++ to making openstack.org/profile an OpenID consumer instead of an OpenID 
producer.

I don’t think there are even any good scalable security-audited battle-tested 
general purpose OpenID producers.  We would have to write one from scratch, or 
take one of the half-done ones and hack on it a great deal to make it fit, and 
then survive being p0wned over and over as we battle harden it.

OTOH, there are a lot of good open source implementations of OpenID consumer 
code out there.

..m

Mark Atwood <[email protected]>
Director of Open Source Engagement for HP Cloud Services
M +1-206-473-7118


> -----Original Message-----
> From: Robert Collins [mailto:[email protected]]
> Sent: Tuesday, September 24, 2013 3:32 PM
> To: Stefano Maffulli
> Cc: <[email protected]>
> Subject: Re: [OpenStack-Infra] List of properties that use Launchpad OpenID
> 
> On 25 September 2013 10:18, Stefano Maffulli <[email protected]> wrote:
> > On Tue 24 Sep 2013 03:04:32 PM PDT, Robert Collins wrote:
> >> Indeed! Please please please *do not* stand up yet another
> >> password-hosting site. Utter waste of everyone's time.
> >
> > I agree with you: we don't nee more complexity. Having our own OpenID
> > provider is needed in order to *reduce* complexity. Remember that the
> > Foundation already has to have *one* system to manage the identity of
> > Foundations' individual members. All ATCs also need to be members of
> > the Foundation, so at the moment all new contributors need to create
> > two
> > accounts: one on Launchpad and one on http://openstack.org/profile.
> > That sucks.
> 
> Can we change openstack.org/profile and make that another OpenID consumer? I 
> don't
> see why the Foundation needs to manage a password.
> 
> That would be a smaller change and reduce the number of passwords folk need to
> manage. And/or look at Persona?
> 
> -Rob
> 
> 
> --
> Robert Collins <[email protected]>
> Distinguished Technologist
> HP Converged Cloud
> 
> _______________________________________________
> OpenStack-Infra mailing list
> [email protected]
> http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-infra

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
OpenStack-Infra mailing list
[email protected]
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-infra

Reply via email to