Re: OpenID Provider Authentication Policy Extension

2007-08-24 Thread Johnny Bufu
David, On 9-Aug-07, at 11:28 AM, Johnny Bufu wrote: > On 21-Jul-07, at 4:55 PM, Recordon, David wrote: >> 5.2 >> >> 2) I'm fine with time coming back instead of number of seconds. > > I wanted to bring openid4java up to the latest PAPE spec, and it > seems the above was not checked in yet. Do you

Re: OpenID Provider Authentication Policy Extension

2007-08-09 Thread Johnny Bufu
Hi David, > On 22-Jun-07, at 9:46 AM, Recordon, David wrote: >> So please, check it out and let me know what you think...especially >> around the questions in the Editorial Comments section at the end. > > Here are the issues that came up while I implemented PAPE in > openid4java: > > [...] > > 5.

Re: OpenID Provider Authentication Policy Extension

2007-07-23 Thread Johnny Bufu
On 21-Jul-07, at 4:55 PM, Recordon, David wrote: > 5.1 > 1) Clarified. > > 2 & 3) Changed the MUST to a SHOULD, since the intent was never to > restrict what a user could do. > > 4) Changed to "Integer" > > 2) I'm fine with time coming back instead of number of seconds. > > 3) Changed to integer.

RE: OpenID Provider Authentication Policy Extension

2007-07-21 Thread Recordon, David
on, David Cc: specs@openid.net Subject: Re: OpenID Provider Authentication Policy Extension David, On 22-Jun-07, at 9:46 AM, Recordon, David wrote: > So please, check it out and let me know what you think...especially > around the questions in the Editorial Comments section at the end. Here

RE: OpenID Provider Authentication Policy Extension

2007-07-21 Thread Recordon, David
ting the extension in the response versus not using any policies. 4) Yeah. Thanks, --David -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hans Granqvist Sent: Friday, June 22, 2007 3:50 PM To: Recordon, David Cc: specs@openid.net Subject: Re: OpenID Provi

RE: OpenID Provider Authentication Policy Extension

2007-07-21 Thread Recordon, David
Thanks, definitely am! Just catching up on a lot of email now. --David -Original Message- From: Johnny Bufu [mailto:[EMAIL PROTECTED] Sent: Friday, July 13, 2007 11:05 AM To: Recordon, David Cc: specs@openid.net Subject: Re: OpenID Provider Authentication Policy Extension David, On

Re: OpenID Provider Authentication Policy Extension

2007-07-13 Thread Johnny Bufu
David, On 22-Jun-07, at 9:46 AM, Recordon, David wrote: > So please, check it out and let me know what you think...especially > around the questions in the Editorial Comments section at the end. > > http://openid.net/specs/openid-provider-authentication-policy- > extension- > 1_0-01.html Hope y

Re: OpenID Provider Authentication Policy Extension

2007-06-28 Thread Johnny Bufu
David, On 22-Jun-07, at 9:46 AM, Recordon, David wrote: > So please, check it out and let me know what you think...especially > around the questions in the Editorial Comments section at the end. Here are the issues that came up while I implemented PAPE in openid4java: 5.1 Request Parameters

RE: OpenID Provider Authentication Policy Extension

2007-06-22 Thread =drummond.reed
Perhaps "non-shared-secret"? "omnidirectional-token"? =Drummond -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hans Granqvist Sent: Friday, June 22, 2007 3:50 PM To: Recordon, David Cc: specs@openid.net Subject: Re: OpenID Provide

Re: OpenID Provider Authentication Policy Extension

2007-06-22 Thread Hans Granqvist
A few comments: * Would be great if all the namespace URLs resolved into live links. It always helps in the XML world and probably would in here too. * Section 4 Defined Authentication Policies We've talked about this before, but I just want to restate that it is a bad idea to name a policy base