<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general">
    <title>gmane.comp.web.openid.general</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8076"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8075"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8074"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8073"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8072"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8071"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8070"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8069"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8068"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8067"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8066"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8065"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8062"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8061"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8060"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8058"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8057"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8056"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8055"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.web.openid.general/8054"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8076">
    <title>Re: [OpenID] Mixi's news (AX, Yahoo!)</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8076</link>
    <description>
Excellent news! Integrating users' social identity and leveraging 
that on an automatically updated basis (daily, weekly, whenever the 
user tries to authenticate again and their Friend/Community status is 
rechecked) sets a good example. Might need more communication between 
OP and hosting provider to duplicate without using an internal 
(same-site) mechanism, but that's one of the things AX can be used 
for, or perhaps the site's API if it has one? I hope to see many 
other sites adopt this - Yahoo!, for instance, though it might not 
have Friends lists (Flickr?) or Communities, it does have *lists*, 
and since many of those have private membership, an anonymous way to 
prove "I am a subscriber to this list." would be *excellent* 
(speaking from a Relying Party standpoint).

-Shade
</description>
    <dc:creator>SitG Admin</dc:creator>
    <dc:date>2008-08-20T15:43:33</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8075">
    <title>[OpenID] Mixi, the largest Japanese SNS,started to offer OpenID and OpenID based friend/group auth</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8075</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Nat Sakimura</dc:creator>
    <dc:date>2008-08-20T11:15:18</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8074">
    <title>[OpenID] Microsoft's healthvault as RP</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8074</link>
    <description>Anyone care to recount their _technical_ interworking (and/or _policy_ accreditation) stories here, against Microsoft's OpenID RP?

https://account.healthvault.com/OpenIdLogin.aspx?rmproc=true


Notice that Microsoft (corporately) disclaims any "endorsement" of OpenID (the general "initiative", I assume)

"Important:  Microsoft does not provide OpenIDs, and does not endorse OpenID or any particular OpenID provider.
Before you choose to use OpenID with HealthVault, we recommend that you evaluate the security and privacy commitments offered by the OpenID issuer and decide if they are appropriate for your HealthVault account. Guard the identity you use to sign in to your HealthVault account. Your OpenID or Windows Live ID is like a key to a safe. The safe may have many security features, but anyone who has the key can open it."

It will be interesting to see if this disclaimer carries any legal weight, given the nature of the personal privacy information involved, especially since the corporation is evidently o</description>
    <dc:creator>Peter Williams</dc:creator>
    <dc:date>2008-08-19T17:21:13</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8073">
    <title>Re: [OpenID] Trying to locate Jon Mills</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8073</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Susanedoherty&lt; at &gt;aol.com</dc:creator>
    <dc:date>2008-08-19T11:25:33</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8072">
    <title>[OpenID] Trying to locate Jon Mills</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8072</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Paul</dc:creator>
    <dc:date>2008-08-19T00:28:34</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8071">
    <title>[OpenID] [ANN] CL-OpenID 1.0 rc1</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8071</link>
    <description>﻿As this year's Google Summer of Code pencils down date has passed, with
great pleasure I announce that CL-OpenID version 1.0 Release Candidate 1
is out.

Cl-OpenID is an implementation of OpenID protocol in Common Lisp.  It
implements OpenID Authentication 2.0 standard and is compatible with
OpenID Authentication 1.1.  Both Relying Party (formerly called OpenID
Consumer), and OpenID Provider are implemented.

CL-OpenID is available on terms of GNU Lesser General Public License
version 2.1 with Franz Inc.'s preamble, also known as LLGPL (Lisp
Lesser General Public License).

The project has been developed as a Google Summer of Code 2008 project,
developed by Maciej Pasternacki and mentored by Anton Vodonosov.
Original application is published at.

CL-OpenID home page is at http://common-lisp.net/project/cl-openid/

Current code is in darcs repository http://common-lisp.net/project/cl-openid/darcs/cl-openid/

The 1.0 Release Candidate 1 version is tagged 1_0_rc1 in darcs, and is
also downloadable from http:</description>
    <dc:creator>Maciek Pasternacki</dc:creator>
    <dc:date>2008-08-18T20:06:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8070">
    <title>Re: [OpenID] Has anyone actually used Immediate mode with AJAX?</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8070</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Andrew Arnott</dc:creator>
    <dc:date>2008-08-18T19:56:14</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8069">
    <title>Re: [OpenID] SaaS &amp; OpenID</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8069</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Tara Kelly</dc:creator>
    <dc:date>2008-08-18T08:09:24</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8068">
    <title>Re: [OpenID] Has anyone actually used Immediate mode with AJAX?</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8068</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Andrew Arnott</dc:creator>
    <dc:date>2008-08-15T09:04:57</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8067">
    <title>[OpenID] Has anyone actually used Immediate mode with AJAX?</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8067</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Andrew Arnott</dc:creator>
    <dc:date>2008-08-15T08:28:50</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8066">
    <title>[OpenID] SaaS &amp; OpenID</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8066</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Uday Subbarayan</dc:creator>
    <dc:date>2008-08-14T17:27:39</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8065">
    <title>[OpenID] Higher SHA values</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8065</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Andrew Arnott</dc:creator>
    <dc:date>2008-08-13T23:41:56</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8062">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8062</link>
    <description>_______________________________________________
general mailing list
general&lt; at &gt;openid.net
http://openid.net/mailman/listinfo/general
</description>
    <dc:creator>Andrew Arnott</dc:creator>
    <dc:date>2008-08-12T14:16:25</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8061">
    <title>Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8061</link>
    <description>On Tue, Aug 12, 2008 at 9:55 AM, Clausen, Martin (DK - Copenhagen)
&lt;mclausen&lt; at &gt;deloitte.dk&gt; wrote:

Browser plugins do not assist RPs.
</description>
    <dc:creator>Ben Laurie</dc:creator>
    <dc:date>2008-08-12T13:31:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8060">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8060</link>
    <description>    Yes, I do mostly look at this issue from the OP/IdP site.
    Which is a huge problem, IMHO.
    As I said, I would most likely prefer a solution like that; at the 
same time it seems easier to me to only allow a simple mapping between 
http and https versions. I'd rather have a quick and dirty solution to 
problem that can be ultimately extended to a more graceful solution, 
than engineer the problem for 6 months and leave the security hole open. 
Nevertheless, a generic identifier re-association would probably be the 
best solution.
    Yes. IMHO, for *any* future version of the protocol or its 
extensions, secure discovery should be REQUIRED--everything else leave 
the door open to more vulnerabilities.

Best,

Gerald
</description>
    <dc:creator>Gerald Beuchelt</dc:creator>
    <dc:date>2008-08-12T13:09:59</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8058">
    <title>Re: [OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8058</link>
    <description>Ben Laurie:

On behalf of openid.net.nz (as I am "just" a service supplier to the
company), I can confirm that the weak/compromised SSL certificate used
by openid.net.nz has been replaced by a strong certificate. Apologies
for the delay here, it has as usual co-incided with important people
being off the net for extended periods of time (aka "holiday").

However, given that openid.net.nz uses a self-signed certificate, the
threat mechanism suggested by Ben probably does not materially change
the "security level" of this service, which is not high.

Most of his points are around the types of authentication implicitly
and explicitly accepted/used by the OpenID implementations around the
net, and I can't address them from here, but if anyone has any
specific recommendation I'll be pleased to hear them :-)

-jim
http://inode.co.nz/
</description>
    <dc:creator>Jim Cheetham</dc:creator>
    <dc:date>2008-08-12T04:58:57</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8057">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8057</link>
    <description>Doesn't SAML have specific support for the very use case of migrating one id to another? Isn't this the name mapping feature - wherein an SP can record a new SP-Identifier (that can be shared across an affiliation of SPs)? I fear my memory is failing me, on the actual details.

Sounds like we could be borrowing the use case analysis of the OASIS folk, at least - even if the service is ultimately expressed using openid-framework protocols. What matters in standards making is getting common service adopted and put into commodity form.

This might be something the academic SAML folks and openid folks could cooperate on. The academic folk don't seem to be too interested in that particular SAML feature - perhaps lacking a strong, practical use case that the openid view on the world finally opens up, as folks see a need to easily swap out their login openid, across 10 web2.0 sites?



-----Original Message-----
From: general-bounces&lt; at &gt;openid.net [mailto:general-bounces&lt; at &gt;openid.net] On Behalf Of SitG Admin
Sent: Monda</description>
    <dc:creator>Peter Williams</dc:creator>
    <dc:date>2008-08-12T03:11:04</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8056">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8056</link>
    <description>
It might be easier to convince them if there were a standard for 
letting both URI's (old and new alike) "claim" the other. More like 
the reverse of claiming, though, since that's dangerous from either 
end; "I am willing to be associated with this URI."

Something that could be automated by Relying Parties.

-Shade
</description>
    <dc:creator>SitG Admin</dc:creator>
    <dc:date>2008-08-12T00:36:06</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8055">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8055</link>
    <description>
Point taken, Eric - therefore I will try to remember, in future, that 
when I want to make something theoretical easier to grasp by giving 
it an imaginary practical form, I should use YOUR name in the example 
:P

-Shade
</description>
    <dc:creator>SitG Admin</dc:creator>
    <dc:date>2008-08-12T00:31:17</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8054">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8054</link>
    <description>
I apologise for the fact that I misunderstood what you were doing in my 
initial response; I thought you were coming at this from the RP's 
perspective, not the OP's.

Really this is a specific form of the general problem of how to 
automatically migrate from one identifier to another. Manually updating 
all RPs you've used can be an arduous process, and some RPs don't even 
allow the identifier(s) associated with an account to be changed.

However, I really don't like the idea of OpenID contradicting the 
established rules for URI normalization. I think if RPs are going to 
have to change anyway, it'd be better to introduce some explicit and 
general mechanism for automatic identifier switching on login. However, 
until most RPs are updated, neither approach is going to be very useful.

What we could really do with is a way to work around this where only the 
OP would have to change. One approach could be to have the identifier 
URL *not* redirect to the https: version, but have the OP UI give the 
user th</description>
    <dc:creator>Martin Atkins</dc:creator>
    <dc:date>2008-08-11T23:01:18</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.web.openid.general/8053">
    <title>Re: [OpenID] RPs accepting https:// identifiers</title>
    <link>http://permalink.gmane.org/gmane.comp.web.openid.general/8053</link>
    <description>
On Aug 11, 2008, at 4:42 PM, SitG Admin wrote:


What if?  Then I would say that you're a lot more interested
in demonstrating your cleverness and trickiness than you are
in providing something that users can understand and use.

"Crazy" is the right adjective.

Eric Norman
</description>
    <dc:creator>Eric Norman</dc:creator>
    <dc:date>2008-08-11T22:26:01</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.web.openid.general">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.web.openid.general</link>
  </textinput>
</rdf:RDF>
