twitter is providing
this information. For now, I&amp;#39;ve created a page on the wiki to explore
this topic further:&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;&lt;a href=&quot;https://activitystreams.pbworks.com/Stats&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;https://activitystreams.pbworks.com/Stats&lt;/a&gt;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Chris&lt;/div&gt;
  &lt;br&gt;
-- &lt;br&gt;
Chris Messina&lt;br&gt;
Open Web Advocate&lt;br&gt;
  &lt;br&gt;
Personal: &lt;a href=&quot;http://factoryjoe.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://factoryjoe.com&lt;/a&gt;&lt;br&gt;
Follow me on Twitter: &lt;a href=&quot;http://twitter.com/chrismessina&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/chrismessina&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
Citizen Agency: &lt;a href=&quot;http://citizenagency.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://citizenagency.com&lt;/a&gt;&lt;br&gt;
Diso Project: &lt;a href=&quot;http://diso-project.org&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://diso-project.org&lt;/a&gt;&lt;br&gt;
OpenID Foundation: &lt;a href=&quot;http://openid.net&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
This email is:   [ ] shareable    [X] ask first   [ ] private&lt;br&gt;
  &lt;/div&gt;&lt;/div&gt;&lt;p&gt;--&lt;/p&gt;
You received this message because you are subscribed to the Google
Groups &amp;quot;PortableContacts&amp;quot; group.&lt;br&gt;
To post to this group, send email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26418626&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;portablecontacts@...&lt;/a&gt;.&lt;br&gt;
For more options, visit this group at
&lt;a href=&quot;http://groups.google.com/group/portablecontacts?hl=&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/portablecontacts?hl=&lt;/a&gt;.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;/div&gt;


&lt;p&gt;&lt;/p&gt;

&lt;p&gt;--&lt;/p&gt;

You received this message because you are subscribed to the Google Groups &amp;quot;PortableContacts&amp;quot; group.&lt;br&gt;

To post to this group, send email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26418626&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;portablecontacts@...&lt;/a&gt;.&lt;br&gt;



For more options, visit this group at &lt;a href=&quot;http://groups.google.com/group/portablecontacts?hl=&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/portablecontacts?hl=&lt;/a&gt;.&lt;br&gt;

&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Chris Messina&lt;br&gt;Open Web Advocate&lt;br&gt;&lt;br&gt;Personal: &lt;a href=&quot;http://factoryjoe.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://factoryjoe.com&lt;/a&gt;&lt;br&gt;Follow me on Twitter: &lt;a href=&quot;http://twitter.com/chrismessina&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/chrismessina&lt;/a&gt;&lt;br&gt;
&lt;br&gt;Citizen Agency: &lt;a href=&quot;http://citizenagency.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://citizenagency.com&lt;/a&gt;&lt;br&gt;Diso Project: &lt;a href=&quot;http://diso-project.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://diso-project.org&lt;/a&gt;&lt;br&gt;OpenID Foundation: &lt;a href=&quot;http://openid.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;&lt;br&gt;
&lt;br&gt;This email is:   [ ] shareable    [X] ask first   [ ] private&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26418626&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Reputation-tp26401608p26418626.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26405369</id>
	<title>Re: [OpenID board] OpenID v.Next session notes from IIW</title>
	<published>2009-11-18T02:18:11Z</published>
	<updated>2009-11-18T02:18:11Z</updated>
	<author>
		<name>Santosh Rajan</name>
	</author>
	<content type="html">This is great stuff. Nice to see clear and reasonable objectives.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I hope we can see an action plan with target date (in six months), milestones, and individual (or group) responsibilities, and hope we can follow the progress till completion.&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Best wishes to all the people involved.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Wed, Nov 18, 2009 at 3:30 PM, Mike Jones &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26405369&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Michael.Jones@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;








&lt;div lang=&quot;EN-US&quot; link=&quot;blue&quot; vlink=&quot;purple&quot;&gt;

&lt;div&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;I’ve posted notes on the consensus goals for OpenID
v.Next arrived at during the session at IIW at &lt;a href=&quot;http://self-issued.info/?p=256&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://self-issued.info/?p=256&lt;/a&gt;.&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt; &lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;                                                                Cheers,&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt;                                                                --
Mike&lt;/p&gt;

&lt;p class=&quot;MsoNormal&quot;&gt; &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;


&lt;br&gt;_______________________________________________&lt;br&gt;
board mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26405369&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;board@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-board&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-board&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;&lt;a href=&quot;http://hi.im/santosh&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hi.im/santosh&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26405369&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;signature&quot;&gt;
Santosh Rajan
&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-v.Next-session-notes-from-IIW-tp26405171p26405369.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26405171</id>
	<title>OpenID v.Next session notes from IIW</title>
	<published>2009-11-18T02:00:45Z</published>
	<updated>2009-11-18T02:00:45Z</updated>
	<author>
		<name>Mike Jones-13</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:x=&quot;urn:schemas-microsoft-com:office:excel&quot; xmlns:p=&quot;urn:schemas-microsoft-com:office:powerpoint&quot; xmlns:a=&quot;urn:schemas-microsoft-com:office:access&quot; xmlns:dt=&quot;uuid:C2F41010-65B3-11d1-A29F-00AA00C14882&quot; xmlns:s=&quot;uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882&quot; xmlns:rs=&quot;urn:schemas-microsoft-com:rowset&quot; xmlns:Z=&quot;urn:schemas-microsoft-com:&quot; xmlns:b=&quot;urn:schemas-microsoft-com:office:publisher&quot; xmlns:ss=&quot;urn:schemas-microsoft-com:office:spreadsheet&quot; xmlns:c=&quot;urn:schemas-microsoft-com:office:component:spreadsheet&quot; xmlns:odc=&quot;urn:schemas-microsoft-com:office:odc&quot; xmlns:oa=&quot;urn:schemas-microsoft-com:office:activation&quot; xmlns:html=&quot;http://www.w3.org/TR/REC-html40&quot; xmlns:q=&quot;http://schemas.xmlsoap.org/soap/envelope/&quot; xmlns:rtc=&quot;http://microsoft.com/officenet/conferencing&quot; xmlns:D=&quot;DAV:&quot; xmlns:Repl=&quot;http://schemas.microsoft.com/repl/&quot; xmlns:mt=&quot;http://schemas.microsoft.com/sharepoint/soap/meetings/&quot; xmlns:x2=&quot;http://schemas.microsoft.com/office/excel/2003/xml&quot; xmlns:ppda=&quot;http://www.passport.com/NameSpace.xsd&quot; xmlns:ois=&quot;http://schemas.microsoft.com/sharepoint/soap/ois/&quot; xmlns:dir=&quot;http://schemas.microsoft.com/sharepoint/soap/directory/&quot; xmlns:ds=&quot;http://www.w3.org/2000/09/xmldsig#&quot; xmlns:dsp=&quot;http://schemas.microsoft.com/sharepoint/dsp&quot; xmlns:udc=&quot;http://schemas.microsoft.com/data/udc&quot; xmlns:xsd=&quot;http://www.w3.org/2001/XMLSchema&quot; xmlns:sub=&quot;http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/&quot; xmlns:ec=&quot;http://www.w3.org/2001/04/xmlenc#&quot; xmlns:sp=&quot;http://schemas.microsoft.com/sharepoint/&quot; xmlns:sps=&quot;http://schemas.microsoft.com/sharepoint/soap/&quot; xmlns:xsi=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; xmlns:udcs=&quot;http://schemas.microsoft.com/data/udc/soap&quot; xmlns:udcxf=&quot;http://schemas.microsoft.com/data/udc/xmlfile&quot; xmlns:udcp2p=&quot;http://schemas.microsoft.com/data/udc/parttopart&quot; xmlns:wf=&quot;http://schemas.microsoft.com/sharepoint/soap/workflow/&quot; xmlns:dsss=&quot;http://schemas.microsoft.com/office/2006/digsig-setup&quot; xmlns:dssi=&quot;http://schemas.microsoft.com/office/2006/digsig&quot; xmlns:mdssi=&quot;http://schemas.openxmlformats.org/package/2006/digital-signature&quot; xmlns:mver=&quot;http://schemas.openxmlformats.org/markup-compatibility/2006&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns:mrels=&quot;http://schemas.openxmlformats.org/package/2006/relationships&quot; xmlns:spwp=&quot;http://microsoft.com/sharepoint/webpartpages&quot; xmlns:ex12t=&quot;http://schemas.microsoft.com/exchange/services/2006/types&quot; xmlns:ex12m=&quot;http://schemas.microsoft.com/exchange/services/2006/messages&quot; xmlns:pptsl=&quot;http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/&quot; xmlns:spsl=&quot;http://microsoft.com/webservices/SharePointPortalServer/PublishedLinksService&quot; xmlns:st=&quot;&amp;#1;&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;I&amp;#8217;ve posted notes on the consensus goals for OpenID
v.Next arrived at during the session at IIW at &lt;a href=&quot;http://self-issued.info/?p=256&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://self-issued.info/?p=256&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cheers,&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --
Mike&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26405171&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-v.Next-session-notes-from-IIW-tp26405171p26405171.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26402543</id>
	<title>Re: Reputation</title>
	<published>2009-11-17T20:54:34Z</published>
	<updated>2009-11-17T20:54:34Z</updated>
	<author>
		<name>John Panzer-5</name>
	</author>
	<content type="html">+1 to stats. &amp;nbsp;And especially to life-of-account, as this is expensive
&lt;br&gt;to game without a time machine.
&lt;br&gt;&lt;br&gt;Note that even with minimal context, it is possible to do useful
&lt;br&gt;statistical analysis and classification based on these types of
&lt;br&gt;features.
&lt;br&gt;&lt;br&gt;On Tuesday, November 17, 2009, Allen Tom &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atom@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On a closely related note, many sites have asked us to add &amp;quot;sign up
&lt;br&gt;&amp;gt; date&amp;quot; as well as other reputation attributes to our OpenID service,
&lt;br&gt;&amp;gt; mostly for anti-abuse purposes. This would be a useful AX attribute,
&lt;br&gt;&amp;gt; especially if OPs are willing to standardize on this.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Allen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Chris Messina wrote:
&lt;br&gt;&amp;gt; On Tue, Nov 17, 2009 at 4:59 PM, Christian Crumlish &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xian@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; it almost seems like its own namespace
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; -x-
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; p.s.: see also &lt;a href=&quot;http://developer.yahoo.com/ypatterns/social/people/reputation/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://developer.yahoo.com/ypatterns/social/people/reputation/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; Well, I think what Monica is talking about are more like &amp;quot;stats&amp;quot;
&lt;br&gt;&amp;gt; than reputation.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; Not all services count such things, but many could provide an
&lt;br&gt;&amp;gt; aggregate count as to the number of friends or contacts someone has, or
&lt;br&gt;&amp;gt; the number of fans or followers they've accrued. Twitter, Facebook, or
&lt;br&gt;&amp;gt; Amazon might also provide the number of lists they've made (for Amazon,
&lt;br&gt;&amp;gt; it'd be wishlists), or other stats.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; I wouldn't call this &amp;quot;reputation&amp;quot; because of the weight (and
&lt;br&gt;&amp;gt; near impossibility) of the subject matter — especially when applying it
&lt;br&gt;&amp;gt; to two disjoint social contexts.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; I think this at least bears inspection as Twitter is providing
&lt;br&gt;&amp;gt; this information. For now, I've created a page on the wiki to explore
&lt;br&gt;&amp;gt; this topic further:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &lt;a href=&quot;https://activitystreams.pbworks.com/Stats&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://activitystreams.pbworks.com/Stats&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; Chris
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Chris Messina
&lt;br&gt;&amp;gt; Open Web Advocate
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Personal: &lt;a href=&quot;http://factoryjoe.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://factoryjoe.com&lt;/a&gt;&lt;br&gt;&amp;gt; Follow me on Twitter: &lt;a href=&quot;http://twitter.com/chrismessina&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/chrismessina&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Citizen Agency: &lt;a href=&quot;http://citizenagency.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://citizenagency.com&lt;/a&gt;&lt;br&gt;&amp;gt; Diso Project: &lt;a href=&quot;http://diso-project.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://diso-project.org&lt;/a&gt;&lt;br&gt;&amp;gt; OpenID Foundation: &lt;a href=&quot;http://openid.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This email is:   [ ] shareable    [X] ask first   [ ] private
&lt;br&gt;&amp;gt; &amp;nbsp; --
&lt;br&gt;&amp;gt; You received this message because you are subscribed to the Google
&lt;br&gt;&amp;gt; Groups &amp;quot;PortableContacts&amp;quot; group.
&lt;br&gt;&amp;gt; To post to this group, send email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;portablecontacts@...&lt;/a&gt;.
&lt;br&gt;&amp;gt; For more options, visit this group at
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://groups.google.com/group/portablecontacts?hl=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/portablecontacts?hl=&lt;/a&gt;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; You received this message because you are subscribed to the Google Groups &amp;quot;PortableContacts&amp;quot; group.
&lt;br&gt;&amp;gt; To post to this group, send email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;portablecontacts@...&lt;/a&gt;.
&lt;br&gt;&amp;gt; For more options, visit this group at &lt;a href=&quot;http://groups.google.com/group/portablecontacts?hl=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/portablecontacts?hl=&lt;/a&gt;.
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;--
&lt;br&gt;John Panzer / Google
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jpanzer@...&lt;/a&gt; / abstractioneer.org / @jpanzer
&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26402543&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Reputation-tp26401608p26402543.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26401608</id>
	<title>Re: Reputation</title>
	<published>2009-11-17T18:48:37Z</published>
	<updated>2009-11-17T18:48:37Z</updated>
	<author>
		<name>Allen Tom-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=windows-1252&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
On a closely related note, many sites have asked us to add &quot;sign up
date&quot; as well as other reputation attributes to our OpenID service,
mostly for anti-abuse purposes. This would be a useful AX attribute,
especially if OPs are willing to standardize on this.&lt;br&gt;
&lt;br&gt;
Allen&lt;br&gt;
&lt;br&gt;
Chris Messina wrote:
&lt;blockquote cite=&quot;mid:1bc4603e0911171817y1a672703l445f9b030ca9c264@mail.gmail.com&quot; type=&quot;cite&quot;&gt;On Tue, Nov 17, 2009 at 4:59 PM, Christian Crumlish &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26401608&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xian@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
    &lt;div&gt;
    &lt;div class=&quot;gmail_quote&quot;&gt;
    &lt;div class=&quot;im&quot;&gt;
    &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;br&gt;
    &lt;/blockquote&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
it almost seems like its own namespace&lt;br&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;-x-&lt;/div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;div&gt;p.s.: see also &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://developer.yahoo.com/ypatterns/social/people/reputation/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://developer.yahoo.com/ypatterns/social/people/reputation/&lt;/a&gt;&lt;/div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Well, I think what Monica is talking about are more like &quot;stats&quot;
than reputation.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Not all services count such things, but many could provide an
aggregate count as to the number of friends or contacts someone has, or
the number of fans or followers they've accrued. Twitter, Facebook, or
Amazon might also provide the number of lists they've made (for Amazon,
it'd be wishlists), or other stats.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;I wouldn't call this &quot;reputation&quot; because of the weight (and
near impossibility) of the subject matter — especially when applying it
to two disjoint social contexts.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;I think this at least bears inspection as Twitter is providing
this information. For now, I've created a page on the wiki to explore
this topic further:&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;https://activitystreams.pbworks.com/Stats&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://activitystreams.pbworks.com/Stats&lt;/a&gt;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Chris&lt;/div&gt;
  &lt;br&gt;
-- &lt;br&gt;
Chris Messina&lt;br&gt;
Open Web Advocate&lt;br&gt;
  &lt;br&gt;
Personal: &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://factoryjoe.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://factoryjoe.com&lt;/a&gt;&lt;br&gt;
Follow me on Twitter: &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://twitter.com/chrismessina&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/chrismessina&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
Citizen Agency: &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://citizenagency.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://citizenagency.com&lt;/a&gt;&lt;br&gt;
Diso Project: &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://diso-project.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://diso-project.org&lt;/a&gt;&lt;br&gt;
OpenID Foundation: &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
This email is:   [ ] shareable    [X] ask first   [ ] private&lt;br&gt;
  &lt;p&gt;--&lt;/p&gt;
You received this message because you are subscribed to the Google
Groups &quot;PortableContacts&quot; group.&lt;br&gt;
To post to this group, send email to &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26401608&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;portablecontacts@...&lt;/a&gt;.&lt;br&gt;
For more options, visit this group at
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://groups.google.com/group/portablecontacts?hl=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://groups.google.com/group/portablecontacts?hl=&lt;/a&gt;.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26401608&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Reputation-tp26401608p26401608.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26370352</id>
	<title>OpenID selector demo screen shots</title>
	<published>2009-11-16T03:24:20Z</published>
	<updated>2009-11-16T03:24:20Z</updated>
	<author>
		<name>Mike Jones-13</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;I&amp;#8217;ve posted a set of screen captures and commentary
corresponding to the OpenID selector demos we gave at the OpenID Summit and the
Internet Identity Workshop at &lt;a href=&quot;http://self-issued.info/?p=235&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://self-issued.info/?p=235&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
-- Mike&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26370352&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-selector-demo-screen-shots-tp26370352p26370352.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26141060</id>
	<title>Re: OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-31T02:58:00Z</published>
	<updated>2009-10-31T02:58:00Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">My blunder. I wonder whatever I was thinking... Must be too tired...&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Thanks for pointing out. &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;=nat&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Tue, Oct 27, 2009 at 12:05 AM, John Bradley &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26141060&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;john.bradley@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;&lt;div style=&quot;word-wrap:break-word&quot;&gt;Nat  you are referring to the assertion lifetimes for a enterprise LAN environment.&lt;div&gt;
&lt;br&gt;&lt;/div&gt;&lt;div&gt;For a environment where the RP is not part of the same domain as the IdP.&lt;/div&gt;&lt;div&gt;Level 1:  5min&lt;/div&gt;&lt;div&gt;Level 2:  5min&lt;/div&gt;&lt;div&gt;Level 3:  5min&lt;/div&gt;&lt;div&gt;Level 4:  MUST NOT use bearer tokens. (Rules out openID)&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The Nonce contains a time stamp that should be used for this.  &lt;/div&gt;&lt;div&gt;Clock synchronization can become an issue with times this small.  NNTP please.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;We could add a TTL to the assertion however it may be as easy to say that OP keep private assertions for a minimum of 5 min.&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Andrew&amp;#39;s app should refresh any unsolicited positive assertions older than 5 min.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;It is interesting that JS can cache assertions like this.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;It perhaps also points out the possibility of people using this technique for cross site scripting to sites that a user thinks they are logged out of.&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;John B. &lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;On 2009-10-26, at 3:40 AM, Nat Sakimura wrote:&lt;/div&gt;&lt;br&gt;&lt;blockquote type=&quot;cite&quot;&gt;
&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
I fully agree on this. &lt;br&gt;
&lt;br&gt;
It is required not only from AJAX scenario, but also from Assurance
Level discussions. &lt;br&gt;
&lt;br&gt;
For example, in SP800-63rev.1, Level 1 assertion must expire in 12
hours, Level 3 assertion in 30 min, &lt;br&gt;
and in IDABC Authentication Policy, &lt;br&gt;
&lt;br&gt;
Level 1: 24 hours, &lt;br&gt;
Level 2: 12 hours&lt;br&gt;
Level 3: 2 hours&lt;br&gt;
Level 4: Immediate (whatever it means...)&lt;br&gt;
&lt;br&gt;
Regards, &lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
&lt;br&gt;
Andrew Arnott wrote:
&lt;blockquote type=&quot;cite&quot;&gt;With the recent OpenID AJAX work I&amp;#39;ve been doing (&lt;a href=&quot;http://samples.dotnetopenauth.net/v3.2/openidrelyingpartywebforms/ajaxlogin.aspx&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;blog
commenting&lt;/a&gt; and &lt;a href=&quot;http://openidux.dotnetopenauth.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;popup login&lt;/a&gt;) I&amp;#39;ve run
across a problem that while small now, may grow as OpenID popularity
increases and AJAX use becomes more mainstream.  
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;When an OP sends a positive assertion signed with a private
association, the RP currently has no idea how long this assertion is
valid.  The OP has their own policy regarding how long before it
expires the assertion based on the response_nonce&amp;#39; timestamp. Some OPs
may reason &amp;quot;well, it should only take a few seconds for an RP to get
back to us to verify this, so any nonce more than 30 seconds old is
expired&amp;quot; in order to keep the used nonce bin from filling up too fast. &lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Here&amp;#39;s the problem: at least with my own AJAX designs, the
positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt; forwarded
immediately to the RP.  Several assertions are gathered, and the user
picks which one to log into the RP with, and to help protect the user&amp;#39;s
privacy, it&amp;#39;s not ideal to send all assertions to the RP or else it&amp;#39;s
easy for the RP to tie several identities together without the user&amp;#39;s
consent.&lt;i&gt; &lt;/i&gt; If the login screen is left open for several minutes,
these assertions can get stale.  Particularly in the blog commenting
scenario where the user my acquire the positive assertion before
writing his blog comment and thereby could wait 15 minutes or more
before posting his comment.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So far, I&amp;#39;m mitigating this at the RP by choosing a &amp;quot;reasonable&amp;quot;
maximum lifetime for the assertion and the javascript automatically
renews the positive assertion after the assertion is assumed to have
expired.  But since this guess at the assertion&amp;#39;s lifetime is not
correct for an arbitrary OP, it would be great if with the positive
assertion signed with a private association the OP could indicate with
another parameter how long the assertion is valid for so the RP
javascript code can renew at the optimal interval.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;What do you think?&lt;br clear=&quot;all&quot;&gt;
--&lt;br&gt;
Andrew Arnott&lt;br&gt;
&amp;quot;I [may] not agree with what you have to say, but I&amp;#39;ll defend to the
death your right to say it.&amp;quot; - S. G. Tallentyre&lt;br&gt;
  &lt;/div&gt;
  &lt;pre&gt;&lt;hr size=&quot;4&quot; width=&quot;90%&quot;&gt;_______________________________________________
specs mailing list
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26141060&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;/div&gt;

_______________________________________________&lt;br&gt;specs mailing list&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26141060&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26141060&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Nat Sakimura (=nat)&lt;br&gt;&lt;a href=&quot;http://www.sakimura.org/en/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sakimura.org/en/&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26141060&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26141060.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26139913</id>
	<title>Re: [OpenID] Content-Type for Key-Value Form response from OP</title>
	<published>2009-10-30T21:47:18Z</published>
	<updated>2009-10-30T21:47:18Z</updated>
	<author>
		<name>Andrew Arnott</name>
	</author>
	<content type="html">I don&amp;#39;t know how to make editorial changes to the spec.  So here&amp;#39;s the thread from a year or so ago, suggesting that OP responses containing Key-Value Form encoding include a content-type header of application/x-openid-kvf rather than text/plain or whatever else OPs might arbitrarily choose.&lt;div&gt;

&lt;br clear=&quot;all&quot;&gt;--&lt;br&gt;Andrew Arnott&lt;br&gt;&amp;quot;I [may] not agree with what you have to say, but I&amp;#39;ll defend to the death your right to say it.&amp;quot; - S. G. Tallentyre&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Fri, Jun 13, 2008 at 5:48 PM, Peter Williams &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pwilliams@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;

Make an editorial change to a spec, and submit for formal consideration to the spec list. Need be only 2 lines long, and the std iana declaration. Nobody recalls emails.&lt;br&gt;
&lt;br&gt;
________________________________&lt;br&gt;
From: Andrew Arnott &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrewarnott@...&lt;/a&gt;&amp;gt;&lt;br&gt;
Sent: Friday, June 13, 2008 5:45 PM&lt;br&gt;
&lt;div class=&quot;im&quot;&gt;To: OpenID List &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;&amp;gt;&lt;br&gt;
&lt;/div&gt;Subject: Re: [OpenID] Content-Type for Key-Value Form response from OP&lt;br&gt;
&lt;div class=&quot;im&quot;&gt;&lt;br&gt;
Unless I hear any objection then, I&amp;#39;m going to code up my library to respond with application/x-openid-kvf as the content-type for Key-Value Form encoded messages.&lt;br&gt;
&lt;br&gt;
Thanks for the help coming up with this, Martin.&lt;br&gt;
&lt;br&gt;
Andrew Arnott&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;On Wed, Jun 11, 2008 at 4:59 PM, Andrew Arnott &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrewarnott@...&lt;/a&gt;&amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrewarnott@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:&lt;br&gt;


(Forwarding to entire list since I hit Reply instead of Reply All).&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Thanks, Martin.  It sounds like application/x-kvf is better than text/kvf then.  Perhaps we can also be more descriptive then as say &amp;quot;application/x-openid-kvf&amp;quot;?&lt;br&gt;
&lt;br&gt;
Andrew Arnott&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;On Wed, Jun 11, 2008 at 1:48 PM, Martin Atkins &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mart@...&lt;/a&gt;&amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mart@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:&lt;br&gt;


Andrew Arnott wrote:&lt;br&gt;
&amp;gt; In that case, I move that we adopt text/kvf as the official Content-Type&lt;br&gt;
&amp;gt; for Key-Value Form encoding response messages.&lt;br&gt;
&amp;gt;&lt;br&gt;
&lt;br&gt;
Hi Andrew,&lt;br&gt;
&lt;br&gt;
Sorry I didn&amp;#39;t see your messages until now.&lt;br&gt;
&lt;br&gt;
I believe the convention for unregistered MIME types is to prefix the&lt;br&gt;
subtype part with &amp;quot;x-&amp;quot;, giving something like text/x-kvf.&lt;br&gt;
&lt;br&gt;
However, since the spec mandates UTF-8 for this message format, it may&lt;br&gt;
be more appropriate to use an &amp;quot;application/&amp;quot; type; text types generally&lt;br&gt;
support a &amp;quot;charset&amp;quot; attribute allowing the content to be in an arbitrary&lt;br&gt;
character encoding, which is not appropriate here.&lt;br&gt;
&lt;br&gt;
_______________________________________________&lt;br&gt;
general mailing list&lt;br&gt;
&lt;/div&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;&amp;lt;mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;&amp;gt;&lt;br&gt;
&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;a href=&quot;http://openid.net/mailman/listinfo/general&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/mailman/listinfo/general&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26139913&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A--OpenID--Content-Type-for-Key-Value-Form-response-from-OP-tp26139913p26139913.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26131464</id>
	<title>Re: OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-30T07:56:37Z</published>
	<updated>2009-10-30T07:56:37Z</updated>
	<author>
		<name>Andrew Arnott</name>
	</author>
	<content type="html">Sure, Allen.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Scenario 1&lt;/b&gt;&lt;/div&gt;&lt;div&gt;You know the &lt;a href=&quot;http://openidux.dotnetopenauth.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openidux.dotnetopenauth.net/&lt;/a&gt; prototype&amp;#39;s selector?  Well, all of those OP buttons simultaneously use checkid_immediate to try to obtain a positive assertion.  As you know, any OPs that have previously asserted the user&amp;#39;s identity at this RP (with &amp;quot;Remember me&amp;quot; checked at the OP) will succeed if the user is logged into the OP.  As each OP button on the selector succeeds at obtaining a positive assertion, it displays a green checkmark to the user, suggesting to him that this button was one he picked previously, and can now log in immediately (without any further interaction with his OP).  Not only does this optimize the login experience for the user, it helps the user avoid splintering his identity by picking 1 OP the first time, and a different OP the second time by accident.  &lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Also, since this prototype web site gives the user the ability to bind multiple authentication tokens to the same account, perhaps both Yahoo and Google&amp;#39;s OP buttons will get a green checkmark on the selector, and either one is the correct choice for the user since both will take the user to the same account.  In this instance, it&amp;#39;s particularly optimal for the user, who may not be logged into both Google and Yahoo, but only one.  The user doesn&amp;#39;t care which OP really does the authenticating this time -- but would like to use whichever one he happens to be logged into, and he might not remember which OP he&amp;#39;s logged into.  These green checkmarks say &amp;quot;Hey, if you click me, you&amp;#39;re guaranteed to be logged in immediately without additional interaction with your OP.&amp;quot;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now the point is, when these positive assertions are obtained and the green checkmark displayed, the positive assertion still has &lt;i&gt;not&lt;/i&gt; been sent to the RP (it&amp;#39;s web server).  It&amp;#39;s held in a Javascript dictionary of discovery results and assertions on the browser.  Why aren&amp;#39;t these positive assertions just sent to the RP immediately so it&amp;#39;s a non-issue?  Two big reasons:&lt;/div&gt;
&lt;div&gt;&lt;ol&gt;&lt;li&gt;Privacy for the user, particularly where the user is using different OPs at the same RP to manage &lt;i&gt;different&lt;/i&gt; accounts at the RP instead of the same account.  This prevents correlating of multiple identifiers at the same RP where the user doesn&amp;#39;t ask for it.&lt;/li&gt;
&lt;li&gt;If the RP verifies these assertions right away, it still must postpone logging the user into the RP until the user chooses which one to use to log in.  The RP must then, since it already invalidated the assertion by verifying it, cross-sign the assertion, send it back to the browser, and wait for one of those assertions to come back, then re-verify the assertion using that proprietary cross-signing mechanism.  Yech on several levels.&lt;/li&gt;
&lt;/ol&gt;&lt;div&gt;&lt;b&gt;Scenario 2&lt;/b&gt;&lt;/div&gt;&lt;div&gt;The blog commenting scenario, where the user never actually logs in, but writes his OpenID Identifier and a &lt;i&gt;long&lt;/i&gt; comment, during which time the positive assertion previously obtained expires.  The RP doesn&amp;#39;t want to maintain state for these... it simply wants to receive the assertion with the comment and thus be able to verify and process the comment in one step.&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Now that all said, I so far have implemented John&amp;#39;s suggestion of considering 5 minutes the maximum lifetime of a positive assertion and just renewing at that interval.  It seems to work well.  If you go to my prototype right now, open up the selector and see a green check mark, and wait exactly five minutes, you&amp;#39;ll see the checkmark disappear momentarily and then reappear as that assertion is refreshed.  &lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;--&lt;br&gt;Andrew Arnott&lt;br&gt;&amp;quot;I [may] not agree with what you have to say, but I&amp;#39;ll defend to the death your right to say it.&amp;quot; - S. G. Tallentyre&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Oct 29, 2009 at 9:44 PM, Allen Tom &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26131464&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atom@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;



  

&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;&lt;div class=&quot;im&quot;&gt;
Andrew Arnott wrote:
&lt;blockquote type=&quot;cite&quot;&gt;&lt;br&gt;
  &lt;div&gt;Here&amp;#39;s the problem: at least with my own AJAX designs, the
positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt; forwarded
immediately to the RP.  Several assertions are gathered, and the user
picks which one to log into the RP with,&lt;/div&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
Can you describe the use case in more detail? The RP has multiple
assertions from different OPs for the same user? &lt;br&gt;
&lt;br&gt;
Allen&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;

&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26131464&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26131464.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26124923</id>
	<title>Re: OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-29T21:44:33Z</published>
	<updated>2009-10-29T21:44:33Z</updated>
	<author>
		<name>Allen Tom-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
Andrew Arnott wrote:
&lt;blockquote cite=&quot;mid:216e54900910251704w5734d20au26d559765004ff2c@mail.gmail.com&quot; type=&quot;cite&quot;&gt;&lt;br&gt;
  &lt;div&gt;Here's the problem: at least with my own AJAX designs, the
positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt;&amp;nbsp;forwarded
immediately to the RP. &amp;nbsp;Several assertions are gathered, and the user
picks which one to log into the RP with,&lt;/div&gt;
&lt;/blockquote&gt;
&lt;br&gt;
Can you describe the use case in more detail? The RP has multiple
assertions from different OPs for the same user? &lt;br&gt;
&lt;br&gt;
Allen&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26124923&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26124923.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26061590</id>
	<title>Re: OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-26T08:05:59Z</published>
	<updated>2009-10-26T08:05:59Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">&lt;html&gt;&lt;head&gt;&lt;/head&gt;&lt;body style=&quot;word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; &quot;&gt;Nat &amp;nbsp;you are referring to the assertion lifetimes for a enterprise LAN environment.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;For a environment where the RP is not part of the same domain as the IdP.&lt;/div&gt;&lt;div&gt;Level 1: &amp;nbsp;5min&lt;/div&gt;&lt;div&gt;Level 2: &amp;nbsp;5min&lt;/div&gt;&lt;div&gt;Level 3: &amp;nbsp;5min&lt;/div&gt;&lt;div&gt;Level 4: &amp;nbsp;MUST NOT use bearer tokens. (Rules out openID)&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The Nonce contains a time stamp that should be used for this. &amp;nbsp;&lt;/div&gt;&lt;div&gt;Clock synchronization can become an issue with times this small. &amp;nbsp;NNTP please.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;We could add a TTL to the assertion however it may be as easy to say that OP keep private assertions for a minimum of 5 min.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Andrew's app should refresh any unsolicited positive assertions older than 5 min.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;It is interesting that JS can cache assertions like this.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;It perhaps also points out the possibility of people using this technique for cross site scripting to sites that a user thinks they are logged out of.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;John B.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;On 2009-10-26, at 3:40 AM, Nat Sakimura wrote:&lt;/div&gt;&lt;br class=&quot;Apple-interchange-newline&quot;&gt;&lt;blockquote type=&quot;cite&quot;&gt;
&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
I fully agree on this. &lt;br&gt;
&lt;br&gt;
It is required not only from AJAX scenario, but also from Assurance
Level discussions. &lt;br&gt;
&lt;br&gt;
For example, in SP800-63rev.1, Level 1 assertion must expire in 12
hours, Level 3 assertion in 30 min, &lt;br&gt;
and in IDABC Authentication Policy, &lt;br&gt;
&lt;br&gt;
Level 1: 24 hours, &lt;br&gt;
Level 2: 12 hours&lt;br&gt;
Level 3: 2 hours&lt;br&gt;
Level 4: Immediate (whatever it means...)&lt;br&gt;
&lt;br&gt;
Regards, &lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
&lt;br&gt;
Andrew Arnott wrote:
&lt;blockquote cite=&quot;mid:216e54900910251704w5734d20au26d559765004ff2c@mail.gmail.com&quot; type=&quot;cite&quot;&gt;With the recent OpenID AJAX work I've been doing (&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://samples.dotnetopenauth.net/v3.2/openidrelyingpartywebforms/ajaxlogin.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blog
commenting&lt;/a&gt; and &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openidux.dotnetopenauth.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;popup login&lt;/a&gt;) I've run
across a problem that while small now, may grow as OpenID popularity
increases and AJAX use becomes more mainstream. &amp;nbsp;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;When an OP sends a positive assertion signed with a private
association, the RP currently has no idea how long this assertion is
valid. &amp;nbsp;The OP has their own policy regarding how long before it
expires the assertion based on the response_nonce' timestamp. Some OPs
may reason &quot;well, it should only take a few seconds for an RP to get
back to us to verify this, so any nonce more than 30 seconds old is
expired&quot; in order to keep the used nonce bin from filling up too fast.&amp;nbsp;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Here's the problem: at least with my own AJAX designs, the
positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt;&amp;nbsp;forwarded
immediately to the RP. &amp;nbsp;Several assertions are gathered, and the user
picks which one to log into the RP with, and to help protect the user's
privacy, it's not ideal to send all assertions to the RP or else it's
easy for the RP to tie several identities together without the user's
consent.&lt;i&gt;&amp;nbsp;&lt;/i&gt; If the login screen is left open for several minutes,
these assertions can get stale. &amp;nbsp;Particularly in the blog commenting
scenario where the user my acquire the positive assertion before
writing his blog comment and thereby could wait 15 minutes or more
before posting his comment.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So far, I'm mitigating this at the RP by choosing a &quot;reasonable&quot;
maximum lifetime for the assertion and the javascript automatically
renews the positive assertion after the assertion is assumed to have
expired. &amp;nbsp;But since this guess at the assertion's lifetime is not
correct for an arbitrary OP, it would be great if with the positive
assertion signed with a private association the OP could indicate with
another parameter how long the assertion is valid for so the RP
javascript code can renew at the optimal interval.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;What do you think?&lt;br clear=&quot;all&quot;&gt;
--&lt;br&gt;
Andrew Arnott&lt;br&gt;
&quot;I [may] not agree with what you have to say, but I'll defend to the
death your right to say it.&quot; - S. G. Tallentyre&lt;br&gt;
  &lt;/div&gt;
  &lt;pre wrap=&quot;&quot;&gt;&lt;hr class=&quot;__postbox_mime_separator&quot; size=&quot;4&quot; width=&quot;90%&quot;&gt;
_______________________________________________
specs mailing list
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26061590&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;/div&gt;

_______________________________________________&lt;br&gt;specs mailing list&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26061590&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/body&gt;&lt;/html&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26061590&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (3K) &lt;a href=&quot;http://old.nabble.com/attachment/26061590/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26061590.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26055071</id>
	<title>Re: OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-25T23:40:49Z</published>
	<updated>2009-10-25T23:40:49Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html; charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
I fully agree on this. &lt;br&gt;
&lt;br&gt;
It is required not only from AJAX scenario, but also from Assurance
Level discussions. &lt;br&gt;
&lt;br&gt;
For example, in SP800-63rev.1, Level 1 assertion must expire in 12
hours, Level 3 assertion in 30 min, &lt;br&gt;
and in IDABC Authentication Policy, &lt;br&gt;
&lt;br&gt;
Level 1: 24 hours, &lt;br&gt;
Level 2: 12 hours&lt;br&gt;
Level 3: 2 hours&lt;br&gt;
Level 4: Immediate (whatever it means...)&lt;br&gt;
&lt;br&gt;
Regards, &lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
&lt;br&gt;
Andrew Arnott wrote:
&lt;blockquote cite=&quot;mid:216e54900910251704w5734d20au26d559765004ff2c@mail.gmail.com&quot; type=&quot;cite&quot;&gt;With the recent OpenID AJAX work I've been doing (&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://samples.dotnetopenauth.net/v3.2/openidrelyingpartywebforms/ajaxlogin.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blog
commenting&lt;/a&gt; and &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openidux.dotnetopenauth.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;popup login&lt;/a&gt;) I've run
across a problem that while small now, may grow as OpenID popularity
increases and AJAX use becomes more mainstream. &amp;nbsp;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;When an OP sends a positive assertion signed with a private
association, the RP currently has no idea how long this assertion is
valid. &amp;nbsp;The OP has their own policy regarding how long before it
expires the assertion based on the response_nonce' timestamp. Some OPs
may reason &quot;well, it should only take a few seconds for an RP to get
back to us to verify this, so any nonce more than 30 seconds old is
expired&quot; in order to keep the used nonce bin from filling up too fast.&amp;nbsp;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;Here's the problem: at least with my own AJAX designs, the
positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt;&amp;nbsp;forwarded
immediately to the RP. &amp;nbsp;Several assertions are gathered, and the user
picks which one to log into the RP with, and to help protect the user's
privacy, it's not ideal to send all assertions to the RP or else it's
easy for the RP to tie several identities together without the user's
consent.&lt;i&gt;&amp;nbsp;&lt;/i&gt; If the login screen is left open for several minutes,
these assertions can get stale. &amp;nbsp;Particularly in the blog commenting
scenario where the user my acquire the positive assertion before
writing his blog comment and thereby could wait 15 minutes or more
before posting his comment.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So far, I'm mitigating this at the RP by choosing a &quot;reasonable&quot;
maximum lifetime for the assertion and the javascript automatically
renews the positive assertion after the assertion is assumed to have
expired. &amp;nbsp;But since this guess at the assertion's lifetime is not
correct for an arbitrary OP, it would be great if with the positive
assertion signed with a private association the OP could indicate with
another parameter how long the assertion is valid for so the RP
javascript code can renew at the optimal interval.&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;What do you think?&lt;br clear=&quot;all&quot;&gt;
--&lt;br&gt;
Andrew Arnott&lt;br&gt;
&quot;I [may] not agree with what you have to say, but I'll defend to the
death your right to say it.&quot; - S. G. Tallentyre&lt;br&gt;
  &lt;/div&gt;
  &lt;pre wrap=&quot;&quot;&gt;
&lt;hr class=&quot;__postbox_mime_separator&quot; size=&quot;4&quot; width=&quot;90%&quot;&gt;
_______________________________________________
specs mailing list
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26055071&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26055071&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26055071.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26053184</id>
	<title>OpenID 2.1: timed priv. assoc. assertions</title>
	<published>2009-10-25T17:04:36Z</published>
	<updated>2009-10-25T17:04:36Z</updated>
	<author>
		<name>Andrew Arnott</name>
	</author>
	<content type="html">With the recent OpenID AJAX work I&amp;#39;ve been doing (&lt;a href=&quot;http://samples.dotnetopenauth.net/v3.2/openidrelyingpartywebforms/ajaxlogin.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blog commenting&lt;/a&gt; and &lt;a href=&quot;http://openidux.dotnetopenauth.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;popup login&lt;/a&gt;) I&amp;#39;ve run across a problem that while small now, may grow as OpenID popularity increases and AJAX use becomes more mainstream.  &lt;div&gt;

&lt;br&gt;&lt;/div&gt;&lt;div&gt;When an OP sends a positive assertion signed with a private association, the RP currently has no idea how long this assertion is valid.  The OP has their own policy regarding how long before it expires the assertion based on the response_nonce&amp;#39; timestamp. Some OPs may reason &amp;quot;well, it should only take a few seconds for an RP to get back to us to verify this, so any nonce more than 30 seconds old is expired&amp;quot; in order to keep the used nonce bin from filling up too fast. &lt;/div&gt;

&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Here&amp;#39;s the problem: at least with my own AJAX designs, the positive assertion the user agent obtains from the OP is &lt;i&gt;not&lt;/i&gt; forwarded immediately to the RP.  Several assertions are gathered, and the user picks which one to log into the RP with, and to help protect the user&amp;#39;s privacy, it&amp;#39;s not ideal to send all assertions to the RP or else it&amp;#39;s easy for the RP to tie several identities together without the user&amp;#39;s consent.&lt;i&gt; &lt;/i&gt; If the login screen is left open for several minutes, these assertions can get stale.  Particularly in the blog commenting scenario where the user my acquire the positive assertion before writing his blog comment and thereby could wait 15 minutes or more before posting his comment.&lt;/div&gt;

&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;So far, I&amp;#39;m mitigating this at the RP by choosing a &amp;quot;reasonable&amp;quot; maximum lifetime for the assertion and the javascript automatically renews the positive assertion after the assertion is assumed to have expired.  But since this guess at the assertion&amp;#39;s lifetime is not correct for an arbitrary OP, it would be great if with the positive assertion signed with a private association the OP could indicate with another parameter how long the assertion is valid for so the RP javascript code can renew at the optimal interval.&lt;/div&gt;

&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;What do you think?&lt;br clear=&quot;all&quot;&gt;--&lt;br&gt;Andrew Arnott&lt;br&gt;&amp;quot;I [may] not agree with what you have to say, but I&amp;#39;ll defend to the death your right to say it.&amp;quot; - S. G. Tallentyre&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26053184&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenID-2.1%3A-timed-priv.-assoc.-assertions-tp26053184p26053184.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25409935</id>
	<title>Re: [OpenID] RP library authors</title>
	<published>2009-09-11T16:31:31Z</published>
	<updated>2009-09-11T16:31:31Z</updated>
	<author>
		<name>John Bradley-9</name>
	</author>
	<content type="html">I would like to say there is some hidden plan that explains it, but no &amp;nbsp;
&lt;br&gt;it is an error.
&lt;br&gt;&lt;br&gt;The tech writer will be reprimanded.
&lt;br&gt;&lt;br&gt;I will have that fixed.
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;John B.
&lt;br&gt;&lt;br&gt;On 2009-09-11, at 7:15 PM, Tatsuki Sakushima wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi John,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The document misses a reference to the PAPE spec in Appendix D.
&lt;br&gt;&amp;gt; Is that done on purpose until some errors in the spec will be fixed?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Tatsuki
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Tatsuki Sakushima
&lt;br&gt;&amp;gt; NRI Pacific - Nomura Research Institute America, Inc.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; (9/11/09 8:49 AM), John Bradley wrote:
&lt;br&gt;&amp;gt;&amp;gt; The GSA profile for openID is available at:
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; Many things that are SHOULD in the openID 2.0 spec are now MUST in &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; the profile.
&lt;br&gt;&amp;gt;&amp;gt; There are new PAPE URI and other modifications.
&lt;br&gt;&amp;gt;&amp;gt; Most of the OP's supporting the profile will not be restricting it &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; to only Gov RP's.
&lt;br&gt;&amp;gt;&amp;gt; Any RP may elect to use all or parts of this new profile for any &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; purpose they choose.
&lt;br&gt;&amp;gt;&amp;gt; Also any OP is free to support it wether or not they are on the GSA &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; whitelist.
&lt;br&gt;&amp;gt;&amp;gt; To get on the GSA white-list OP's must support the profile and be &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; audited against a Trust Framework. &amp;nbsp;The OIDF has information &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; available an applying through it's program.
&lt;br&gt;&amp;gt;&amp;gt; There are quite a number of requirements on the RP side, that need &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; to be met.
&lt;br&gt;&amp;gt;&amp;gt; The sooner these features are in libraries the sooner government &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; agencies can move ahead with deployments.
&lt;br&gt;&amp;gt;&amp;gt; If there is interest we can set up a google group where developers &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; can get there questions on implementing the profile answered.
&lt;br&gt;&amp;gt;&amp;gt; If I can get to IIW in Nov, &amp;nbsp;I would like to organize a session on &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; this for people.
&lt;br&gt;&amp;gt;&amp;gt; There will be revisions to the profile in the future as we all gain &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; experience.
&lt;br&gt;&amp;gt;&amp;gt; The people who worked on the profile tried to profile only the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; existing specifications as written without inventing anything &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; incompatible with existing implementations.
&lt;br&gt;&amp;gt;&amp;gt; The GSA's goal is to enable as many existing identities as possible &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; to have access to govenment resources without making people create &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; new username and password accounts at each of the thousands &amp;nbsp;of &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; potential RP sites.
&lt;br&gt;&amp;gt;&amp;gt; Extra attention was taken to allow openID to be used without &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; divulging ANY PII to the government.
&lt;br&gt;&amp;gt;&amp;gt; This includes the use of a Pseudonymous openID identifier to allow &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; sites that can take no PII or do any correlation to still use openID.
&lt;br&gt;&amp;gt;&amp;gt; The regulation on this is quite strict. &amp;nbsp;We could not convert the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; ID to a pseudonym on the RP side and adhere to the regulation.
&lt;br&gt;&amp;gt;&amp;gt; We hope that the profile maximizes participation of OP's and RPs &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; alike, while not placing insurmountable burdens on developers.
&lt;br&gt;&amp;gt;&amp;gt; RP's and OP's that don't intend to make use of the profile need to &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; make no changes at all.
&lt;br&gt;&amp;gt;&amp;gt; I regret bot being able to share more of this with you sooner. &amp;nbsp;The &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; OIDF and the other foundations were requested not to discuss this &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; publicly until after the government announcements.
&lt;br&gt;&amp;gt;&amp;gt; Regards
&lt;br&gt;&amp;gt;&amp;gt; John Bradley
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25409935&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;general mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25409935&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-general&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-general&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OpenID--RP-library-authors-tp25403898p25409935.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25409760</id>
	<title>Re: [OpenID] RP library authors</title>
	<published>2009-09-11T16:15:43Z</published>
	<updated>2009-09-11T16:15:43Z</updated>
	<author>
		<name>Tatsuki Sakushima</name>
	</author>
	<content type="html">Hi John,
&lt;br&gt;&lt;br&gt;The document misses a reference to the PAPE spec in Appendix D.
&lt;br&gt;Is that done on purpose until some errors in the spec will be fixed?
&lt;br&gt;&lt;br&gt;Tatsuki
&lt;br&gt;&lt;br&gt;Tatsuki Sakushima
&lt;br&gt;NRI Pacific - Nomura Research Institute America, Inc.
&lt;br&gt;&lt;br&gt;(9/11/09 8:49 AM), John Bradley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; The GSA profile for openID is available at:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Many things that are SHOULD in the openID 2.0 spec are now MUST in the 
&lt;br&gt;&amp;gt; profile.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There are new PAPE URI and other modifications.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Most of the OP's supporting the profile will not be restricting it to 
&lt;br&gt;&amp;gt; only Gov RP's.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Any RP may elect to use all or parts of this new profile for any purpose 
&lt;br&gt;&amp;gt; they choose.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Also any OP is free to support it wether or not they are on the GSA 
&lt;br&gt;&amp;gt; whitelist.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; To get on the GSA white-list OP's must support the profile and be 
&lt;br&gt;&amp;gt; audited against a Trust Framework. &amp;nbsp;The OIDF has information available 
&lt;br&gt;&amp;gt; an applying through it's program.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There are quite a number of requirements on the RP side, that need to be 
&lt;br&gt;&amp;gt; met.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The sooner these features are in libraries the sooner government 
&lt;br&gt;&amp;gt; agencies can move ahead with deployments.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; If there is interest we can set up a google group where developers can 
&lt;br&gt;&amp;gt; get there questions on implementing the profile answered.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; If I can get to IIW in Nov, &amp;nbsp;I would like to organize a session on this 
&lt;br&gt;&amp;gt; for people.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There will be revisions to the profile in the future as we all gain 
&lt;br&gt;&amp;gt; experience.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The people who worked on the profile tried to profile only the existing 
&lt;br&gt;&amp;gt; specifications as written without inventing anything incompatible with 
&lt;br&gt;&amp;gt; existing implementations.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The GSA's goal is to enable as many existing identities as possible to 
&lt;br&gt;&amp;gt; have access to govenment resources without making people create new 
&lt;br&gt;&amp;gt; username and password accounts at each of the thousands &amp;nbsp;of potential RP 
&lt;br&gt;&amp;gt; sites.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Extra attention was taken to allow openID to be used without divulging 
&lt;br&gt;&amp;gt; ANY PII to the government.
&lt;br&gt;&amp;gt; This includes the use of a Pseudonymous openID identifier to allow sites 
&lt;br&gt;&amp;gt; that can take no PII or do any correlation to still use openID.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The regulation on this is quite strict. &amp;nbsp;We could not convert the ID to 
&lt;br&gt;&amp;gt; a pseudonym on the RP side and adhere to the regulation.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; We hope that the profile maximizes participation of OP's and RPs alike, 
&lt;br&gt;&amp;gt; while not placing insurmountable burdens on developers.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; RP's and OP's that don't intend to make use of the profile need to make 
&lt;br&gt;&amp;gt; no changes at all.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I regret bot being able to share more of this with you sooner. &amp;nbsp;The OIDF 
&lt;br&gt;&amp;gt; and the other foundations were requested not to discuss this publicly 
&lt;br&gt;&amp;gt; until after the government announcements.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Regards
&lt;br&gt;&amp;gt; John Bradley
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25409760&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;/div&gt;_______________________________________________
&lt;br&gt;general mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25409760&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-general&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-general&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OpenID--RP-library-authors-tp25403898p25409760.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25403898</id>
	<title>[OpenID] RP library authors</title>
	<published>2009-09-11T08:49:18Z</published>
	<updated>2009-09-11T08:49:18Z</updated>
	<author>
		<name>John Bradley-9</name>
	</author>
	<content type="html">The GSA profile for openID is available at:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.idmanagement.gov/documents/ICAM_OpenID20Profile.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;Many things that are SHOULD in the openID 2.0 spec are now MUST in the &amp;nbsp;
&lt;br&gt;profile.
&lt;br&gt;&lt;br&gt;There are new PAPE URI and other modifications.
&lt;br&gt;&lt;br&gt;Most of the OP's supporting the profile will not be restricting it to &amp;nbsp;
&lt;br&gt;only Gov RP's.
&lt;br&gt;&lt;br&gt;Any RP may elect to use all or parts of this new profile for any &amp;nbsp;
&lt;br&gt;purpose they choose.
&lt;br&gt;&lt;br&gt;Also any OP is free to support it wether or not they are on the GSA &amp;nbsp;
&lt;br&gt;whitelist.
&lt;br&gt;&lt;br&gt;To get on the GSA white-list OP's must support the profile and be &amp;nbsp;
&lt;br&gt;audited against a Trust Framework. &amp;nbsp;The OIDF has information available &amp;nbsp;
&lt;br&gt;an applying through it's program.
&lt;br&gt;&lt;br&gt;There are quite a number of requirements on the RP side, that need to &amp;nbsp;
&lt;br&gt;be met.
&lt;br&gt;&lt;br&gt;The sooner these features are in libraries the sooner government &amp;nbsp;
&lt;br&gt;agencies can move ahead with deployments.
&lt;br&gt;&lt;br&gt;If there is interest we can set up a google group where developers can &amp;nbsp;
&lt;br&gt;get there questions on implementing the profile answered.
&lt;br&gt;&lt;br&gt;If I can get to IIW in Nov, &amp;nbsp;I would like to organize a session on &amp;nbsp;
&lt;br&gt;this for people.
&lt;br&gt;&lt;br&gt;There will be revisions to the profile in the future as we all gain &amp;nbsp;
&lt;br&gt;experience.
&lt;br&gt;&lt;br&gt;The people who worked on the profile tried to profile only the &amp;nbsp;
&lt;br&gt;existing specifications as written without inventing anything &amp;nbsp;
&lt;br&gt;incompatible with existing implementations.
&lt;br&gt;&lt;br&gt;The GSA's goal is to enable as many existing identities as possible to &amp;nbsp;
&lt;br&gt;have access to govenment resources without making people create new &amp;nbsp;
&lt;br&gt;username and password accounts at each of the thousands &amp;nbsp;of potential &amp;nbsp;
&lt;br&gt;RP sites.
&lt;br&gt;&lt;br&gt;Extra attention was taken to allow openID to be used without divulging &amp;nbsp;
&lt;br&gt;ANY PII to the government.
&lt;br&gt;This includes the use of a Pseudonymous openID identifier to allow &amp;nbsp;
&lt;br&gt;sites that can take no PII or do any correlation to still use openID.
&lt;br&gt;&lt;br&gt;The regulation on this is quite strict. &amp;nbsp;We could not convert the ID &amp;nbsp;
&lt;br&gt;to a pseudonym on the RP side and adhere to the regulation.
&lt;br&gt;&lt;br&gt;We hope that the profile maximizes participation of OP's and RPs &amp;nbsp;
&lt;br&gt;alike, while not placing insurmountable burdens on developers.
&lt;br&gt;&lt;br&gt;RP's and OP's that don't intend to make use of the profile need to &amp;nbsp;
&lt;br&gt;make no changes at all.
&lt;br&gt;&lt;br&gt;I regret bot being able to share more of this with you sooner. &amp;nbsp;The &amp;nbsp;
&lt;br&gt;OIDF and the other foundations were requested not to discuss this &amp;nbsp;
&lt;br&gt;publicly until after the government announcements.
&lt;br&gt;&lt;br&gt;Regards
&lt;br&gt;John Bradley
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;general mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25403898&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;general@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-general&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-general&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-OpenID--RP-library-authors-tp25403898p25403898.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25299044</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-04T10:57:08Z</published>
	<updated>2009-09-04T10:57:08Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">Typing in a directed identity URL is perfectly acceptable, &amp;nbsp;and &amp;nbsp;
&lt;br&gt;required for some OP Google if there is no dedicated button.
&lt;br&gt;&lt;br&gt;Unless we change openID 2.0 (a possibility) &amp;nbsp;we currently have two &amp;nbsp;
&lt;br&gt;existing services &amp;lt;Type&amp;gt;
&lt;br&gt;One for normal logins and one for identifier select.
&lt;br&gt;&lt;br&gt;We need one rel each for that. &amp;nbsp;They exiting &amp;lt;Type&amp;gt; URI may well work.
&lt;br&gt;&lt;br&gt;I don't know that delegating is the correct word for this.
&lt;br&gt;It is not necessarily openID delegation.
&lt;br&gt;&lt;br&gt;It is an indirection to another XRD to get more information about the &amp;nbsp;
&lt;br&gt;desired relationship.
&lt;br&gt;&lt;br&gt;In XRI 2.0 this was called a redirect, but was not used by XRDS-Simple.
&lt;br&gt;&lt;br&gt;How openID uses LRDD and XRD to resolve endpoints is not something &amp;nbsp;
&lt;br&gt;that will be in the XRD spec itself.
&lt;br&gt;&lt;br&gt;It may be that we decide we don't need a special rel for the provider &amp;nbsp;
&lt;br&gt;relationship and that having the media type application/xrd+xml on the &amp;nbsp;
&lt;br&gt;two current rels is sufficient.
&lt;br&gt;&lt;br&gt;One other thing to think about is that we do have optional &amp;lt;Type&amp;gt; &amp;nbsp;
&lt;br&gt;elements for PAPE, AX, SREG and perhaps others.
&lt;br&gt;&lt;br&gt;Should those go in the users XRD as hints to RPs as additional rel &amp;nbsp;
&lt;br&gt;pointing to the providers XRD?
&lt;br&gt;&lt;br&gt;There are a bunch of things that we need to discuss about how XRD can &amp;nbsp;
&lt;br&gt;be used for openID discovery.
&lt;br&gt;&lt;br&gt;John B.
&lt;br&gt;On 2009-09-04, at 1:27 PM, Santosh Rajan wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If I understood you correctly, you are suggesting 2 endpoints and 1 &amp;nbsp;
&lt;br&gt;&amp;gt; delegate
&lt;br&gt;&amp;gt; Rel for Openid. The 2nd endpoint for identifier select.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Now this is what I am not clear about. Pls correct me If I am wrong.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1) Since the subject of this discussion is the users XRD, identifier &amp;nbsp;
&lt;br&gt;&amp;gt; select
&lt;br&gt;&amp;gt; is not relevant here. The RP already has the users claimed_id. That &amp;nbsp;
&lt;br&gt;&amp;gt; is what
&lt;br&gt;&amp;gt; he would have typed in (his OpenID) to get to his XRD. Unless of &amp;nbsp;
&lt;br&gt;&amp;gt; cource he
&lt;br&gt;&amp;gt; typed his email like identifier, (which is webfinger).
&lt;br&gt;&amp;gt; 2) If the user typed in his directed identity (a misnomer according to
&lt;br&gt;&amp;gt; some), that would be handled by his host-meta which would delegate &amp;nbsp;
&lt;br&gt;&amp;gt; to his
&lt;br&gt;&amp;gt; XRDS like this.
&lt;br&gt;&amp;gt; &amp;lt;XRD&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;lt;Host&amp;gt;example.com&amp;lt;/Host&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;lt;Link&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;Rel&amp;gt;&lt;a href=&quot;http://openid.net/rel/delegate&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/delegate&lt;/a&gt;&amp;lt;/Rel&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://whatever.com/08/id&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://whatever.com/08/id&lt;/a&gt;&amp;lt;/URI&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;MediaType&amp;gt;application/xrds+xml&amp;lt;MediaType&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;&amp;lt;/Link&amp;gt;
&lt;br&gt;&amp;gt; &amp;lt;/XRD&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please note above the mediatype is &amp;quot;xrds&amp;quot; not &amp;quot;xrd&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Also I think Nat's suggestion that we need a separate thread to &amp;nbsp;
&lt;br&gt;&amp;gt; discuss
&lt;br&gt;&amp;gt; OpenID discovery WRT LRDD is what is required. I would go one step &amp;nbsp;
&lt;br&gt;&amp;gt; more and
&lt;br&gt;&amp;gt; suggest we need a wiki page under &amp;quot;emerging tech&amp;quot;.
&lt;br&gt;&amp;gt; If nobody wants to do that, I will do that if I find time this &amp;nbsp;
&lt;br&gt;&amp;gt; weekend. :-)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; John Bradley-7 wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We still need two endpoints as well as the delegate to support
&lt;br&gt;&amp;gt;&amp;gt; identifier select with openID 2.0.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; John B.
&lt;br&gt;&amp;gt;&amp;gt; On 2009-09-03, at 9:30 AM, Santosh Rajan wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; To make discovery easier &amp;nbsp;for an RP, I suggest we limit the RP to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; look for one of two resources in a users XRD.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 1) An OpenID Endpoint
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 2) An OpenID Delegate.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; If an OpenID endpoint is not available in a users XRD, the RP will
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; next look for a delegated host. In both cases the RP is looking for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; a Rel value in a Link Element. So I suggest something like this for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Rel values
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 1) &lt;a href=&quot;http://openid.net/rel/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 2) &lt;a href=&quot;http://openid.net/rel/delegate&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/delegate&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Sep 3, 2009 at 10:55 AM, Nat Sakimura &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The first XRD in my example is the &amp;quot;User Discovery&amp;quot; XRD in Dirk's
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; post.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I am talking about what to use for &amp;lt;rel&amp;gt; URI here.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; In XRI TC's discussion, we disccussed that it probably is not &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; right to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; use the same URI for both &amp;quot;User Discovery&amp;quot; document (which defines
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; relationship, &amp;quot;Relationship URI&amp;quot;) and &amp;quot;Provider Discovery&amp;quot; (which
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; defines the service).
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I suppose Dirk is using the same URI just for the lack of this
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;quot;Relationship URI&amp;quot;.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Also, in Dirk's example, in User Discovery, he is siting
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://openid.example.com/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I suppose this is somewhat misleading.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I suppose it should be
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (Note: I have added # to denote that it is pointing to a non
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; information resource.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; As it is a non-information resource, the matching information
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; resource has to be
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; discovered by some other protocol, such as LRDD/site-meta.)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; latest XRD schema.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; It is unified with &amp;lt;Subject&amp;gt;. How to express the &amp;quot;Subject Set&amp;quot; or
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; entire domain is
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; still under discussion, I believe, in site-meta discussion. The last
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I have seen is
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; something like: &amp;lt;Subject&amp;gt;site-meta://example.com&amp;lt;/Subject&amp;gt;.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Personally, I do not like it. (W3C people will not either, I think.)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; What some XRI TC people suggested was to use something like
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but this is
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; something
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; that should be discussed in another thread.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; What I was referring to as &amp;quot;not sure&amp;quot; was whether we need to support
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; all types of LRDD
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; or just one, for OpenID. I have got an opinion on that but I am
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; intending to start
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; yet another thread for that. (Or somebody else can do so. I am
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; rather time constrained.)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I think it is a good practice to separate those threads and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; concentrate on one issue
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; per thread so that we can avoid drifting discussion.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; This thread is only about the Relationship URI.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Santosh Rajan wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; There is an article posted here related to this.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; So how does this work in the above framework?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; So, User's XRD would have something like
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is fetched during the discovery. (I am still not so sure about
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the relationship between X-XRDS-Location: header and site_meta etc.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Are we abandoning the header model?)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; get the Service's XRD like:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; to find out the concrete endpoint of this authentication service.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; John Bradley wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Allen,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In XRD 1.0 we are moving to a link based model.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; So a users XRD rather than having to specify the openID providers
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; service can point to an openID provider.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; The URIs that we currently use describe the service not the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; provider.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I think Nat is looking for a link relationship that describes a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; user pointing &amp;nbsp;to a service providers XRD rather than to the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; service itself.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; There will be a bunch of new link types required for various
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; protocols.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; John B.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On 2009-09-02, at 5:27 PM, Allen Tom wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hi Nat,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Can you explain the problem in a bit more detail? Can you give an
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; example use case?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thanks
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Allen
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Nat Sakimura wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; relationship.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; What shall we use?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Something like:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -- 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -- 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Santosh Rajan
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; View this message in context: &lt;a href=&quot;http://www.nabble.com/XRD-and-OpenID-2.1-tp25252899p25298589.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/XRD-and-OpenID-2.1-tp25252899p25298589.html&lt;/a&gt;&lt;br&gt;&amp;gt; Sent from the OpenID - Specs mailing list archive at Nabble.com.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25299044&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25299044.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25298589</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-04T10:27:57Z</published>
	<updated>2009-09-04T10:27:57Z</updated>
	<author>
		<name>Santosh Rajan</name>
	</author>
	<content type="html">If I understood you correctly, you are suggesting 2 endpoints and 1 delegate Rel for Openid. The 2nd endpoint for identifier select.
&lt;br&gt;&lt;br&gt;Now this is what I am not clear about. Pls correct me If I am wrong.
&lt;br&gt;&lt;br&gt;1) Since the subject of this discussion is the users XRD, identifier select is not relevant here. The RP already has the users claimed_id. That is what he would have typed in (his OpenID) to get to his XRD. Unless of cource he typed his email like identifier, (which is webfinger).
&lt;br&gt;2) If the user typed in his directed identity (a misnomer according to some), that would be handled by his host-meta which would delegate to his XRDS like this.
&lt;br&gt;&amp;lt;XRD&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;lt;Host&amp;gt;example.com&amp;lt;/Host&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;lt;Link&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;Rel&amp;gt;&lt;a href=&quot;http://openid.net/rel/delegate&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/delegate&lt;/a&gt;&amp;lt;/Rel&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;URI&amp;gt;&lt;a href=&quot;http://whatever.com/08/id&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://whatever.com/08/id&lt;/a&gt;&amp;lt;/URI&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;MediaType&amp;gt;application/xrds+xml&amp;lt;MediaType&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;lt;/Link&amp;gt;
&lt;br&gt;&amp;lt;/XRD&amp;gt;
&lt;br&gt;&lt;br&gt;Please note above the mediatype is &amp;quot;xrds&amp;quot; not &amp;quot;xrd&amp;quot;.
&lt;br&gt;&lt;br&gt;Also I think Nat's suggestion that we need a separate thread to discuss OpenID discovery WRT LRDD is what is required. I would go one step more and suggest we need a wiki page under &amp;quot;emerging tech&amp;quot;.
&lt;br&gt;If nobody wants to do that, I will do that if I find time this weekend. :-)
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;John Bradley-7 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;We still need two endpoints as well as the delegate to support &amp;nbsp;
&lt;br&gt;identifier select with openID 2.0.
&lt;br&gt;&lt;br&gt;John B.
&lt;br&gt;On 2009-09-03, at 9:30 AM, Santosh Rajan wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; To make discovery easier &amp;nbsp;for an RP, I suggest we limit the RP to &amp;nbsp;
&lt;br&gt;&amp;gt; look for one of two resources in a users XRD.
&lt;br&gt;&amp;gt; 1) An OpenID Endpoint
&lt;br&gt;&amp;gt; 2) An OpenID Delegate.
&lt;br&gt;&amp;gt; If an OpenID endpoint is not available in a users XRD, the RP will &amp;nbsp;
&lt;br&gt;&amp;gt; next look for a delegated host. In both cases the RP is looking for &amp;nbsp;
&lt;br&gt;&amp;gt; a Rel value in a Link Element. So I suggest something like this for &amp;nbsp;
&lt;br&gt;&amp;gt; Rel values
&lt;br&gt;&amp;gt; 1) &lt;a href=&quot;http://openid.net/rel/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&lt;br&gt;&amp;gt; 2) &lt;a href=&quot;http://openid.net/rel/delegate&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/delegate&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Sep 3, 2009 at 10:55 AM, Nat Sakimura &amp;lt;n-sakimura@nri.co.jp&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; The first XRD in my example is the &amp;quot;User Discovery&amp;quot; XRD in Dirk's &amp;nbsp;
&lt;br&gt;&amp;gt; post.
&lt;br&gt;&amp;gt; I am talking about what to use for &amp;lt;rel&amp;gt; URI here.
&lt;br&gt;&amp;gt; In XRI TC's discussion, we disccussed that it probably is not right to
&lt;br&gt;&amp;gt; use the same URI for both &amp;quot;User Discovery&amp;quot; document (which defines
&lt;br&gt;&amp;gt; relationship, &amp;quot;Relationship URI&amp;quot;) and &amp;quot;Provider Discovery&amp;quot; (which &amp;nbsp;
&lt;br&gt;&amp;gt; defines the service).
&lt;br&gt;&amp;gt; I suppose Dirk is using the same URI just for the lack of this &amp;nbsp;
&lt;br&gt;&amp;gt; &amp;quot;Relationship URI&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Also, in Dirk's example, in User Discovery, he is siting
&lt;br&gt;&amp;gt; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://openid.example.com/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I suppose this is somewhat misleading.
&lt;br&gt;&amp;gt; I suppose it should be
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; (Note: I have added # to denote that it is pointing to a non &amp;nbsp;
&lt;br&gt;&amp;gt; information resource.
&lt;br&gt;&amp;gt; As it is a non-information resource, the matching information &amp;nbsp;
&lt;br&gt;&amp;gt; resource has to be
&lt;br&gt;&amp;gt; discovered by some other protocol, such as LRDD/site-meta.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in the &amp;nbsp;
&lt;br&gt;&amp;gt; latest XRD schema.
&lt;br&gt;&amp;gt; It is unified with &amp;lt;Subject&amp;gt;. How to express the &amp;quot;Subject Set&amp;quot; or &amp;nbsp;
&lt;br&gt;&amp;gt; entire domain is
&lt;br&gt;&amp;gt; still under discussion, I believe, in site-meta discussion. The last &amp;nbsp;
&lt;br&gt;&amp;gt; I have seen is
&lt;br&gt;&amp;gt; something like: &amp;lt;Subject&amp;gt;site-meta://example.com&amp;lt;/Subject&amp;gt;.
&lt;br&gt;&amp;gt; Personally, I do not like it. (W3C people will not either, I think.)
&lt;br&gt;&amp;gt; What some XRI TC people suggested was to use something like
&lt;br&gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but this is &amp;nbsp;
&lt;br&gt;&amp;gt; something
&lt;br&gt;&amp;gt; that should be discussed in another thread.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What I was referring to as &amp;quot;not sure&amp;quot; was whether we need to support &amp;nbsp;
&lt;br&gt;&amp;gt; all types of LRDD
&lt;br&gt;&amp;gt; or just one, for OpenID. I have got an opinion on that but I am &amp;nbsp;
&lt;br&gt;&amp;gt; intending to start
&lt;br&gt;&amp;gt; yet another thread for that. (Or somebody else can do so. I am &amp;nbsp;
&lt;br&gt;&amp;gt; rather time constrained.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I think it is a good practice to separate those threads and &amp;nbsp;
&lt;br&gt;&amp;gt; concentrate on one issue
&lt;br&gt;&amp;gt; per thread so that we can avoid drifting discussion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This thread is only about the Relationship URI.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Santosh Rajan wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; There is an article posted here related to this.
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; So how does this work in the above framework?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura &amp;lt;n-sakimura@nri.co.jp&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; So, User's XRD would have something like
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; This is fetched during the discovery. (I am still not so sure about
&lt;br&gt;&amp;gt;&amp;gt; the relationship between X-XRDS-Location: header and site_meta etc.
&lt;br&gt;&amp;gt;&amp;gt; Are we abandoning the header model?)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.
&lt;br&gt;&amp;gt;&amp;gt; Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt; to
&lt;br&gt;&amp;gt;&amp;gt; get the Service's XRD like:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; to find out the concrete endpoint of this authentication service.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; John Bradley wrote:
&lt;br&gt;&amp;gt;&amp;gt; Allen,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In XRD 1.0 we are moving to a link based model.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; So a users XRD rather than having to specify the openID providers &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; service can point to an openID provider.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The URIs that we currently use describe the service not the provider.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I think Nat is looking for a link relationship that describes a &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; user pointing &amp;nbsp;to a service providers XRD rather than to the &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; service itself.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; There will be a bunch of new link types required for various &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; protocols.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; John B.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On 2009-09-02, at 5:27 PM, Allen Tom wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi Nat,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Can you explain the problem in a bit more detail? Can you give an &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; example use case?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks
&lt;br&gt;&amp;gt;&amp;gt; Allen
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Nat Sakimura wrote:
&lt;br&gt;&amp;gt;&amp;gt; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; relationship.
&lt;br&gt;&amp;gt;&amp;gt; What shall we use?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Something like:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; specs@lists.openid.net
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; specs@lists.openid.net
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; specs@lists.openid.net
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -- 
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;specs@lists.openid.net
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
&lt;div class=&quot;signature&quot;&gt;
Santosh Rajan
&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25298589.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25298082</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-04T09:57:53Z</published>
	<updated>2009-09-04T09:57:53Z</updated>
	<author>
		<name>Santosh Rajan</name>
	</author>
	<content type="html">Yes, &lt;a href=&quot;http://openid.net/rel/my_op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/my_op&lt;/a&gt;&amp;nbsp;looks better.
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Nat Sakimura-2 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;You do not want to state the endpoint. You only want to sate the 
&lt;br&gt;provider, IMHO.
&lt;br&gt;So, &lt;a href=&quot;http://openid.net/rel/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&amp;nbsp;would not be a good naming.
&lt;br&gt;I like something in the line of
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://openid.net/rel/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/op&lt;/a&gt;&amp;nbsp;etc. or more verbose version of it like:
&lt;br&gt;&lt;a href=&quot;http://openid.net/rel/my_op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/my_op&lt;/a&gt;&amp;nbsp;etc.
&lt;br&gt;&lt;br&gt;=nat
&lt;br&gt;&lt;br&gt;Santosh Rajan wrote:
&lt;br&gt;&amp;gt; To make discovery easier &amp;nbsp;for an RP, I suggest we limit the RP to look 
&lt;br&gt;&amp;gt; for one of two resources in a users XRD.
&lt;br&gt;&amp;gt; 1) An OpenID Endpoint
&lt;br&gt;&amp;gt; 2) An OpenID Delegate.
&lt;br&gt;&amp;gt; If an OpenID endpoint is not available in a users XRD, the RP will 
&lt;br&gt;&amp;gt; next look for a delegated host. In both cases the RP is looking for a 
&lt;br&gt;&amp;gt; Rel value in a Link Element. So I suggest something like this for Rel 
&lt;br&gt;&amp;gt; values
&lt;br&gt;&amp;gt; 1) &lt;a href=&quot;http://openid.net/rel/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2) &lt;a href=&quot;http://openid.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;gt;/rel/delegate
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Sep 3, 2009 at 10:55 AM, Nat Sakimura &amp;lt;n-sakimura@nri.co.jp 
&lt;br&gt;&amp;gt; &amp;lt;mailto:n-sakimura@nri.co.jp&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; The first XRD in my example is the &amp;quot;User Discovery&amp;quot; XRD in Dirk's
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; post.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I am talking about what to use for &amp;lt;rel&amp;gt; URI here.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; In XRI TC's discussion, we disccussed that it probably is not
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; right to
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; use the same URI for both &amp;quot;User Discovery&amp;quot; document (which defines
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; relationship, &amp;quot;Relationship URI&amp;quot;) and &amp;quot;Provider Discovery&amp;quot; (which
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; defines the service).
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I suppose Dirk is using the same URI just for the lack of this
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;quot;Relationship URI&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Also, in Dirk's example, in User Discovery, he is siting
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://openid.example.com/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I suppose this is somewhat misleading.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I suppose it should be
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;URI&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; (Note: I have added # to denote that it is pointing to a non
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; information resource.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; As it is a non-information resource, the matching information
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; resource has to be
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; discovered by some other protocol, such as LRDD/site-meta.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; the latest XRD schema.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; It is unified with &amp;lt;Subject&amp;gt;. How to express the &amp;quot;Subject Set&amp;quot; or
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; entire domain is
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; still under discussion, I believe, in site-meta discussion. The
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; last I have seen is
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; something like: &amp;lt;Subject&amp;gt;site-meta://example.com
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;&lt;a href=&quot;http://example.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com&lt;/a&gt;&amp;gt;&amp;lt;/Subject&amp;gt;.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Personally, I do not like it. (W3C people will not either, I think.)
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; What some XRI TC people suggested was to use something like
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but this is
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; something
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; that should be discussed in another thread.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; What I was referring to as &amp;quot;not sure&amp;quot; was whether we need to
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; support all types of LRDD
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; or just one, for OpenID. I have got an opinion on that but I am
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; intending to start
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; yet another thread for that. (Or somebody else can do so. I am
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; rather time constrained.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I think it is a good practice to separate those threads and
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; concentrate on one issue
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; per thread so that we can avoid drifting discussion.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; This thread is only about the Relationship URI.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; =nat
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Santosh Rajan wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; There is an article posted here related to this.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; So how does this work in the above framework?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;lt;n-sakimura@nri.co.jp &amp;lt;mailto:n-sakimura@nri.co.jp&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; So, User's XRD would have something like
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This is fetched during the discovery. (I am still not so sure
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; about
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; the relationship between X-XRDS-Location: header and
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; site_meta etc.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Are we abandoning the header model?)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Once it was found, the RP goes to the url specified in the
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;link&amp;gt; to
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; get the Service's XRD like:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/link&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/xrd&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; to find out the concrete endpoint of this authentication service.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; =nat
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; John Bradley wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Allen,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; In XRD 1.0 we are moving to a link based model.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; So a users XRD rather than having to specify the openID
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; providers service can point to an openID provider.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The URIs that we currently use describe the service not
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; the provider.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; I think Nat is looking for a link relationship that
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; describes a user pointing &amp;nbsp;to a service providers XRD
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; rather than to the service itself.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; There will be a bunch of new link types required for
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; various protocols.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; John B.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; On 2009-09-02, at 5:27 PM, Allen Tom wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hi Nat,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Can you explain the problem in a bit more detail? Can
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you give an example use case?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Thanks
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Allen
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Nat Sakimura wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; the user=OP relationship.
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; What shall we use?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Something like:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; =nat
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs@lists.openid.net
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;mailto:specs@lists.openid.net&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs@lists.openid.net &amp;lt;mailto:specs@lists.openid.net&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; specs@lists.openid.net &amp;lt;mailto:specs@lists.openid.net&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; -- 
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; specs@lists.openid.net
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;specs@lists.openid.net
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
&lt;div class=&quot;signature&quot;&gt;
Santosh Rajan
&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25298082.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25288280</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-03T21:48:44Z</published>
	<updated>2009-09-03T21:48:44Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html; charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
You do not want to state the endpoint. You only want to sate the
provider, IMHO. &lt;br&gt;
So, &lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://openid.net/rel/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt; would not be a good naming. &lt;br&gt;
I like something in the line of &lt;br&gt;
&lt;br&gt;
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://openid.net/rel/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/op&lt;/a&gt; etc. or more verbose version of it like: &lt;br&gt;
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://openid.net/rel/my_op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/my_op&lt;/a&gt; etc. &lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
&lt;br&gt;
Santosh Rajan wrote:
&lt;blockquote cite=&quot;mid:b6b112650909030630yd9f731bo52dce9cb35ce7772@mail.gmail.com&quot; type=&quot;cite&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: arial,sans-serif; font-size: 13px; border-collapse: collapse;&quot;&gt;To
make discovery easier &amp;nbsp;for an RP, I suggest we limit the RP to look for
one of two resources in a users XRD.
  &lt;div&gt;1) An OpenID Endpoint&lt;/div&gt;
  &lt;div&gt;2) An OpenID Delegate.&lt;/div&gt;
  &lt;div&gt;If an OpenID endpoint is not available in a users XRD, the RP
will next look for a delegated host. In both cases the RP is looking
for a Rel value in a Link Element. So I suggest something like this for
Rel values&lt;/div&gt;
  &lt;div&gt;1)&amp;nbsp;&lt;span style=&quot;font-family: arial,sans-serif; font-size: 13px; border-collapse: collapse;&quot;&gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176);&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
  &lt;div&gt;&lt;span style=&quot;font-size: 13px;&quot;&gt;&lt;/span&gt;&lt;font face=&quot;arial, sans-serif&quot;&gt;&lt;span style=&quot;border-collapse: collapse;&quot;&gt;2)&amp;nbsp;&lt;span style=&quot;font-size: 13px;&quot;&gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176);&quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;/rel/delegate&lt;/span&gt;&lt;br&gt;
  &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;
  &lt;/span&gt;&lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 10:55 AM, Nat
Sakimura &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
    &lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;The first XRD in my example
is the &quot;User Discovery&quot; XRD in Dirk's post.
    &lt;br&gt;
I am talking about what to use for &amp;lt;rel&amp;gt; URI here. &lt;br&gt;
In XRI TC's discussion, we disccussed that it probably is not right to &lt;br&gt;
use the same URI for both &quot;User Discovery&quot; document (which defines &lt;br&gt;
relationship, &quot;Relationship URI&quot;) and &quot;Provider Discovery&quot; (which
defines the service). &lt;br&gt;
I suppose Dirk is using the same URI just for the lack of this
&quot;Relationship URI&quot;. &lt;br&gt;
    &lt;br&gt;
Also, in Dirk's example, in User Discovery, he is siting &lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.example.com/op&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;&lt;br&gt;
    &lt;br&gt;
I suppose this is somewhat misleading. &lt;br&gt;
I suppose it should be &lt;br&gt;
    &lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;&lt;br&gt;
    &lt;br&gt;
(Note: I have added # to denote that it is pointing to a non
information resource. &lt;br&gt;
As it is a non-information resource, the matching information resource
has to be &lt;br&gt;
discovered by some other protocol, such as LRDD/site-meta.)&lt;br&gt;
    &lt;br&gt;
As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in
the latest XRD schema. &lt;br&gt;
It is unified with &amp;lt;Subject&amp;gt;. How to express the &quot;Subject Set&quot; or
entire domain is &lt;br&gt;
still under discussion, I believe, in site-meta discussion. The last I
have seen is &lt;br&gt;
something like: &amp;lt;Subject&amp;gt;site-meta://&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://example.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;example.com&lt;/a&gt;&amp;lt;/Subject&amp;gt;.
    &lt;br&gt;
Personally, I do not like it. (W3C people will not either, I think.) &lt;br&gt;
What some XRI TC people suggested was to use something like &lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW,
but
this is something &lt;br&gt;
that should be discussed in another thread. &lt;br&gt;
    &lt;br&gt;
What I was referring to as &quot;not sure&quot; was whether we need to support
all types of LRDD &lt;br&gt;
or just one, for OpenID. I have got an opinion on that but I am
intending to start &lt;br&gt;
yet another thread for that. (Or somebody else can do so. I am rather
time constrained.) &lt;br&gt;
    &lt;br&gt;
I think it is a good practice to separate those threads and concentrate
on one issue &lt;br&gt;
per thread so that we can avoid drifting discussion. &lt;br&gt;
    &lt;br&gt;
This thread is only about the Relationship URI. &lt;br&gt;
    &lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
=nat&lt;/font&gt;
    &lt;div&gt;
    &lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
    &lt;br&gt;
    &lt;br&gt;
Santosh Rajan wrote:
    &lt;blockquote type=&quot;cite&quot;&gt;There is an article posted here related to
this.
      &lt;div&gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;/div&gt;
      &lt;div&gt;&lt;br&gt;
      &lt;/div&gt;
      &lt;div&gt;So how does this work in the above framework?&lt;/div&gt;
      &lt;div&gt;&lt;br&gt;
      &lt;br&gt;
      &lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 9:26 AM, Nat
Sakimura &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
      &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;So,
User's
XRD would have something like&lt;br&gt;
        &lt;br&gt;
&amp;lt;xrd id=&quot;foo&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://sakimura.org/nat&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
        &lt;br&gt;
This is fetched during the discovery. (I am still not so sure about&lt;br&gt;
the relationship between X-XRDS-Location: header and site_meta etc.&lt;br&gt;
Are we abandoning the header model?)&lt;br&gt;
        &lt;br&gt;
Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.&lt;br&gt;
Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt;
to&lt;br&gt;
get the Service's XRD like:&lt;br&gt;
        &lt;br&gt;
&amp;lt;xrd id=&quot;baa&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
        &lt;br&gt;
to find out the concrete endpoint of this authentication service.&lt;br&gt;
        &lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
=nat&lt;/font&gt;
        &lt;div&gt;
        &lt;div&gt;&lt;br&gt;
        &lt;br&gt;
John Bradley wrote:&lt;br&gt;
        &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;Allen,&lt;br&gt;
          &lt;br&gt;
In XRD 1.0 we are moving to a link based model.&lt;br&gt;
          &lt;br&gt;
So a users XRD rather than having to specify the openID providers
service can point to an openID provider.&lt;br&gt;
          &lt;br&gt;
The URIs that we currently use describe the service not the provider.&lt;br&gt;
          &lt;br&gt;
I think Nat is looking for a link relationship that describes a user
pointing &amp;nbsp;to a service providers XRD rather than to the service itself.&lt;br&gt;
          &lt;br&gt;
There will be a bunch of new link types required for various protocols.&lt;br&gt;
          &lt;br&gt;
John B.&lt;br&gt;
          &lt;br&gt;
          &lt;br&gt;
On 2009-09-02, at 5:27 PM, Allen Tom wrote:&lt;br&gt;
          &lt;br&gt;
          &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;Hi
Nat,&lt;br&gt;
            &lt;br&gt;
Can you explain the problem in a bit more detail? Can you give an
example use case?&lt;br&gt;
            &lt;br&gt;
Thanks&lt;br&gt;
Allen&lt;br&gt;
            &lt;br&gt;
            &lt;br&gt;
Nat Sakimura wrote:&lt;br&gt;
            &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;The
second topic for OpenID 2.1&lt;br&gt;
              &lt;br&gt;
Maybe, it should be separated to the Discovery but...&lt;br&gt;
              &lt;br&gt;
In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP
relationship.&lt;br&gt;
What shall we use?&lt;br&gt;
              &lt;br&gt;
Something like:&lt;br&gt;
              &lt;br&gt;
              &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;
              &lt;br&gt;
=nat&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
              &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
              &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
            &lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
            &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
            &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
        &lt;/blockquote&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
        &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
        &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
        &lt;/div&gt;
        &lt;/div&gt;
      &lt;/blockquote&gt;
      &lt;/div&gt;
      &lt;br&gt;
      &lt;br clear=&quot;all&quot;&gt;
      &lt;br&gt;
-- &lt;br&gt;
      &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;
      &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
      &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
      &lt;br&gt;
      &lt;br&gt;
      &lt;/div&gt;
    &lt;/blockquote&gt;
    &lt;/div&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;br&gt;
  &lt;br clear=&quot;all&quot;&gt;
  &lt;br&gt;
-- &lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  &lt;pre wrap=&quot;&quot;&gt;
&lt;hr class=&quot;__postbox_mime_separator&quot; size=&quot;4&quot; width=&quot;90%&quot;&gt;
_______________________________________________
specs mailing list
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25288280&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25288280.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25283669</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-03T13:35:59Z</published>
	<updated>2009-09-03T13:35:59Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">&lt;html&gt;&lt;head&gt;&lt;/head&gt;&lt;body style=&quot;word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; &quot;&gt;We still need two endpoints as well as the delegate to support identifier select with openID 2.0.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;John B.&lt;br&gt;&lt;div&gt;&lt;div&gt;On 2009-09-03, at 9:30 AM, Santosh Rajan wrote:&lt;/div&gt;&lt;br class=&quot;Apple-interchange-newline&quot;&gt;&lt;blockquote type=&quot;cite&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: arial, sans-serif; font-size: 13px; border-collapse: collapse; &quot;&gt;To make discovery easier &amp;nbsp;for an RP, I suggest we limit the RP to look for one of two resources in a users XRD.&lt;div&gt;
1) An OpenID Endpoint&lt;/div&gt;&lt;div&gt;2) An OpenID Delegate.&lt;/div&gt;&lt;div&gt;If an OpenID endpoint is not available in a users XRD, the RP will next look for a delegated host. In both cases the RP is looking for a Rel value in a Link Element. So I suggest something like this for Rel values&lt;/div&gt;
&lt;div&gt;1)&amp;nbsp;&lt;span style=&quot;font-family: arial, sans-serif; font-size: 13px; border-collapse: collapse; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span style=&quot;font-size: 13px; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;&lt;/a&gt;&lt;/span&gt;&lt;font face=&quot;arial, sans-serif&quot;&gt;&lt;span style=&quot;border-collapse: collapse; &quot;&gt;2)&amp;nbsp;&lt;span style=&quot;font-size: 13px; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;/rel/delegate&lt;/span&gt;&lt;br&gt;
&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/span&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 10:55 AM, Nat Sakimura &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;



  
  

&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
The first XRD in my example is the &quot;User Discovery&quot; XRD in Dirk's post.
&lt;br&gt;
I am talking about what to use for &amp;lt;rel&amp;gt; URI here. &lt;br&gt;
In XRI TC's discussion, we disccussed that it probably is not right to &lt;br&gt;
use the same URI for both &quot;User Discovery&quot; document (which defines &lt;br&gt;
relationship, &quot;Relationship URI&quot;) and &quot;Provider Discovery&quot; (which
defines the service). &lt;br&gt;
I suppose Dirk is using the same URI just for the lack of this
&quot;Relationship URI&quot;. &lt;br&gt;
&lt;br&gt;
Also, in Dirk's example, in User Discovery, he is siting &lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a href=&quot;http://openid.example.com/op&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;&lt;br&gt;
&lt;br&gt;
I suppose this is somewhat misleading. &lt;br&gt;
I suppose it should be &lt;br&gt;
&lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;&lt;br&gt;
&lt;br&gt;
(Note: I have added # to denote that it is pointing to a non
information resource. &lt;br&gt;
As it is a non-information resource, the matching information resource
has to be &lt;br&gt;
discovered by some other protocol, such as LRDD/site-meta.)&lt;br&gt;
&lt;br&gt;
As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in
the latest XRD schema. &lt;br&gt;
It is unified with &amp;lt;Subject&amp;gt;. How to express the &quot;Subject Set&quot; or
entire domain is &lt;br&gt;
still under discussion, I believe, in site-meta discussion. The last I
have seen is &lt;br&gt;
something like: &amp;lt;Subject&amp;gt;site-meta://&lt;a href=&quot;http://example.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;example.com&lt;/a&gt;&amp;lt;/Subject&amp;gt;.
&lt;br&gt;
Personally, I do not like it. (W3C people will not either, I think.) &lt;br&gt;
What some XRI TC people suggested was to use something like &lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but
this is something &lt;br&gt;
that should be discussed in another thread. &lt;br&gt;
&lt;br&gt;
What I was referring to as &quot;not sure&quot; was whether we need to support
all types of LRDD &lt;br&gt;
or just one, for OpenID. I have got an opinion on that but I am
intending to start &lt;br&gt;
yet another thread for that. (Or somebody else can do so. I am rather
time constrained.) &lt;br&gt;
&lt;br&gt;
I think it is a good practice to separate those threads and concentrate
on one issue &lt;br&gt;
per thread so that we can avoid drifting discussion. &lt;br&gt;
&lt;br&gt;
This thread is only about the Relationship URI. &lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
=nat&lt;/font&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Santosh Rajan wrote:
&lt;blockquote type=&quot;cite&quot;&gt;There is an article posted here related to this.
  &lt;div&gt;&lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So how does this work in the above framework?&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura
  &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;So,
User's XRD would have something like&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&quot;foo&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
This is fetched during the discovery. (I am still not so sure about&lt;br&gt;
the relationship between X-XRDS-Location: header and site_meta etc.&lt;br&gt;
Are we abandoning the header model?)&lt;br&gt;
    &lt;br&gt;
Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.&lt;br&gt;
Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt;
to&lt;br&gt;
get the Service's XRD like:&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&quot;baa&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
to find out the concrete endpoint of this authentication service.&lt;br&gt;
    &lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
=nat&lt;/font&gt;
    &lt;div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;br&gt;
John Bradley wrote:&lt;br&gt;
    &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
Allen,&lt;br&gt;
      &lt;br&gt;
In XRD 1.0 we are moving to a link based model.&lt;br&gt;
      &lt;br&gt;
So a users XRD rather than having to specify the openID providers
service can point to an openID provider.&lt;br&gt;
      &lt;br&gt;
The URIs that we currently use describe the service not the provider.&lt;br&gt;
      &lt;br&gt;
I think Nat is looking for a link relationship that describes a user
pointing &amp;nbsp;to a service providers XRD rather than to the service itself.&lt;br&gt;
      &lt;br&gt;
There will be a bunch of new link types required for various protocols.&lt;br&gt;
      &lt;br&gt;
John B.&lt;br&gt;
      &lt;br&gt;
      &lt;br&gt;
On 2009-09-02, at 5:27 PM, Allen Tom wrote:&lt;br&gt;
      &lt;br&gt;
      &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
Hi Nat,&lt;br&gt;
        &lt;br&gt;
Can you explain the problem in a bit more detail? Can you give an
example use case?&lt;br&gt;
        &lt;br&gt;
Thanks&lt;br&gt;
Allen&lt;br&gt;
        &lt;br&gt;
        &lt;br&gt;
Nat Sakimura wrote:&lt;br&gt;
        &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
The second topic for OpenID 2.1&lt;br&gt;
          &lt;br&gt;
Maybe, it should be separated to the Discovery but...&lt;br&gt;
          &lt;br&gt;
In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP
relationship.&lt;br&gt;
What shall we use?&lt;br&gt;
          &lt;br&gt;
Something like:&lt;br&gt;
          &lt;br&gt;
          &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;
          &lt;br&gt;
=nat&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
          &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
          &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
        &lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
        &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
        &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
    &lt;/blockquote&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
    &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
    &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;br&gt;
  &lt;br clear=&quot;all&quot;&gt;
  &lt;br&gt;
-- &lt;br&gt;
  &lt;a href=&quot;http://santrajan.blogspot.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;
  &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
  &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  &lt;/div&gt;
&lt;/blockquote&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;

&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;&lt;a href=&quot;http://santrajan.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/body&gt;&lt;/html&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25283669&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25283669.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25276087</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-03T06:30:10Z</published>
	<updated>2009-09-03T06:30:10Z</updated>
	<author>
		<name>Santosh Rajan</name>
	</author>
	<content type="html">&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: arial, sans-serif; font-size: 13px; border-collapse: collapse; &quot;&gt;To make discovery easier  for an RP, I suggest we limit the RP to look for one of two resources in a users XRD.&lt;div&gt;
1) An OpenID Endpoint&lt;/div&gt;&lt;div&gt;2) An OpenID Delegate.&lt;/div&gt;&lt;div&gt;If an OpenID endpoint is not available in a users XRD, the RP will next look for a delegated host. In both cases the RP is looking for a Rel value in a Link Element. So I suggest something like this for Rel values&lt;/div&gt;
&lt;div&gt;1) &lt;span style=&quot;font-family: arial, sans-serif; font-size: 13px; border-collapse: collapse; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rel/endpoint&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span style=&quot;font-size: 13px; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;&lt;/a&gt;&lt;/span&gt;&lt;font face=&quot;arial, sans-serif&quot;&gt;&lt;span style=&quot;border-collapse: collapse; &quot;&gt;2) &lt;span style=&quot;font-size: 13px; &quot;&gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; style=&quot;color: rgb(42, 93, 176); &quot; rel=&quot;nofollow&quot;&gt;http://openid.net&lt;/a&gt;/rel/delegate&lt;/span&gt;&lt;br&gt;
&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;/span&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 10:55 AM, Nat Sakimura &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;



  
  

&lt;div bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
The first XRD in my example is the &amp;quot;User Discovery&amp;quot; XRD in Dirk&amp;#39;s post.
&lt;br&gt;
I am talking about what to use for &amp;lt;rel&amp;gt; URI here. &lt;br&gt;
In XRI TC&amp;#39;s discussion, we disccussed that it probably is not right to &lt;br&gt;
use the same URI for both &amp;quot;User Discovery&amp;quot; document (which defines &lt;br&gt;
relationship, &amp;quot;Relationship URI&amp;quot;) and &amp;quot;Provider Discovery&amp;quot; (which
defines the service). &lt;br&gt;
I suppose Dirk is using the same URI just for the lack of this
&amp;quot;Relationship URI&amp;quot;. &lt;br&gt;
&lt;br&gt;
Also, in Dirk&amp;#39;s example, in User Discovery, he is siting &lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a href=&quot;http://openid.example.com/op&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;&lt;br&gt;
&lt;br&gt;
I suppose this is somewhat misleading. &lt;br&gt;
I suppose it should be &lt;br&gt;
&lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;&lt;br&gt;
&lt;br&gt;
(Note: I have added # to denote that it is pointing to a non
information resource. &lt;br&gt;
As it is a non-information resource, the matching information resource
has to be &lt;br&gt;
discovered by some other protocol, such as LRDD/site-meta.)&lt;br&gt;
&lt;br&gt;
As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in
the latest XRD schema. &lt;br&gt;
It is unified with &amp;lt;Subject&amp;gt;. How to express the &amp;quot;Subject Set&amp;quot; or
entire domain is &lt;br&gt;
still under discussion, I believe, in site-meta discussion. The last I
have seen is &lt;br&gt;
something like: &amp;lt;Subject&amp;gt;site-meta://&lt;a href=&quot;http://example.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;example.com&lt;/a&gt;&amp;lt;/Subject&amp;gt;.
&lt;br&gt;
Personally, I do not like it. (W3C people will not either, I think.) &lt;br&gt;
What some XRI TC people suggested was to use something like &lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://example.com/#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but
this is something &lt;br&gt;
that should be discussed in another thread. &lt;br&gt;
&lt;br&gt;
What I was referring to as &amp;quot;not sure&amp;quot; was whether we need to support
all types of LRDD &lt;br&gt;
or just one, for OpenID. I have got an opinion on that but I am
intending to start &lt;br&gt;
yet another thread for that. (Or somebody else can do so. I am rather
time constrained.) &lt;br&gt;
&lt;br&gt;
I think it is a good practice to separate those threads and concentrate
on one issue &lt;br&gt;
per thread so that we can avoid drifting discussion. &lt;br&gt;
&lt;br&gt;
This thread is only about the Relationship URI. &lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
=nat&lt;/font&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Santosh Rajan wrote:
&lt;blockquote type=&quot;cite&quot;&gt;There is an article posted here related to this.
  &lt;div&gt;&lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So how does this work in the above framework?&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura
  &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;So,
User&amp;#39;s XRD would have something like&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
This is fetched during the discovery. (I am still not so sure about&lt;br&gt;
the relationship between X-XRDS-Location: header and site_meta etc.&lt;br&gt;
Are we abandoning the header model?)&lt;br&gt;
    &lt;br&gt;
Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.&lt;br&gt;
Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt;
to&lt;br&gt;
get the Service&amp;#39;s XRD like:&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
to find out the concrete endpoint of this authentication service.&lt;br&gt;
    &lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
=nat&lt;/font&gt;
    &lt;div&gt;
    &lt;div&gt;&lt;br&gt;
    &lt;br&gt;
John Bradley wrote:&lt;br&gt;
    &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
Allen,&lt;br&gt;
      &lt;br&gt;
In XRD 1.0 we are moving to a link based model.&lt;br&gt;
      &lt;br&gt;
So a users XRD rather than having to specify the openID providers
service can point to an openID provider.&lt;br&gt;
      &lt;br&gt;
The URIs that we currently use describe the service not the provider.&lt;br&gt;
      &lt;br&gt;
I think Nat is looking for a link relationship that describes a user
pointing  to a service providers XRD rather than to the service itself.&lt;br&gt;
      &lt;br&gt;
There will be a bunch of new link types required for various protocols.&lt;br&gt;
      &lt;br&gt;
John B.&lt;br&gt;
      &lt;br&gt;
      &lt;br&gt;
On 2009-09-02, at 5:27 PM, Allen Tom wrote:&lt;br&gt;
      &lt;br&gt;
      &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
Hi Nat,&lt;br&gt;
        &lt;br&gt;
Can you explain the problem in a bit more detail? Can you give an
example use case?&lt;br&gt;
        &lt;br&gt;
Thanks&lt;br&gt;
Allen&lt;br&gt;
        &lt;br&gt;
        &lt;br&gt;
Nat Sakimura wrote:&lt;br&gt;
        &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left:1px solid rgb(204, 204, 204);margin:0pt 0pt 0pt 0.8ex;padding-left:1ex&quot;&gt;
The second topic for OpenID 2.1&lt;br&gt;
          &lt;br&gt;
Maybe, it should be separated to the Discovery but...&lt;br&gt;
          &lt;br&gt;
In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP
relationship.&lt;br&gt;
What shall we use?&lt;br&gt;
          &lt;br&gt;
Something like:&lt;br&gt;
          &lt;br&gt;
          &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;
          &lt;br&gt;
=nat&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
          &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
          &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
        &lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
        &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
        &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
    &lt;/blockquote&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
    &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
    &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;br&gt;
  &lt;br clear=&quot;all&quot;&gt;
  &lt;br&gt;
-- &lt;br&gt;
  &lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;
  &lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
  &lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  &lt;/div&gt;
&lt;/blockquote&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;

&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25276087&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;signature&quot;&gt;
Santosh Rajan
&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25276087.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25270016</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-02T22:25:50Z</published>
	<updated>2009-09-02T22:25:50Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html; charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
  &lt;title&gt;&lt;/title&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
The first XRD in my example is the &quot;User Discovery&quot; XRD in Dirk's post.
&lt;br&gt;
I am talking about what to use for &amp;lt;rel&amp;gt; URI here. &lt;br&gt;
In XRI TC's discussion, we disccussed that it probably is not right to &lt;br&gt;
use the same URI for both &quot;User Discovery&quot; document (which defines &lt;br&gt;
relationship, &quot;Relationship URI&quot;) and &quot;Provider Discovery&quot; (which
defines the service). &lt;br&gt;
I suppose Dirk is using the same URI just for the lack of this
&quot;Relationship URI&quot;. &lt;br&gt;
&lt;br&gt;
Also, in Dirk's example, in User Discovery, he is siting &lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://openid.example.com/op&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.example.com/op&lt;/a&gt;&amp;lt;/URI&amp;gt;&lt;br&gt;
&lt;br&gt;
I suppose this is somewhat misleading. &lt;br&gt;
I suppose it should be &lt;br&gt;
&lt;br&gt;
&amp;lt;URI&amp;gt;&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;URI&amp;gt;&lt;br&gt;
&lt;br&gt;
(Note: I have added # to denote that it is pointing to a non
information resource. &lt;br&gt;
As it is a non-information resource, the matching information resource
has to be &lt;br&gt;
discovered by some other protocol, such as LRDD/site-meta.)&lt;br&gt;
&lt;br&gt;
As to the Provider Discovery is concerned, there is no &amp;lt;Host&amp;gt; in
the latest XRD schema. &lt;br&gt;
It is unified with &amp;lt;Subject&amp;gt;. How to express the &quot;Subject Set&quot; or
entire domain is &lt;br&gt;
still under discussion, I believe, in site-meta discussion. The last I
have seen is &lt;br&gt;
something like: &amp;lt;Subject&amp;gt;site-meta://example.com&amp;lt;/Subject&amp;gt;.
&lt;br&gt;
Personally, I do not like it. (W3C people will not either, I think.) &lt;br&gt;
What some XRI TC people suggested was to use something like &lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a class=&quot;moz-txt-link-freetext&quot; href=&quot;http://example.com/#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://example.com/#&lt;/a&gt;&amp;lt;/Subject&amp;gt; as in AWWW, but
this is something &lt;br&gt;
that should be discussed in another thread. &lt;br&gt;
&lt;br&gt;
What I was referring to as &quot;not sure&quot; was whether we need to support
all types of LRDD &lt;br&gt;
or just one, for OpenID. I have got an opinion on that but I am
intending to start &lt;br&gt;
yet another thread for that. (Or somebody else can do so. I am rather
time constrained.) &lt;br&gt;
&lt;br&gt;
I think it is a good practice to separate those threads and concentrate
on one issue &lt;br&gt;
per thread so that we can avoid drifting discussion. &lt;br&gt;
&lt;br&gt;
This thread is only about the Relationship URI. &lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Santosh Rajan wrote:
&lt;blockquote cite=&quot;mid:b6b112650909022127j67927124u99ffd7049679f88c@mail.gmail.com&quot; type=&quot;cite&quot;&gt;There is an article posted here related to this.
  &lt;div&gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;/div&gt;
  &lt;div&gt;So how does this work in the above framework?&lt;/div&gt;
  &lt;div&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura
  &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25270016&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt;
wrote:&lt;br&gt;
  &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;So,
User's XRD would have something like&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&quot;foo&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://sakimura.org/nat&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
This is fetched during the discovery. (I am still not so sure about&lt;br&gt;
the relationship between X-XRDS-Location: header and site_meta etc.&lt;br&gt;
Are we abandoning the header model?)&lt;br&gt;
    &lt;br&gt;
Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.&lt;br&gt;
Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt;
to&lt;br&gt;
get the Service's XRD like:&lt;br&gt;
    &lt;br&gt;
&amp;lt;xrd id=&quot;baa&quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
    &lt;br&gt;
to find out the concrete endpoint of this authentication service.&lt;br&gt;
    &lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
=nat&lt;/font&gt;
    &lt;div&gt;
    &lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
    &lt;br&gt;
John Bradley wrote:&lt;br&gt;
    &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Allen,&lt;br&gt;
      &lt;br&gt;
In XRD 1.0 we are moving to a link based model.&lt;br&gt;
      &lt;br&gt;
So a users XRD rather than having to specify the openID providers
service can point to an openID provider.&lt;br&gt;
      &lt;br&gt;
The URIs that we currently use describe the service not the provider.&lt;br&gt;
      &lt;br&gt;
I think Nat is looking for a link relationship that describes a user
pointing &amp;nbsp;to a service providers XRD rather than to the service itself.&lt;br&gt;
      &lt;br&gt;
There will be a bunch of new link types required for various protocols.&lt;br&gt;
      &lt;br&gt;
John B.&lt;br&gt;
      &lt;br&gt;
      &lt;br&gt;
On 2009-09-02, at 5:27 PM, Allen Tom wrote:&lt;br&gt;
      &lt;br&gt;
      &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hi Nat,&lt;br&gt;
        &lt;br&gt;
Can you explain the problem in a bit more detail? Can you give an
example use case?&lt;br&gt;
        &lt;br&gt;
Thanks&lt;br&gt;
Allen&lt;br&gt;
        &lt;br&gt;
        &lt;br&gt;
Nat Sakimura wrote:&lt;br&gt;
        &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
The second topic for OpenID 2.1&lt;br&gt;
          &lt;br&gt;
Maybe, it should be separated to the Discovery but...&lt;br&gt;
          &lt;br&gt;
In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP
relationship.&lt;br&gt;
What shall we use?&lt;br&gt;
          &lt;br&gt;
Something like:&lt;br&gt;
          &lt;br&gt;
          &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;
          &lt;br&gt;
=nat&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
          &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25270016&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
          &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
        &lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
        &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25270016&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
        &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/blockquote&gt;
    &lt;/blockquote&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
    &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25270016&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
    &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
    &lt;/div&gt;
    &lt;/div&gt;
  &lt;/blockquote&gt;
  &lt;/div&gt;
  &lt;br&gt;
  &lt;br clear=&quot;all&quot;&gt;
  &lt;br&gt;
-- &lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
  &lt;a moz-do-not-send=&quot;true&quot; href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  &lt;/div&gt;
&lt;/blockquote&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25270016&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25270016.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25269640</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-02T21:27:43Z</published>
	<updated>2009-09-02T21:27:43Z</updated>
	<author>
		<name>Santosh Rajan</name>
	</author>
	<content type="html">There is an article posted here related to this.&lt;div&gt;&lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;
&lt;a href=&quot;http://www.hueniverse.com/hueniverse/2009/09/openid-and-lrdd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;/a&gt;So how does this work in the above framework?&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Sep 3, 2009 at 9:26 AM, Nat Sakimura &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269640&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;n-sakimura@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;So, User&amp;#39;s XRD would have something like&lt;br&gt;
&lt;br&gt;
&amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
&lt;br&gt;
This is fetched during the discovery. (I am still not so sure about&lt;br&gt;
the relationship between X-XRDS-Location: header and site_meta etc.&lt;br&gt;
Are we abandoning the header model?)&lt;br&gt;
&lt;br&gt;
Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.&lt;br&gt;
Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt; to&lt;br&gt;
get the Service&amp;#39;s XRD like:&lt;br&gt;
&lt;br&gt;
&amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;&lt;br&gt;
&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;&lt;br&gt;
&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;&lt;br&gt;
&amp;lt;link&amp;gt;&lt;br&gt;
&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;&lt;br&gt;
&amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;&lt;br&gt;
&amp;lt;/link&amp;gt;&lt;br&gt;
&amp;lt;/xrd&amp;gt;&lt;br&gt;
&lt;br&gt;
to find out the concrete endpoint of this authentication service.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
=nat&lt;/font&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;h5&quot;&gt;&lt;br&gt;
&lt;br&gt;
John Bradley wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
Allen,&lt;br&gt;
&lt;br&gt;
In XRD 1.0 we are moving to a link based model.&lt;br&gt;
&lt;br&gt;
So a users XRD rather than having to specify the openID providers service can point to an openID provider.&lt;br&gt;
&lt;br&gt;
The URIs that we currently use describe the service not the provider.&lt;br&gt;
&lt;br&gt;
I think Nat is looking for a link relationship that describes a user pointing  to a service providers XRD rather than to the service itself.&lt;br&gt;
&lt;br&gt;
There will be a bunch of new link types required for various protocols.&lt;br&gt;
&lt;br&gt;
John B.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
On 2009-09-02, at 5:27 PM, Allen Tom wrote:&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
Hi Nat,&lt;br&gt;
&lt;br&gt;
Can you explain the problem in a bit more detail? Can you give an example use case?&lt;br&gt;
&lt;br&gt;
Thanks&lt;br&gt;
Allen&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Nat Sakimura wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
The second topic for OpenID 2.1&lt;br&gt;
&lt;br&gt;
Maybe, it should be separated to the Discovery but...&lt;br&gt;
&lt;br&gt;
In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP relationship.&lt;br&gt;
What shall we use?&lt;br&gt;
&lt;br&gt;
Something like:&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
=nat&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269640&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt; &lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269640&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt; &lt;br&gt;
&lt;/blockquote&gt;&lt;/blockquote&gt;
_______________________________________________&lt;br&gt;
specs mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269640&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://twitter.com/santoshrajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://twitter.com/santoshrajan&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.facebook.com/santosh.rajan&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.facebook.com/santosh.rajan&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269640&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;signature&quot;&gt;
Santosh Rajan
&lt;a href=&quot;http://santrajan.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://santrajan.blogspot.com&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25269640.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25269443</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-02T20:56:18Z</published>
	<updated>2009-09-02T20:56:18Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">So, User's XRD would have something like
&lt;br&gt;&lt;br&gt;&amp;lt;xrd id=&amp;quot;foo&amp;quot;&amp;gt;
&lt;br&gt;&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://sakimura.org/nat&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sakimura.org/nat&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;lt;ds:Signature&amp;gt; ... &amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;lt;link&amp;gt;
&lt;br&gt;&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/rels/myopenid_provider&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/rels/myopenid_provider&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;lt;url&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;lt;/link&amp;gt;
&lt;br&gt;&amp;lt;/xrd&amp;gt;
&lt;br&gt;&lt;br&gt;This is fetched during the discovery. (I am still not so sure about
&lt;br&gt;the relationship between X-XRDS-Location: header and site_meta etc.
&lt;br&gt;Are we abandoning the header model?)
&lt;br&gt;&lt;br&gt;Then, the RP searches for my relationship with OP through &amp;lt;rel&amp;gt;.
&lt;br&gt;Once it was found, the RP goes to the url specified in the &amp;lt;link&amp;gt; to
&lt;br&gt;get the Service's XRD like:
&lt;br&gt;&lt;br&gt;&amp;lt;xrd id=&amp;quot;baa&amp;quot;&amp;gt;
&lt;br&gt;&amp;lt;Subject&amp;gt;&lt;a href=&quot;http://myopenid.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://myopenid.net/&lt;/a&gt;&amp;lt;/Subject&amp;gt;
&lt;br&gt;&amp;lt;ds:Signature&amp;gt;...&amp;lt;/ds:Signature&amp;gt;
&lt;br&gt;&amp;lt;link&amp;gt;
&lt;br&gt;&amp;lt;rel&amp;gt;&lt;a href=&quot;http://openid.net/op/endpoint&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openid.net/op/endpoint&lt;/a&gt;&amp;lt;/rel&amp;gt;
&lt;br&gt;&amp;lt;url&amp;gt;&lt;a href=&quot;http://specs.openid.net/auth/2.0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/auth/2.0&lt;/a&gt;&amp;lt;/url&amp;gt;
&lt;br&gt;&amp;lt;/link&amp;gt;
&lt;br&gt;&amp;lt;/xrd&amp;gt;
&lt;br&gt;&lt;br&gt;to find out the concrete endpoint of this authentication service.
&lt;br&gt;&lt;br&gt;=nat
&lt;br&gt;&lt;br&gt;John Bradley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Allen,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In XRD 1.0 we are moving to a link based model.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; So a users XRD rather than having to specify the openID providers 
&lt;br&gt;&amp;gt; service can point to an openID provider.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The URIs that we currently use describe the service not the provider.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I think Nat is looking for a link relationship that describes a user 
&lt;br&gt;&amp;gt; pointing &amp;nbsp;to a service providers XRD rather than to the service itself.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; There will be a bunch of new link types required for various protocols.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; John B.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On 2009-09-02, at 5:27 PM, Allen Tom wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi Nat,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Can you explain the problem in a bit more detail? Can you give an 
&lt;br&gt;&amp;gt;&amp;gt; example use case?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks
&lt;br&gt;&amp;gt;&amp;gt; Allen
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Nat Sakimura wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; relationship.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; What shall we use?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Something like:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269443&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269443&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&amp;nbsp;
&lt;/div&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25269443&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25269443.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25267472</id>
	<title>Re: return_to url in the OpenID responses</title>
	<published>2009-09-02T16:35:35Z</published>
	<updated>2009-09-02T16:35:35Z</updated>
	<author>
		<name>Nat Sakimura</name>
	</author>
	<content type="html">+1 for a relay state, but not for the size thing. This is a completely
&lt;br&gt;separate issue than the Artifact binding.
&lt;br&gt;&lt;br&gt;Artifact binding is needed anyways for several reasons.
&lt;br&gt;&lt;br&gt;For example, mobile browsers etc., an Artifact binding is essential.
&lt;br&gt;You must not think that that the transmission only happens over a fast
&lt;br&gt;connection. In mobile scenarios, typically, the browser session is
&lt;br&gt;over the slow connection while the server to server connection is over
&lt;br&gt;a fast connection. So, latency-wise, the Artifact binding is going to
&lt;br&gt;be much better, in fact, orders better, and kinder to an OP from the
&lt;br&gt;point of view of number of simultaneous port that they have to keep
&lt;br&gt;open. Also, you are talking about IE limit, but mobile browser limit
&lt;br&gt;is much more severe, like 256 bytes per a GET query.
&lt;br&gt;&lt;br&gt;In addition, I would like to point out that over 70% of the traffic is
&lt;br&gt;now generated from the mobile browsers. In the U.S., it might not have
&lt;br&gt;happened yet, but you may be heading towards the direction as well.
&lt;br&gt;People do not use a PC when it suffice with a Phone. User experience
&lt;br&gt;is much better that way.
&lt;br&gt;&lt;br&gt;I would further say this: A protocol or service that can only be
&lt;br&gt;provided over a single channel like PC is DEAD. It has to be provided
&lt;br&gt;over mobile, PC internet, TV internet, etc. simultaneously. This is
&lt;br&gt;not my word. This is the testimony from the EC (Electric Commerce)
&lt;br&gt;consortium (I need to check their English name though...) at the
&lt;br&gt;Japanese government meeting that discusses the authentication
&lt;br&gt;guideline. IMHO, EU and US will come to the same state in a few years.
&lt;br&gt;&lt;br&gt;Also, the Artifact is needed for security reasons as well. You need it
&lt;br&gt;for LoA2+. With the advent of Government 2.0, we need it NOW. We
&lt;br&gt;should have done that long before.
&lt;br&gt;&lt;br&gt;=nat
&lt;br&gt;&lt;br&gt;On Thu, Sep 3, 2009 at 3:58 AM, Praveen
&lt;br&gt;Alavilli&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267472&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;praveen.alavilli@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; I wasn't sure if this was ever discussed so sending it to the specs list.
&lt;br&gt;&amp;gt; Currently the &amp;quot;openid.return_to&amp;quot; url param is a required parameter in all
&lt;br&gt;&amp;gt; OpenID positive assertions. I understand the reasons behind it, but I wonder
&lt;br&gt;&amp;gt; if passing back the whole return_to url (along with it's query params) as
&lt;br&gt;&amp;gt; response param is really required. Returning the return_to url in the
&lt;br&gt;&amp;gt; response just duplicates the same data that's already included in the
&lt;br&gt;&amp;gt; response url contributing to the problem of the response url length close to
&lt;br&gt;&amp;gt; or in some cases exceeding the max length allowed by certain browsers
&lt;br&gt;&amp;gt; (IE!).
&lt;br&gt;&amp;gt; Given that all the query parameters attached to the return_to param are
&lt;br&gt;&amp;gt; anyway included in the redirect url, and the spec explicitly says that it's
&lt;br&gt;&amp;gt; up to the RP to ensure those params are not modified by outside parties, can
&lt;br&gt;&amp;gt; we:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; modify the signing method to include all query parameters (not just openid
&lt;br&gt;&amp;gt; params) in the signature base string (follow something like the OAuth
&lt;br&gt;&amp;gt; signing mechanism) and modify the openid.return_to param in the response to
&lt;br&gt;&amp;gt; be just the request uri part (not including the rest of the non-OpenID RP
&lt;br&gt;&amp;gt; specific parameters), OR
&lt;br&gt;&amp;gt; add a new request parameter (say openid.rpState) that RPs can use to store
&lt;br&gt;&amp;gt; their state/context info so they don't need to include them in the return_to
&lt;br&gt;&amp;gt; url and so the OPs sign it along with the rest of the openid parameters in
&lt;br&gt;&amp;gt; the response ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know that there have been discussions going on about adding support for
&lt;br&gt;&amp;gt; artifact binding to OpenID in 2.1 but that just unnecessarily adds
&lt;br&gt;&amp;gt; additional requests for every OpenID login request. Not sure if the
&lt;br&gt;&amp;gt; latencies incurred due to those are worth the effort. The other option to
&lt;br&gt;&amp;gt; use a POST instead of a GET to avoid the url length issues causes bad back
&lt;br&gt;&amp;gt; button user experience.
&lt;br&gt;&amp;gt; Any other thoughts ?
&lt;br&gt;&amp;gt; thanks
&lt;br&gt;&amp;gt; Praveen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267472&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Nat Sakimura (=nat)
&lt;br&gt;&lt;a href=&quot;http://www.sakimura.org/en/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sakimura.org/en/&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267472&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/return_to-url-in-the-OpenID-responses-tp25263632p25267472.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25267141</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-02T16:01:28Z</published>
	<updated>2009-09-02T16:01:28Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">Allen,
&lt;br&gt;&lt;br&gt;In XRD 1.0 we are moving to a link based model.
&lt;br&gt;&lt;br&gt;So a users XRD rather than having to specify the openID providers &amp;nbsp;
&lt;br&gt;service can point to an openID provider.
&lt;br&gt;&lt;br&gt;The URIs that we currently use describe the service not the provider.
&lt;br&gt;&lt;br&gt;I think Nat is looking for a link relationship that describes a user &amp;nbsp;
&lt;br&gt;pointing &amp;nbsp;to a service providers XRD rather than to the service itself.
&lt;br&gt;&lt;br&gt;There will be a bunch of new link types required for various protocols.
&lt;br&gt;&lt;br&gt;John B.
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 2009-09-02, at 5:27 PM, Allen Tom wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Nat,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can you explain the problem in a bit more detail? Can you give an &amp;nbsp;
&lt;br&gt;&amp;gt; example use case?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks
&lt;br&gt;&amp;gt; Allen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Nat Sakimura wrote:
&lt;br&gt;&amp;gt;&amp;gt; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP &amp;nbsp;
&lt;br&gt;&amp;gt;&amp;gt; relationship.
&lt;br&gt;&amp;gt;&amp;gt; What shall we use?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Something like:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; =nat
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267141&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267141&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25267141&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25267141.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25266081</id>
	<title>Re: XRD and OpenID 2.1</title>
	<published>2009-09-02T14:27:45Z</published>
	<updated>2009-09-02T14:27:45Z</updated>
	<author>
		<name>Allen Tom-2</name>
	</author>
	<content type="html">Hi Nat,
&lt;br&gt;&lt;br&gt;Can you explain the problem in a bit more detail? Can you give an 
&lt;br&gt;example use case?
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Allen
&lt;br&gt;&lt;br&gt;&lt;br&gt;Nat Sakimura wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; The second topic for OpenID 2.1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Maybe, it should be separated to the Discovery but...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP relationship.
&lt;br&gt;&amp;gt; What shall we use?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Something like:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; =nat
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25266081&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25266081&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25266081.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25264730</id>
	<title>Re: return_to url in the OpenID responses</title>
	<published>2009-09-02T12:55:00Z</published>
	<updated>2009-09-02T12:55:00Z</updated>
	<author>
		<name>George Fletcher-2</name>
	</author>
	<content type="html">+1 for relay state and signing all parameters
&lt;br&gt;&lt;br&gt;Great point about discovery and dynamic parameters!
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;George
&lt;br&gt;&lt;br&gt;Breno de Medeiros wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; +1 for a relay state
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In my view the OpenID spec is broken with regards to the return_to
&lt;br&gt;&amp;gt; URL. For instance, how do you reconcile the need for dynamic elements
&lt;br&gt;&amp;gt; in the return_to URL with the recommended behavior of putting the
&lt;br&gt;&amp;gt; return_to URL in the discovery document?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Wed, Sep 2, 2009 at 11:58 AM, Praveen
&lt;br&gt;&amp;gt; Alavilli&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25264730&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;praveen.alavilli@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt; I wasn't sure if this was ever discussed so sending it to the specs list.
&lt;br&gt;&amp;gt;&amp;gt; Currently the &amp;quot;openid.return_to&amp;quot; url param is a required parameter in all
&lt;br&gt;&amp;gt;&amp;gt; OpenID positive assertions. I understand the reasons behind it, but I wonder
&lt;br&gt;&amp;gt;&amp;gt; if passing back the whole return_to url (along with it's query params) as
&lt;br&gt;&amp;gt;&amp;gt; response param is really required. Returning the return_to url in the
&lt;br&gt;&amp;gt;&amp;gt; response just duplicates the same data that's already included in the
&lt;br&gt;&amp;gt;&amp;gt; response url contributing to the problem of the response url length close to
&lt;br&gt;&amp;gt;&amp;gt; or in some cases exceeding the max length allowed by certain browsers
&lt;br&gt;&amp;gt;&amp;gt; (IE!).
&lt;br&gt;&amp;gt;&amp;gt; Given that all the query parameters attached to the return_to param are
&lt;br&gt;&amp;gt;&amp;gt; anyway included in the redirect url, and the spec explicitly says that it's
&lt;br&gt;&amp;gt;&amp;gt; up to the RP to ensure those params are not modified by outside parties, can
&lt;br&gt;&amp;gt;&amp;gt; we:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; modify the signing method to include all query parameters (not just openid
&lt;br&gt;&amp;gt;&amp;gt; params) in the signature base string (follow something like the OAuth
&lt;br&gt;&amp;gt;&amp;gt; signing mechanism) and modify the openid.return_to param in the response to
&lt;br&gt;&amp;gt;&amp;gt; be just the request uri part (not including the rest of the non-OpenID RP
&lt;br&gt;&amp;gt;&amp;gt; specific parameters), OR
&lt;br&gt;&amp;gt;&amp;gt; add a new request parameter (say openid.rpState) that RPs can use to store
&lt;br&gt;&amp;gt;&amp;gt; their state/context info so they don't need to include them in the return_to
&lt;br&gt;&amp;gt;&amp;gt; url and so the OPs sign it along with the rest of the openid parameters in
&lt;br&gt;&amp;gt;&amp;gt; the response ?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I know that there have been discussions going on about adding support for
&lt;br&gt;&amp;gt;&amp;gt; artifact binding to OpenID in 2.1 but that just unnecessarily adds
&lt;br&gt;&amp;gt;&amp;gt; additional requests for every OpenID login request. Not sure if the
&lt;br&gt;&amp;gt;&amp;gt; latencies incurred due to those are worth the effort. The other option to
&lt;br&gt;&amp;gt;&amp;gt; use a POST instead of a GET to avoid the url length issues causes bad back
&lt;br&gt;&amp;gt;&amp;gt; button user experience.
&lt;br&gt;&amp;gt;&amp;gt; Any other thoughts ?
&lt;br&gt;&amp;gt;&amp;gt; thanks
&lt;br&gt;&amp;gt;&amp;gt; Praveen
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25264730&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25264730&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/return_to-url-in-the-OpenID-responses-tp25263632p25264730.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25263707</id>
	<title>Re: return_to url in the OpenID responses</title>
	<published>2009-09-02T12:02:35Z</published>
	<updated>2009-09-02T12:02:35Z</updated>
	<author>
		<name>Breno de Medeiros</name>
	</author>
	<content type="html">+1 for a relay state
&lt;br&gt;&lt;br&gt;In my view the OpenID spec is broken with regards to the return_to
&lt;br&gt;URL. For instance, how do you reconcile the need for dynamic elements
&lt;br&gt;in the return_to URL with the recommended behavior of putting the
&lt;br&gt;return_to URL in the discovery document?
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Wed, Sep 2, 2009 at 11:58 AM, Praveen
&lt;br&gt;Alavilli&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25263707&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;praveen.alavilli@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; I wasn't sure if this was ever discussed so sending it to the specs list.
&lt;br&gt;&amp;gt; Currently the &amp;quot;openid.return_to&amp;quot; url param is a required parameter in all
&lt;br&gt;&amp;gt; OpenID positive assertions. I understand the reasons behind it, but I wonder
&lt;br&gt;&amp;gt; if passing back the whole return_to url (along with it's query params) as
&lt;br&gt;&amp;gt; response param is really required. Returning the return_to url in the
&lt;br&gt;&amp;gt; response just duplicates the same data that's already included in the
&lt;br&gt;&amp;gt; response url contributing to the problem of the response url length close to
&lt;br&gt;&amp;gt; or in some cases exceeding the max length allowed by certain browsers
&lt;br&gt;&amp;gt; (IE!).
&lt;br&gt;&amp;gt; Given that all the query parameters attached to the return_to param are
&lt;br&gt;&amp;gt; anyway included in the redirect url, and the spec explicitly says that it's
&lt;br&gt;&amp;gt; up to the RP to ensure those params are not modified by outside parties, can
&lt;br&gt;&amp;gt; we:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; modify the signing method to include all query parameters (not just openid
&lt;br&gt;&amp;gt; params) in the signature base string (follow something like the OAuth
&lt;br&gt;&amp;gt; signing mechanism) and modify the openid.return_to param in the response to
&lt;br&gt;&amp;gt; be just the request uri part (not including the rest of the non-OpenID RP
&lt;br&gt;&amp;gt; specific parameters), OR
&lt;br&gt;&amp;gt; add a new request parameter (say openid.rpState) that RPs can use to store
&lt;br&gt;&amp;gt; their state/context info so they don't need to include them in the return_to
&lt;br&gt;&amp;gt; url and so the OPs sign it along with the rest of the openid parameters in
&lt;br&gt;&amp;gt; the response ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know that there have been discussions going on about adding support for
&lt;br&gt;&amp;gt; artifact binding to OpenID in 2.1 but that just unnecessarily adds
&lt;br&gt;&amp;gt; additional requests for every OpenID login request. Not sure if the
&lt;br&gt;&amp;gt; latencies incurred due to those are worth the effort. The other option to
&lt;br&gt;&amp;gt; use a POST instead of a GET to avoid the url length issues causes bad back
&lt;br&gt;&amp;gt; button user experience.
&lt;br&gt;&amp;gt; Any other thoughts ?
&lt;br&gt;&amp;gt; thanks
&lt;br&gt;&amp;gt; Praveen
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; specs mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25263707&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;--Breno
&lt;br&gt;&lt;br&gt;+1 (650) 214-1007 desk
&lt;br&gt;+1 (408) 212-0135 (Grand Central)
&lt;br&gt;MTV-41-3 : 383-A
&lt;br&gt;PST (GMT-8) / PDT(GMT-7)
&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25263707&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/return_to-url-in-the-OpenID-responses-tp25263632p25263707.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25263632</id>
	<title>return_to url in the OpenID responses</title>
	<published>2009-09-02T11:58:49Z</published>
	<updated>2009-09-02T11:58:49Z</updated>
	<author>
		<name>Praveen Alavilli-2</name>
	</author>
	<content type="html">Hi,&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I wasn&amp;#39;t sure if this was ever discussed so sending it to the specs list. &lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Currently the &amp;quot;openid.return_to&amp;quot; url param is a required parameter in all OpenID positive assertions. I understand the reasons behind it, but I wonder if passing back the whole return_to url (along with it&amp;#39;s query params) as response param is really required. Returning the return_to url in the response just duplicates the same data that&amp;#39;s already included in the response url contributing to the problem of the response url length close to or in some cases exceeding the max length allowed by certain browsers (IE!). &lt;/div&gt;


&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Given that all the query parameters attached to the return_to param are anyway included in the redirect url, and the spec explicitly says that it&amp;#39;s up to the RP to ensure those params are not modified by outside parties, can we:&lt;/div&gt;

&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;modify the signing method to include all query parameters (not just openid params) in the signature base string (follow something like the OAuth signing mechanism) and modify the openid.return_to param in the response to be just the request uri part (not including the rest of the non-OpenID RP specific parameters), OR&lt;/li&gt;

&lt;li&gt;add a new request parameter (say openid.rpState) that RPs can use to store their state/context info so they don&amp;#39;t need to include them in the return_to url and so the OPs sign it along with the rest of the openid parameters in the response ? &lt;br&gt;

&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I know that there have been discussions going on about adding support for artifact binding to OpenID in 2.1 but that just unnecessarily adds additional requests for every OpenID login request. Not sure if the latencies incurred due to those are worth the effort. The other option to use a POST instead of a GET to avoid the url length issues causes bad back button user experience.&lt;/div&gt;

&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Any other thoughts ?&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;thanks&lt;/div&gt;&lt;div&gt;Praveen&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25263632&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/return_to-url-in-the-OpenID-responses-tp25263632p25263632.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25252899</id>
	<title>XRD and OpenID 2.1</title>
	<published>2009-09-02T00:28:53Z</published>
	<updated>2009-09-02T00:28:53Z</updated>
	<author>
		<name>Nat Sakimura-2</name>
	</author>
	<content type="html">The second topic for OpenID 2.1
&lt;br&gt;&lt;br&gt;Maybe, it should be separated to the Discovery but...
&lt;br&gt;&lt;br&gt;In XRD 1.0, we need to define &amp;lt;Rel&amp;gt; type url for the user=OP relationship.
&lt;br&gt;What shall we use?
&lt;br&gt;&lt;br&gt;Something like:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://specs.openid.net/rel/openid_provider#&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://specs.openid.net/rel/openid_provider#&lt;/a&gt;&lt;br&gt;&lt;br&gt;=nat
&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25252899&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/XRD-and-OpenID-2.1-tp25252899p25252899.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25164590</id>
	<title>Re: Some implementations don't process the HEAD element correctly</title>
	<published>2009-08-26T18:23:08Z</published>
	<updated>2009-08-26T18:23:08Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">Sorry I was unclear.
&lt;br&gt;&lt;br&gt;I wasn't criticizing openID 2.0 for being silent on where the meta tag &amp;nbsp;
&lt;br&gt;for X-XRDS.
&lt;br&gt;&lt;br&gt;Only that there is no requirement in the spec to place the other tags &amp;nbsp;
&lt;br&gt;in the HEAD.
&lt;br&gt;&lt;br&gt;That is the only unfortunate part.
&lt;br&gt;&lt;br&gt;John B.
&lt;br&gt;On 26-Aug-09, at 4:48 PM, Josh Hoyt wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Wed, Aug 26, 2009 at 8:24 AM, John &amp;nbsp;
&lt;br&gt;&amp;gt; Bradley&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25164590&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;john.bradley@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Yadis requires the X-XRDS meta tag to be inside the &amp;lt;head&amp;gt; element.
&lt;br&gt;&amp;gt;&amp;gt; OpenID 2.0 is silent on it.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This is a little unfair to the OpenID 2.0 specification, since in
&lt;br&gt;&amp;gt; order for a document to BE valid HTML[1] or XHTML[2], META tags are
&lt;br&gt;&amp;gt; only allowed to be in the HEAD.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; It might have been nice for implementers if that relevant bit of
&lt;br&gt;&amp;gt; information were duplicated in the OpenID 2.0 specification, but even
&lt;br&gt;&amp;gt; without it, the requirement is well-specified.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Josh
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1. &lt;a href=&quot;http://www.w3.org/TR/html401/sgml/dtd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.w3.org/TR/html401/sgml/dtd.html&lt;/a&gt;&lt;br&gt;&amp;gt; 2. &lt;a href=&quot;http://www.w3.org/TR/xhtml1/dtds.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.w3.org/TR/xhtml1/dtds.html&lt;/a&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25164590&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Some-implementations-don%27t-process-the-HEAD-element-correctly-tp25154660p25164590.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25161733</id>
	<title>Re: Some implementations don't process the HEAD element correctly</title>
	<published>2009-08-26T13:48:48Z</published>
	<updated>2009-08-26T13:48:48Z</updated>
	<author>
		<name>Josh Hoyt-2</name>
	</author>
	<content type="html">On Wed, Aug 26, 2009 at 8:24 AM, John Bradley&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25161733&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;john.bradley@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Yadis requires the X-XRDS meta tag to be inside the &amp;lt;head&amp;gt; element.
&lt;br&gt;&amp;gt; OpenID 2.0 is silent on it.
&lt;br&gt;&lt;br&gt;This is a little unfair to the OpenID 2.0 specification, since in
&lt;br&gt;order for a document to BE valid HTML[1] or XHTML[2], META tags are
&lt;br&gt;only allowed to be in the HEAD.
&lt;br&gt;&lt;br&gt;It might have been nice for implementers if that relevant bit of
&lt;br&gt;information were duplicated in the OpenID 2.0 specification, but even
&lt;br&gt;without it, the requirement is well-specified.
&lt;br&gt;&lt;br&gt;Josh
&lt;br&gt;&lt;br&gt;1. &lt;a href=&quot;http://www.w3.org/TR/html401/sgml/dtd.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.w3.org/TR/html401/sgml/dtd.html&lt;/a&gt;&lt;br&gt;2. &lt;a href=&quot;http://www.w3.org/TR/xhtml1/dtds.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.w3.org/TR/xhtml1/dtds.html&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25161733&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Some-implementations-don%27t-process-the-HEAD-element-correctly-tp25154660p25161733.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25155416</id>
	<title>Re: Some implementations don't process the HEAD element correctly</title>
	<published>2009-08-26T08:24:24Z</published>
	<updated>2009-08-26T08:24:24Z</updated>
	<author>
		<name>John Bradley-7</name>
	</author>
	<content type="html">&lt;html&gt;&lt;body style=&quot;word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; &quot;&gt;There is talk of removing HTML discovery in future.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;It is a known security problem.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Yadis requires the X-XRDS meta tag to be inside the &amp;lt;head&amp;gt; element.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;OpenID 2.0 is silent on it. &amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Getting rid of the meta http-eqiv tag from the HTML will be a challenge, and a point for debate.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;I think the other elements will go except for backwards compatibility with older RPs.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;John B.&lt;br&gt;&lt;div&gt;&lt;div&gt;On 26-Aug-09, at 10:51 AM, Andrew Arnott wrote:&lt;/div&gt;&lt;br class=&quot;Apple-interchange-newline&quot;&gt;&lt;blockquote type=&quot;cite&quot;&gt;Thanks, Thomas. &amp;nbsp;I hadn't meant to drop the list with my reply.&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;You're points are all correct too. &amp;nbsp;I guess my only argument is: a fully compliant HTML parser in an OpenID RP library would be very heavyweight, and anything less would mean it's buggy. &amp;nbsp;So far, the community seems satisfied with &quot;mostly there&quot; implementations. &amp;nbsp;I agree it's not perfect, but in the next major OpenID spec, HTML discovery is likely to be removed anyway, so I don't think any implementers have motivation to fix these bugs that can easily be worked around.&lt;/div&gt; &lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;BTW, missing HEAD tags is just one bug, and it seems disproportionate to stress this &lt;i&gt;one&lt;/i&gt;&amp;nbsp;over all the others. &amp;nbsp;Some of which are perhaps more serious. &amp;nbsp;I imagine many RPs don't ignore LINK tags that appear within HTML &amp;lt;!-- comments --&amp;gt;. &amp;nbsp;And to properly respect comments requires Javascript parsing (I think!) in order to avoid ending the comment when a javascript function contains a string with &quot;--&amp;gt;&quot; in it.&lt;/div&gt; &lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Just some more thoughts. &amp;nbsp;As an RP implementer myself, I do fix some HTML discovery bugs that come in, but not all of them for the reasons given above.&lt;br clear=&quot;all&quot;&gt;--&lt;br&gt;Andrew Arnott&lt;br&gt;&quot;I [may] not agree with what you have to say, but I'll defend to the death your right to say it.&quot; - S. G. Tallentyre&lt;br&gt; &lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Wed, Aug 26, 2009 at 7:39 AM, Thomas Hühn &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25155416&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;huehn@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt; [you mailed off-list, was that intentional?]&lt;br&gt; &lt;br&gt; Andrew Arnott schrieb:&lt;div class=&quot;im&quot;&gt;&lt;br&gt; &lt;br&gt; &amp;gt; The difference is &quot;&amp;lt;LINK&amp;gt;&quot; might appear somewhere in the &amp;lt;BODY&amp;gt; of the &amp;gt; page&lt;br&gt; &lt;br&gt;&lt;/div&gt; Not in a valid HTML document. :-)&lt;br&gt; &lt;br&gt; Of course you have to think about invalid ones as well, because browsers accept them.&lt;br&gt; &lt;br&gt; But that doesn't have anything to do with whether there is a &amp;lt;HEAD&amp;gt; tag.&lt;br&gt; &lt;br&gt; The security implications are totally independent from having or omitting HEAD tags.&lt;br&gt; &lt;br&gt; Look, it's perfectly clear at any point in the HTML text whether this point belongs to HEAD or to BODY. The HEAD tags are irrelevant.&lt;br&gt; &lt;br&gt; Google even recommends omitting them: &lt;a href=&quot;http://code.google.com/speed/articles/optimizing-html.html&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/speed/articles/optimizing-html.html&lt;/a&gt;&lt;div class=&quot;im&quot;&gt;&lt;br&gt; &lt;br&gt; &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt; I agree with Shade. &amp;nbsp;It's sub-optimal security for OpenID RPs to try grokking HTML in the first place. &amp;nbsp;I'm sure if you tried everything &lt;br&gt; &lt;/blockquote&gt; &lt;br&gt;&lt;/div&gt; Of course parsing HTML is hell, but you have specified it.&lt;div class=&quot;im&quot;&gt;&lt;br&gt; &lt;br&gt; &lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt; &quot;legal&quot;, you'd likely find dozens of ways that RPs are imperfect. &amp;nbsp;But since delegation is a relatively rare scenario anyway (hundreds of millions of OpenIDs out there today, only a few actually delegate since it's an advanced user scenario) I think it's very reasonable to put a few restrictions on it so that RPs can be more secure and written more easily.&lt;br&gt; &lt;/blockquote&gt; &lt;br&gt;&lt;/div&gt; That doesn't change anything.&lt;br&gt; &lt;br&gt; Everything you're saying is absolutely right. But it doesn't have anything to do with whether the HEAD element is surrounded by HEAD tags.&lt;br&gt; &lt;br&gt; My example is *valid*, by the OpenID specification. I have placed LINK elements inside the HEAD element. That's what the OpenID spec demands.&lt;br&gt; &lt;br&gt; The implementation is *buggy*. Yes, that's a fringe case. I can't really blame the author for not thinking about this.&lt;br&gt; &lt;br&gt; And the spec is fine by itself but could be improved for the benefit of developers and users.&lt;br&gt; &lt;br&gt; So there are several ways to handle it:&lt;br&gt; &lt;br&gt; 1. The status quo -- don't do anything: perfectly okay, but probably many more implementations will be buggy, without the developers even knowing about the pitfall.&lt;br&gt; &lt;br&gt; 2. making clear in the spec that the HEAD element does not necessarily correspond to HEAD tags and that a simple grep is *wrong*.&lt;br&gt; &lt;br&gt; 3. re-wording the spec so that it is clear that only a subset of HTML is supported, requiring the HEAD tag(s).&lt;br&gt; &lt;br&gt; I'd prefer 2., just adding a non-normative note to the spec.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt; &lt;br&gt; Thomas&lt;br&gt; &lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt; _______________________________________________&lt;br&gt;specs mailing list&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25155416&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/body&gt;&lt;/html&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;specs mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25155416&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;specs@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.openid.net/mailman/listinfo/openid-specs&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.openid.net/mailman/listinfo/openid-specs&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Some-implementations-don%27t-process-the-HEAD-element-correctly-tp25154660p25155416.html" />
</entry>

</feed>
