Re: OpenID support for XACML

2007-10-31 Thread Nat Sakimura
It would be interesting to me, at least. My team is currently considering using OpenID for real business transactions and sorting out what is there and what is not there. For something that is not there, we have to create one and perhaps propose as a spec. Nat McGovern, James F (HTSC, IT) wrot

Re: HMAC-256 vs HMAC-SHA256 for openid.assoc_type

2007-10-31 Thread Josh Hoyt
On 10/30/07, Manger, James H <[EMAIL PROTECTED]> wrote: > It was "HMAC-SHA256" in draft 9 (10 Sep 2007), but had changed to "HMAC-256" > in draft 10 (13 Oct 2007). The change is looking more like a typo. Indeed, this is an error in the text. It's intended to be HMAC-SHA256. Josh

OpenID support for XACML

2007-10-31 Thread McGovern, James F (HTSC, IT)
Currently OpenID 2.0 is targeted for supporting consumer-oriented interactions. I would love to develop a sense as to when/if members of OpenID have any interest in sketching out B2B interactions where not only identity is important but also assertion of authorization information at runtime via XA