David Ammouial wrote:
On Thursday 15 February 2007 18:02, Peter Saint-Andre wrote:
Given the momentum behind OpenID, it would be good to integrate it with
that system rather than build something that stands alone.
Also, how do you compare your approach to XEP-0070 and XEP-0101?

Concerning XEP-0101, I just answered to Richard's email on this matter. The two projects are indeed very similar, except that XEP-0101 is written as being tied to HTTP, whereas DIAS defines the ticket exchange and the HTTP authentication in distinct documents, thus enabling to use the ticket system on other channels than an HTTP communication.

The main difference with XEP-0070 is that the latter identifies the user _after_ the request, i.e. it is a verification, whereas XEP-0101 and DIAS do it before. Also, XEP-0070 is HTTP-specific.

I think HTTP is the main use case for all this stuff right now and the OpenID folks seem to agree, but you're right that we might want to authenticate / verify other channels (FTP, SIP, who knows). It would be good for XMPP to play well with everything that's happening in this distributed identity space. :-)

Peter

--
Peter Saint-Andre
XMPP Standards Foundation
http://www.xmpp.org/xsf/people/stpeter.shtml

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to