<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenID &#187; openid</title>
	<atom:link href="http://openid.net/tag/openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://openid.net</link>
	<description>Home of the OpenID community</description>
	<lastBuildDate>Tue, 31 Jan 2012 01:01:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<atom:link rel='hub' href='http://openid.net/?pushpress=hub'/>
		<item>
		<title>REMINDER &#8211; OpenID “Connect Tech” Summit &#8211; September 12-13, 2011</title>
		<link>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/</link>
		<comments>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 19:15:48 +0000</pubDate>
		<dc:creator>Karinhanson</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[Summit Events]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[events]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[summit]]></category>

		<guid isPermaLink="false">http://openid.net/?p=6925</guid>
		<description><![CDATA[The OpenID Foundation is launching its third OpenID Summits for 2011. This event is co-sponsored by Microsoft and will be held at the Microsoft Research Campus in Mountain View.  The OpenID Foundation&#8217;s 2011 series of OpenID Summits focuses on use cases and topics of interest to key developers, executives and analysts in the online identity [...]]]></description>
			<content:encoded><![CDATA[<p align="left">The OpenID Foundation is launching its third OpenID Summits for 2011. This event is co-sponsored by Microsoft and will be held at the Microsoft Research Campus in Mountain View.  The OpenID Foundation&#8217;s 2011 series of OpenID Summits focuses on use cases and topics of interest to key developers, executives and analysts in the online identity industry.</p>
<p align="left">This OpenID summit gives web site developers and technologists a closer look at the OpenID Connect protocol, its use cases and adoption plans by leading companies. We will introduce &#8220;Account Chooser&#8221; its implementation and user experience and provide interop testing and feedback for next generation OpenID adoption.</p>
<p align="left"> Please join us on Monday, September 12, 2011 from 12:00 Noon until 5:00pm PDT and Tuesday, September 13, 2011 from 10:00am to 5:00pm PDT.</p>
<p align="left"> Registration is now open at the following link: <a title="REGISTER NOW!" href="http://openidsummitsept2011.eventbrite.com/" target="_blank">REGISTER NOW!</a></p>
<p style="text-align: left;" align="left"> Location:<br />
<strong>Microsoft Research Silicon Valley Campus &#8211; 1288 Pear Avenue, Mountain View, CA  94043</strong></p>
<p><strong>OpenID Connect Tech  Summit </strong></p>
<p align="left"><strong>AGENDA: Monday,<br />
September 12, 2011 &#8211; 12:00pm-5:00pm</strong></p>
<p><strong>Noon: Lunch will be provided for attendees </strong></p>
<p align="left">12:00-12:20<strong> &#8211; Welcome</strong><br />
Don Thibeau, Executive Director, The OpenID Foundation</p>
<p><strong>Technical Sessions</strong></p>
<p>12:20-1:00 &#8211; <strong>Overview and Update of OpenID Connect and OAuth 2.0</strong>, Mike Jones, Microsoft,<br />
Director of Identity Partnerships</p>
<p>1:00-3:00<strong> &#8211; OpenID Connect Spec development</strong> (Working Group Review led by Allen Tom and Mike Jones)<br />
[2 hours]</p>
<ul>
<li>Timing goals for ratification</li>
<li>Core protocol</li>
<li>Dynamic RP registration and IDP discovery</li>
<li>Claims</li>
<li>Session Management</li>
<li>Artifact Binding</li>
<li>US Government OpenID Connect profile</li>
</ul>
<p>3:20-4:00 &#8211; <strong>Open time for Technical Interop, </strong> Allen Tom &amp; Mike Jones [60 min]</p>
<p>4:00-4:40 &#8211; <strong>OpenID Connect: Building Test Infrastructure, </strong>Roland Hedberg</p>
<p>4:40-5:00 &#8211; <strong>Wrap-up</strong>, Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left"><strong>AGENDA: Tuesday, September 13, 2011 &#8211; 10:00am-5:00pm</strong></p>
<p align="left"><strong>Business Session</strong></p>
<p>10:00-10:20 <strong>- Welcome</strong> Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left">10:20-11:00 <strong>- Feedback Review OpenID Connect</strong> Mike Jones, Microsoft<br />
and Allen Tom, Directors, The OpenID Foundation</p>
<p align="left">11:00-11:40 - <strong>Overview and Update of Account Chooser,  </strong>A presentation on a new sign in experience for the web, how to get involved, and an update on the legal status of related IP. Scott David, K&amp;L Gates,  Basheer Tome,  Independent &amp; Eric Sachs, Google</p>
<p align="left">11:40-12:20 &#8211; <strong>Migrating Users to Identity Providers From Email/Password Logins&#8221;,  </strong>A Summary of the experience of websites, including Google, that have started to migrate users from traditional logins to identity providers.  Eric Sachs,  Google, Product Manager</p>
<p align="left">12:20-1:00 &#8211; <strong>Lunch</strong></p>
<p align="left">1:00-1:40 &#8211; <strong>Microsoft as an RP and IDP</strong>, Speaker (TBD)</p>
<p align="left">1:40-2:20 &#8211; <strong>Way Beyond Single Sign On,</strong> Greg Keegstra, Janrain</p>
<p align="left">2:20-3:00 &#8211; <strong>The Value Proposition for OpenID Connect &amp; Account Chooser in the Enterprise</strong>, Pam Dingle, Ping Identity</p>
<p align="left">3:00-3:20 &#8211; Break</p>
<p align="left">3:20-4:00 &#8211; <strong>Open Identity and Online Adoption</strong>, A discussion on trends in the adoption of social login among online businesses. Patrick Salyer, Gigya</p>
<p align="left">4:00-4:40 &#8211; <strong>OpenID Connect &amp; UMA Synergies</strong>, OpenID Connect and User-Managed Access (UMA) solve interestingly complementary problems.  This session will explore use cases and proposals for combining them.  Macie Machulak</p>
<p align="left">4:40-5:00 -<strong> Wrap up</strong> Don Thibeau, Executive Director, The OpenID Foundation</p>
<p align="left">Best regards,</p>
<p>Don Thibeau, Executive  Director<br />
OpenID Foundation</p>
<p style="text-align: left;"><strong>Additional information is available at:</strong></p>
<p style="text-align: left;" align="left"><a title="OpenID Connect" href="http://openid.net/connect/" target="_blank">http://openid.net/connect/</a></p>
<p style="text-align: left;" align="left"><a title="Accountchooser" href="http://accountchooser.com/" target="_blank">http://accountchooser.com/</a></p>
<p>&nbsp;</p>
<p style="text-align: center;">Hosted by:</p>
<p style="text-align: center;"><a href="http://openid.net/wordpress-content/uploads/2011/08/oIDF_Msft-logos.jpg"><img class="aligncenter size-full wp-image-6943" title="oIDF_Msft logos" src="http://openid.net/wordpress-content/uploads/2011/08/oIDF_Msft-logos.jpg" alt="" width="288" height="93" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/08/22/openid-%e2%80%9cconnect-tech%e2%80%9d-summit-september-12-13-2011/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Current Map for OpenID Connect</title>
		<link>http://openid.net/2011/07/15/current-map-for-openid-connect/</link>
		<comments>http://openid.net/2011/07/15/current-map-for-openid-connect/#comments</comments>
		<pubDate>Sat, 16 Jul 2011 01:00:26 +0000</pubDate>
		<dc:creator>Nat Sakimura</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[developer]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[spec]]></category>
		<category><![CDATA[specification]]></category>

		<guid isPermaLink="false">http://openid.net/?p=6019</guid>
		<description><![CDATA[There is now a set of functionally complete specifications for OpenID Connect.  The diagram below shows the relationships between the current specs and contains links to each of them.  These specifications are ready for early developer feedback and prototype implementation work.  Please send feedback on them to the OpenID Artifact Binding Working Group Mailing List. [...]]]></description>
			<content:encoded><![CDATA[<p>There is now a set of functionally complete specifications for OpenID Connect.  The diagram below shows the relationships between the current specs and contains links to each of them.  These specifications are ready for <em><strong>early developer feedback</strong></em> and prototype implementation work.  Please send feedback on them to the <a title="OpenID Artifact Binding Working Group Mailing List" href="http://lists.openid.net/mailman/listinfo/openid-specs-ab">OpenID Artifact Binding Working Group Mailing List</a>.</p>
<p>OpenID Connect uses the best practices of widely used OAuth/REST/JSON based APIs to define a <em><strong>standard and interoperable</strong></em> way to authenticate users.  Developers should care because rather than having to learn an new and slightly different version of essentially the same API every time they want to integrate with a different identity provider, they can just do it in a standard way using a consistent interface.  In the long run, OpenID Connect will make the web more interoperable, because it makes it easier for developers to integrate with multiple services.</p>
<p>FYI, the working group *is* <strong><em>planning to reorganize the specs</em></strong> to have the minimal set of OpenID Connect functionality be contained in a single document, although this will likely not be in place for a few weeks.  Even before that is done, we wanted to make people aware of this set of specs now so early implementation work and technical feedback can occur.  Remaining edits to the specs should consist of corrections, clarifications, and reorganization, rather than additions of significant new functionality.  For now, developers should <span style="font-weight: bold; color: #ff0000;">start with the</span> (admittedly awkwardly named) <a href="http://openid.net/specs/openid-connect-http-redirect-1_0.html">OpenID Connect HTTP Redirect Binding spec</a>.</p>
<p>Let the feedback and prototyping begin! [*1]</p>
<map name="GraffleExport">
<area shape="rect" coords="182,385,244,422" href="http://self-issued.info/docs/draft-jones-json-web-token.html" />
<area shape="rect" coords="255,385,312,422" href="http://self-issued.info/docs/draft-jones-json-web-signature.html" />
<area shape="rect" coords="395,385,462,422" href="http://self-issued.info/docs/draft-jones-json-web-key.html" />
<area shape="rect" coords="322,385,384,422" href="http://self-issued.info/docs/draft-jones-json-web-encryption.html" />
<area shape="rect" coords="470,385,532,431" href="http://self-issued.info/docs/draft-jones-simple-web-discovery.html" />
<area shape="rect" coords="72,385,164,447" href="http://tools.ietf.org/html/draft-ietf-oauth-v2" />
<area shape="rect" coords="327,60,442,112" href="http://openid.net/specs/openid-connect-discovery-1_0.html" />
<area shape="rect" coords="458,60,573,112" href="http://openid.net/specs/openid-connect-registration-1_0.html" />
<area shape="rect" coords="114,135,229,187" href="http://openid.net/specs/openid-connect-userinfo-1_0.html" />
<area shape="rect" coords="390,135,506,187" href="http://openid.net/specs/openid-connect-session-1_0.html" />
<area shape="rect" coords="180,60,296,112" href="http://openid.net/specs/openid-connect-core-1_0.html" />
<area shape="rect" coords="53,60,168,112" href="http://openid.net/specs/openid-connect-http-redirect-1_0.html" />
<area shape="rect" coords="244,243,360,295" href="http://openid.net/specs/openid-connect-framework-1_0.html" /> </map>
<p><img usemap="#GraffleExport" src="http://openid.net/wordpress-content/uploads/2011/07/OpenIDConnect-Map-13jul2011-v3.png" border="0" alt="" /></p>
<p>[*1] The easiest way to do is to join the AB list at <a href="http://lists.openid.net/mailman/listinfo/openid-specs-ab" target="_blank">http://lists.openid.net/mailman/listinfo/openid-specs-ab</a>, submit the contribution agreement from <a href="http://openid.net/intellectual-property/" target="_blank">http://openid.net/intellectual-property/</a> (which you can now do online!), and then send comments to the <a href="mailto:openid-specs-ab@lists.openid.net">openid-specs-ab@lists.openid.net</a> .</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/07/15/current-map-for-openid-connect/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OpenID&#8217;s Second Act: OpenID Connect</title>
		<link>http://openid.net/2011/05/20/openids-second-act-openid-connect/</link>
		<comments>http://openid.net/2011/05/20/openids-second-act-openid-connect/#comments</comments>
		<pubDate>Fri, 20 May 2011 19:04:37 +0000</pubDate>
		<dc:creator>jfe</dc:creator>
				<category><![CDATA[Foundation]]></category>
		<category><![CDATA[Specs]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[spec]]></category>

		<guid isPermaLink="false">http://openid.net/?p=5845</guid>
		<description><![CDATA[Many in the open standards community have a &#8220;what have you done for me lately&#8221; chip implanted deep in their programming souls. It&#8217;s logical to want the evolution of OpenID technology to keep up with the rate of its adoption. We all want the pace of technology improvement to map onto the promise of what [...]]]></description>
			<content:encoded><![CDATA[<p>Many in the open standards community have a &#8220;what have you done for me lately&#8221; chip implanted deep in their programming souls. It&#8217;s logical to want the evolution of OpenID technology to keep up with the rate of its adoption. We all want the pace of technology improvement to map onto the promise of what has become the most popular decentralized single-sign-on protocol on the web. Some of the most impatient include members of the Board of the OpenID Foundation who aren&#8217;t satisfied with hanging an &#8220;over a billion served&#8221; on the OpenID Foundation website.</p>
<p><strong>The &#8220;co-evolution&#8221; of OAuth and OpenID</strong></p>
<p>Late last year, the members of the OpenID Artifact Binding and OpenID Connect Working Groups joined forces to develop a simple, common specification.  The result had been informally referred to as &#8220;OpenID Artifact Binding/Connect&#8221; or &#8220;OpenID ABC&#8221;. Key contributors from both working groups have been working on a core specification ever since.  Weekly specification calls have methodically focused on identifying and closing open issues.  A key milestone was reached at IIW earlier this month:  the remaining open issues were identified, tradeoffs debated, and all issues closed &#8211; with consensus decisions recorded in the Artifact Binding mailing list archives.  The working group is now refining the specifications to reflect those decisions, as well as tracking the evolution of closely related specifications like OAuth 2.0.</p>
<p>Having passed this gate, the OpenID board decided to brand the result &#8220;OpenID Connect&#8221; and solicit as wide and diverse feedback as possible. The OpenID Retail Summit at PayPal, the &#8220;Security&#8221; Summit at Symantec, and last week&#8217;s OpenID Summit in Munich at the European Identity Conference all featured detailed briefings and feedback on OpenID Connect.  While still a work in progress, OpenID Connect has achieved the levels of participation and consensus needed to advance to the next phase:  interoperability testing for multiple use cases in several venues worldwide.  We’ll continue to engage developers and potential deployers about OpenID Connect at upcoming OpenID Summits, including the next summit on July 19 in Colorado sponsored by Ping Identity, in to better understand, critique, refine, test, and ready OpenID Connect for prime time.</p>
<p><strong>A look under the hood of OpenID Connect:</strong></p>
<p>- web and developer friendly, building upon OAuth 2.0 and JSON<br />
- simple site registration functionality (the &#8220;Connect&#8221; part)<br />
- works well on mobile phones (the &#8220;Artifact Binding&#8221; part)<br />
- simple JSON-based claims model<br />
- reuses claims definitions from existing Portable Contacts specification<br />
- can achieve a range of security characteristics, spanning use cases from social networks to those needing higher levels of assurance<br />
- modular specifications, so deployers need only implement the functionality their applications need.</p>
<p>The strength of the open standards is the ongoing scrutiny from a global community of supporters and skeptics. Progress depends on those with the &#8220;courage of the first draft.&#8221; Our special thanks go to OpenID Board members Mike Jones, Nat Sakimura, and John Bradley, together with Breno de Medeiros from Google and Chuck Mortimore from Salesforce:  working group participants whose dedication and perspectives were critical to building consensus, closing the open issues,  and setting the stage for OpenID&#8217;s next act.</p>
<p>Don Thibeau<br />
Executive Director</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/05/20/openids-second-act-openid-connect/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Map for OpenID Connect</title>
		<link>http://openid.net/2011/04/29/a-map-for-openid-abc/</link>
		<comments>http://openid.net/2011/04/29/a-map-for-openid-abc/#comments</comments>
		<pubDate>Sat, 30 Apr 2011 01:54:00 +0000</pubDate>
		<dc:creator>John Bradley</dc:creator>
				<category><![CDATA[Specs]]></category>
		<category><![CDATA[abc]]></category>
		<category><![CDATA[attribute]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[claims]]></category>
		<category><![CDATA[connect]]></category>
		<category><![CDATA[distributed]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[specification]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://openid.net/?p=5491</guid>
		<description><![CDATA[IIW is rapidly approaching. We plan to take advantage of face to face discussions on the around the next version of openID. For those attending and others I want to point to the various potions of the spec work so that people have that in hand for IIW. One of the changes from openID 2.0 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>IIW is rapidly approaching.</strong></p>
<p>We plan to take advantage of face to face discussions on the around the next version of openID.</p>
<p>For those attending and others I want to point to the various potions of the spec work so that people have that in hand for IIW.</p>
<p>One of the changes from <a href="http://openid.net/specs/openid-authentication-2_0.html">openID 2.0</a> is that the new specification is more modular.</p>
<p>The following diagram illustrates the components and links to the specs:</p>
<p><img id="Image-Maps_7201104291118095" usemap="#Image-Maps_7201104291118095" src="http://openid4.us/specs/ab/OpenID-ABC-Framework.630.png" border="0" alt="" width="630" height="470" /></p>
<p>&nbsp;</p>
<p>(Click on the diagram to see each specifications.)</p>
<p>Everything is built on top of <strong><a href="http://tools.ietf.org/html/draft-ietf-oauth-v2-15" target="_blank">OAuth 2.0</a></strong> and the <strong><a href="http://self-issued.info/docs/draft-ietf-oauth-v2-bearer.html" target="_blank">Bearer Token Profile</a></strong> of OAuth.</p>
<p>We are supporting multiple OAuth Flows for different device types.</p>
<p><strong>The heart of OpenID Connect is the <a href="http://openid4.us/specs/ab/openid-connect-core-1_0.html" target="_blank">Core spec</a> that describes the abstract protocol.</strong></p>
<div>We have created bindings for several of the <a href="http://tools.ietf.org/html/draft-ietf-oauth-v2-15" target="_blank">OAuth</a> flows.</div>
<div>These include:</div>
<div style="padding-left: 30px;">
<ol>
<li><a href="http://openid4.us/specs/ab/openid-connect-ab-1_0.html" target="_blank">Artifact</a>, a optimized flow for mobile devices that have URL length limitations.</li>
<li><a href="http://openid4.us/specs/ab/openid-connect-code-1_0.html">Web App/Code Grant</a>, a strait forward and simple binding for web servers.</li>
<li>Smart Client, a binding for Smart user agents (in development)</li>
</ol>
</div>
<div><strong>JSON Web Token</strong> is used by Core.  It has Four parts:</div>
<div style="padding-left: 30px;">
<ol>
<li><a href="http://self-issued.info/docs/draft-jones-json-web-token.html">JSON Web Token</a>, The core token spec</li>
<li><a href="http://self-issued.info/docs/draft-jones-json-web-signature-01.html">JSON Web Signature</a>, The signature spec</li>
<li><a href="http://self-issued.info/docs/draft-jones-json-web-encryption.html">JSON Web Encryption</a>,  The encryption spec</li>
<li><a href="http://self-issued.info/docs/draft-jones-json-web-key.html">JSON Web Key</a>, A simple way to represent Public Keys</li>
</ol>
</div>
<p><strong>Discovery</strong> of user identifiers such as email for URI is performed by a <strong><a href="http://openid4.us/specs/ab/openid-connect-swd-1_0.html" target="_blank">profile</a></strong> of <strong><a href="http://self-issued.info/docs/draft-jones-simple-web-discovery-00.html">Simple Web Discovery</a></strong></p>
<p><strong><a href="http://openid4.us/specs/ab/openid-connect-sm-1_0.html">Session Management</a></strong> is currently a separate spec, however it may be folded into Core.</p>
<p><em>Revised: <a href="http://openid4.us/specs/ab/openid-connect-core-1_0.html">Core 1.0d03 incorporates the session management endpoints and eliminates some duplication.</a></em></p>
<h3>Outstanding Issues</h3>
<p>We are hoping to use our face 2 face time around IIW to resolve some of the outstanding issues:</p>
<div style="padding-left: 30px;">
<ol>
<li>Claimed ID type.   We have two proposals, one for a single URL and another for a two part identifier where the user_ID and the IdP/OP identifier are separate.</li>
<li>An extension for PAPE/Authentication Context.   This will be required for government and other higher security applications.</li>
<li>A formal spec for the User Info Endpoint and defining the base attribute schema.</li>
<li>Defining how other extensions can be added.</li>
<li>Defining a syntax for requesting sets of claims from trusted sources.</li>
</ol>
</div>
<p>We will be producing a implementers guide to make it easier for people to build clients without having to wade through all of the separate specs.</p>
<p>Expect an update after IIW in May.</p>
<p>John B.</p>
<map id="_Image-Maps_7201104291118095" name="Image-Maps_7201104291118095">
<area title="openid connect core" shape="rect" coords="66,87,162,167" href="http://openid4.us/specs/ab/openid-connect-core-1_0.html" alt="openid connect core" />
<area title="json web token" shape="rect" coords="173,88,235,168" href="http://self-issued.info/docs/draft-jones-json-web-token.html" alt="json web token" />
<area title="json web signature" shape="rect" coords="238,86,300,166" href="http://self-issued.info/docs/draft-jones-json-web-signature-01.html" alt="json web signature" />
<area title="json web encryption" shape="rect" coords="301,86,363,166" href="http://self-issued.info/docs/draft-jones-json-web-encryption.html" alt="json web encryption" />
<area title="json web key" shape="rect" coords="366,86,428,166" href="http://self-issued.info/docs/draft-jones-json-web-key.html" alt="json web key" />
<area title="simple web discovery" shape="rect" coords="444,87,506,167" href="http://openid4.us/specs/ab/openid-connect-swd-1_0.html" alt="simple web discovery" />
<area title="session management" shape="rect" coords="512,86,574,166" href="http://openid4.us/specs/ab/openid-connect-sm-1_0.html" alt="session management" />
<area title="web app binding" shape="rect" coords="66,211,168,291" href="http://openid4.us/specs/ab/openid-connect-code-1_0.html" alt="web app binding" />
<area title="user agent binding" shape="rect" coords="176,211,278,291" href="http://openid4.us/specs/ab/openid-connect-ua-1_0.html" alt="user agent binding" />
<area title="artifact binding" shape="rect" coords="283,209,385,289" href="http://openid4.us/specs/ab/openid-connect-ab-1_0.html" alt="artifact binding" />
<area title="Image Map" shape="rect" coords="628,468,630,470" href="http://www.image-maps.com/index.php?aff=mapped_users_7201104291118095" alt="Image Map" /> </map>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2011/04/29/a-map-for-openid-abc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Notes from the Latest Technology Summit</title>
		<link>http://openid.net/2010/11/22/notes-from-the-latest-technology-summit/</link>
		<comments>http://openid.net/2010/11/22/notes-from-the-latest-technology-summit/#comments</comments>
		<pubDate>Mon, 22 Nov 2010 08:56:39 +0000</pubDate>
		<dc:creator>Amanda Richardson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[openid]]></category>

		<guid isPermaLink="false">http://openid.net/?p=4159</guid>
		<description><![CDATA[by Jesse Stay Just before the latest Internet Identity Workshop, a few dozen members of the OpenID Foundation met at Facebook for a technology summit. Sessions ranged from the future of OpenID – looking at Connect and Artifact Binding – to details around profile data, signing, and encryption. Over the afternoon the group came to [...]]]></description>
			<content:encoded><![CDATA[<p>by Jesse Stay</p>
<p>Just before the latest Internet Identity Workshop, a few dozen members of the OpenID Foundation met at Facebook for a technology summit. Sessions ranged from the future of OpenID – looking at Connect and Artifact Binding – to details around profile data, signing, and encryption. Over the afternoon the group came to consensus around a number of different technical proposals.</p>
<p>You can find my notes from the day at <a href="http://bit.ly/b69H7d">http://bit.ly/b69H7d</a> and we encourage you to continue discussion on the mailing lists.  If you were at the Summit, please feel free to add anything we may have missed.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2010/11/22/notes-from-the-latest-technology-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenID Japan Launches with 32 Member Companies</title>
		<link>http://openid.net/2008/11/03/openid-japan-launches-with-32-member-companies/</link>
		<comments>http://openid.net/2008/11/03/openid-japan-launches-with-32-member-companies/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 20:59:04 +0000</pubDate>
		<dc:creator>Brian Kissel</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[openid]]></category>

		<guid isPermaLink="false">http://openid.net/?p=138</guid>
		<description><![CDATA[The OpenID Foundation is pleased to share that OpenID Japan has launched with 32 members including merchants, portals, educational institutions, insurance companies, manufacturing companies, airlines, and banks. This announcement is significant for several reasons: The number and breadth of industries represented by the new members The use of OpenID by member companies for commercial transactions [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenID Foundation is pleased to share that <a href="http://www.openid.or.jp/">OpenID Japan</a> has launched with <a href="http://www.sakimura.org/en/modules/wordpress/index.php?p=55">32 members</a> including merchants, portals, educational institutions, insurance companies, manufacturing companies, airlines, and banks.</p>
<p>This announcement is significant for several reasons:</p>
<ol>
<li>The number and breadth of industries represented by the new members</li>
<li>The use of OpenID by member companies for commercial transactions</li>
<li>Collaboration between OpenID Japan and Liberty Alliance Japan</li>
<li>An earlier survey by internet.com and Marsh Research of Japanese internet users found that 28% of knew about OpenID and 15% were using OpenID</li>
</ol>
<p>Congratulations to OpenID Japan on these significant milestones.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2008/11/03/openid-japan-launches-with-32-member-companies/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft and Google announce OpenID support</title>
		<link>http://openid.net/2008/10/30/microsoft-and-google-announce-openid-support/</link>
		<comments>http://openid.net/2008/10/30/microsoft-and-google-announce-openid-support/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 19:27:55 +0000</pubDate>
		<dc:creator>The Shared Admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[openid]]></category>

		<guid isPermaLink="false">http://openid.net/?p=120</guid>
		<description><![CDATA[This is a historic week for OpenID. Google and Microsoft announced the release of code to support OpenID 2.0 across their most important properties. On Monday, Microsoft, announced OpenID 2.0 support for their 460 million users on the LiveID platform. On Wednesday Google said it will be supporting OpenID 2.0 for any user that has [...]]]></description>
			<content:encoded><![CDATA[<p>This is a historic week for OpenID.  Google and Microsoft announced the release of code to support OpenID 2.0 across their most important properties.  On Monday, Microsoft, <a href="http://dev.live.com/blogs/devlive/archive/2008/10/27/421.aspx">announced</a> OpenID 2.0 support for their 460 million users on the LiveID platform.  On Wednesday Google <a href="http://google-code-updates.blogspot.com/2008/10/google-moves-towards-single-sign-on.html">said</a> it will be supporting OpenID 2.0 for any user that has a Google account.  Both of these deployments are great news for the OpenID community and the Internet at large.  It can be safely said that within the coming months, every single user on the Internet will have an OpenID.</p>
<p>There was some <a href="http://neosmart.net/blog/2008/google-doesnt-use-openid/">discussion</a> from a few people yesterday claiming that Google&#8217;s implementation was a fork of OpenID.  Today, Eric Sachs, Google&#8217;s lead on this effort, has <a href="http://google-code-updates.blogspot.com/2008/10/moving-another-step-closer-to-single.html">another post</a> responding to some of this early criticism:</p>
<blockquote><p>That registration requirement also led to some confusion because users wanted to be able to use existing websites that accept OpenID 2.0 compliant logins by simply entering gmail.com (or in some cases their E-mail address) into the login boxes on those websites.  &#8230;  Once the XRDS file is live, end-users should be able to use the service by typing gmail.com in the OpenID field of any login box that supports OpenID 2.0, similar to how Yahoo users can type yahoo.com or their Yahoo E-mail address (In the meantime, if you feel really geeky, you can type <a href="https://www.google.com/accounts/o8/id">https://www.google.com/accounts/o8/id</a> into an OpenID 2.0 login box).</p></blockquote>
<p>Although these are both considered &#8220;preview releases&#8221; by both companies, the fact that they have put code out there that developers can start to work with is absolutely fantastic.  Both Google and Microsoft have stated that these are testing implementations and as such, their may be certain limitations while they work on localization, scaling and general UI.</p>
<p><a href="http://self-issued.info">Mike Jones</a> <a href="http://self-issued.info/?p=89">talks</a> about some of the details of the Microsoft LiveID testing:</p>
<blockquote><p>One feature of the OpenID 2.0 implementation that I’d like to call your attention to is that they give users a choice, on a per-relying party basis, whether to use a site-specific OpenID URL at the site for privacy reasons, or whether to use a public identifier for yourself – explicitly enabling correlation of your identity interactions on different sites.</p></blockquote>
<p>We also have an episode of <a href="http://theSocialWeb.tv">theSocialWeb.tv</a> where we have Eric Sachs from Google talking about this historic week with <a href="http://daveman692.livejournal.com">David Recordon</a>, <a href="http://josephsmarr.com/">Joseph Smarr</a> and <a href="http://therealmccrea.com/">John McCrea</a>:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="437" height="288" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="id" value="viddler" /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent" /><param name="src" value="http://www.viddler.com/player/fb9b7b9b/" /><embed id="viddler" type="application/x-shockwave-flash" width="437" height="288" src="http://www.viddler.com/player/fb9b7b9b/" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2008/10/30/microsoft-and-google-announce-openid-support/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>OpenID Content Provider Advisory Committee Kickoff Meeting</title>
		<link>http://openid.net/2008/10/01/openid-content-provider-advisory-committee-kickoff-meeting/</link>
		<comments>http://openid.net/2008/10/01/openid-content-provider-advisory-committee-kickoff-meeting/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 17:45:13 +0000</pubDate>
		<dc:creator>Brian Kissel</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[affinity groups]]></category>
		<category><![CDATA[aol]]></category>
		<category><![CDATA[content providers]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[media companies]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://openid.net/?p=77</guid>
		<description><![CDATA[AARP, AOL, BBC, Google, Hearst Magazines, JanRain, Meredith, MySpace, National 4-H, National Public Radio (NPR), The New York Times, Reed Business Information, Six Apart, Time Inc., Vidoop, and Yahoo meet in NY City for first OpenID Content Provider Advisory Committee meeting hosted by the BBC.]]></description>
			<content:encoded><![CDATA[<p><a href="http://openid.net/wp-content/uploads/2008/10/openid_content_meeting.jpg"><img class="size-medium wp-image-87" style="float: right; margin-left: 15px" src="http://openid.net/wp-content/uploads/2008/10/openid_content_meeting-300x153.jpg" alt="Participants from the first OpenID Content Provider Advisory Meeting" width="300" height="153" /></a>A couple of weeks ago the BBC hosted twenty-six people from seventeen organizations including eight OpenID Providers and eight OpenID Relying Parties (sites which accept OpenID logins) in New York City to kick off an OpenID Content Provider Advisory Committee.  The goal of the session was to answer specific questions by the Content Provider community (media companies and national affinity groups) as well as to provide feedback to the OpenID Foundation, its member companies, and the wider community on the future direction of OpenID.</p>
<p>While OpenID has <a href="http://online.wsj.com/article/SB122227787438071729.html">seen rapid adoption in the &#8220;user generated content&#8221; segment</a> (blogs, discussion groups, wikis, etc.), we were very excited to see increased interest from mainstream media companies and affinity organizations.  Participants at this event included AARP, AOL, BBC, Google, Hearst Magazines, JanRain, Meredith, MySpace, National 4-H, National Public Radio (NPR), The New York Times, Reed Business Information, Six Apart, Time Inc., Vidoop, and Yahoo!.</p>
<p>Throughout the day we covered a wide range of topics including:</p>
<ul>
<li><strong>Business case for OpenID</strong> —  use cases and economic impact</li>
<li><strong>Best practices</strong> for OpenID Providers and Relying Parties in the areas of user experience, data support, security, and product features</li>
<li><strong>Optimal Content Provider user experience</strong></li>
<li><strong>Data Management </strong>— sources, integration, industry specific data, accuracy, security &amp; trust</li>
<li><strong>Coming Enhancements</strong> — Provider Authentication Policy Extension (PAPE), OAuth, Portable Contacts API, MySpace Data Availability, and integration of OpenID into browsers.</li>
</ul>
<p>Yahoo!, Google, and MySpace all presented information about their OpenID Provider services, thoughts on user experience and lessons learned, and some future plans.  <strong>National 4-H</strong> presented a summary of an OpenID-based integrated National, State, and Local web platform that they will be deploying in the coming months.  We shared a case study on <strong>Japan Airlines (JAL)</strong> federated partner commerce using OpenID with the proposed Trusted Data Exchange (TX) extension that <strong>Nomura Research Institute</strong> (NRI) has been developing.   There was extensive discussion between existing and potential Relying Parties and the OpenID Providers about what would facilitate faster and broader adoption of OpenID in the Content Provider community.  The session was moderated and feedback captured by Market Focus, a strategic marketing consulting firm who will be performing additional customer and market research on behalf of the OpenID Foundation.</p>
<p>If other content providers would like to join this advisory committee, please contact <a href="mailto:jernst@netmesh.com">Johannes Ernst</a> or <a href="mailto:bkissel@janrain.com">Brian Kissel</a> <a href="mailto:bkissel@janrain.com"></a>of the OpenID Foundation Customer Research Committee for further information.</p>
<p>Additionally, many members of the OpenID community will be attending the upcoming <a href="http://iiw.idcommons.net/Iiw2008b">Internet Identity Workshop (IIW) on November 10-12</a> at the Computer History Museum in Mt. View, CA.  This will provide a great venue for face to face discussions and additional opportunities to provide input and feedback on the future direction of OpenID.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2008/10/01/openid-content-provider-advisory-committee-kickoff-meeting/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>mixi Supports OpenID with the Simple Registration Extension</title>
		<link>http://openid.net/2008/08/25/mixi-supports-openid-with-the-simple-registration-extension/</link>
		<comments>http://openid.net/2008/08/25/mixi-supports-openid-with-the-simple-registration-extension/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 22:33:09 +0000</pubDate>
		<dc:creator>David Recordon</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[mixi]]></category>
		<category><![CDATA[movable type]]></category>
		<category><![CDATA[openid]]></category>

		<guid isPermaLink="false">http://openid.net/?p=71</guid>
		<description><![CDATA[Last week mixi, the largest social network in Japan, become an OpenID Provider for all of their fifteen-million plus users; one in five Japanese web users are on mixi. While they are another large OpenID Provider &#8212; which some argue is a bad thing &#8212; they are the first large OpenID Provider to also support [...]]]></description>
			<content:encoded><![CDATA[<p>Last week <a href="http://mixi.jp/">mixi</a>, the largest social network in Japan, become an OpenID Provider for all of their fifteen-million plus users; one in five Japanese web users are on mixi.  While they are another large OpenID Provider &#8212; which some argue is a bad thing &#8212; they are the first large OpenID Provider to also support exchanging profile information.  While early adopters using OpenID Providers such as <a href="http://myopenid.com/">MyOpenID.com</a>, <a href="http://MyVidoop.com/">MyVidoop.com</a>, and <a href="http://pip.verisignlabs.com/">VeriSign&#8217;s PIP</a> have had the ability to exchange profile information for well over a year with the <a href="http://openid.net/specs/openid-simple-registration-extension-1_0.html">Simple Registration Extension</a>, this is an important step forward with larger OpenID Providers seeing the value in exchanging profile information as well.  This means that when a mixi user logs in to a site using their OpenID, the site is able to request access to things from their profile like their name.</p>
<p>Earlier today, ReadWriteWeb wrote more about how <a href="http://www.readwriteweb.com/archives/mixi_brings_sophisticated_open.php">Mixi Brings Sophisticated OpenID to Millions of Japanese Users</a> asking why Facebook isn&#8217;t using OpenID for their Connect APIs and providing a good overview of why mixi adopting OpenID with Simple Registration is helping to push the envelope:</p>
<blockquote><p>The moral of the story, though, is that another major social network now supports OpenID and is pushing the envelope with the features included. They aren&#8217;t acting as a relying party yet, allowing users to login with OpenID from other networks, but the functionality of Mixi user profiles has now increased dramatically thanks to open standards.</p></blockquote>
<p>Along with mixi&#8217;s launch last week, <a href="http://www.movabletype.org/2008/08/connecting_mixi_with_movable_type.html">Six Apart released a mixi commenting plugin for Movable Type</a>.  (Disclosure: I work for Six Apart)  This plugin allows mixi users to comment on Movable Type powered blogs and have their name from their profile show up next to their comment.</p>
<p>All in all, great news for OpenID coming out of Japan!</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2008/08/25/mixi-supports-openid-with-the-simple-registration-extension/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Challenges facing OpenID</title>
		<link>http://openid.net/2008/08/10/challenges-facing-openid/</link>
		<comments>http://openid.net/2008/08/10/challenges-facing-openid/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 05:00:37 +0000</pubDate>
		<dc:creator>Scott Kveton</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[usability]]></category>

		<guid isPermaLink="false">http://openid.net/?p=70</guid>
		<description><![CDATA[Its been an busy week in the world of OpenID. On Friday Ben Laurie announced a security vulnerability around OpenID that relates to existing problems with DNS and certain SSL certificates. Discussions on the OpenID General mailing list have been fruitful and the major OpenID providers out there today have disclosed that they are either [...]]]></description>
			<content:encoded><![CDATA[<p>Its been an busy week in the world of OpenID.  On Friday Ben Laurie <a href="http://seclists.org/fulldisclosure/2008/Aug/0123.html">announced</a> a security vulnerability around OpenID that relates to existing problems with DNS and certain SSL certificates.  Discussions on the <a href="http://openid.net/mailman/listinfo/general">OpenID General</a> mailing list have been fruitful and the major OpenID providers out there today have disclosed that they are either not vulnerable or patching quickly.  It should also be noted that none of the providers listed at <a href="http://openid.net/get">openid.net/get</a> were ever vulnerable to this attack.</p>
<p>One of the greatest parts of the OpenID community is that the people developing this technology react so quickly to problems that inevitably arise.  There is no such thing as 100% secure with anything on the Internet but we can (and have) put measures into place to react quickly as a community when issues like this occur.</p>
<p>OpenID has two challenges it faces to increase adoption and use; security and usability.  This afternoon, Randall Stross of the New York Times published his <a href="http://www.nytimes.com/2008/08/10/technology/10digi.html">&#8220;Digital Domain&#8221;</a> column criticizing OpenID on both of these points.  Its great to see people looking at security with regards to OpenID and asking the hard questions and it also highlights a few common misconceptions:</p>
<ul>
<li><strong>Authentication is out of scope for OpenID:</strong> Because there is no silver bullet for security, the way you authenticate your OpenID is actually out-of-scope of the protocol.  As such, you can use whatever level of security you want to protect your OpenID.  We have seen vendors offer unique solutions like Verisign&#8217;s <a href="http://www.verisign.com/authentication/consumer-authentication/vip-authentication/">VIP</a>, JanRain&#8217;s <a href="https://www.myopenid.com/about_callverifid">CallVerifID</a> and Vidoop&#8217;s <a href="http://www.vidoop.com/products">ImageShield</a> created to provide alternatives to passwords for authenticating users&#8217; OpenID&#8217;s.  OpenID allows companies both large and small to experiment with ways to authenticate their users without requiring buy-in from sites across the Internet.</li>
<li><strong>Information Cards solve a different problem than OpenID&#8217;s:</strong> In his article, Randall mentions how Information Cards are more superior in terms of authentication compared to OpenID.  In actuality, you can use an Information Card to secure your OpenID if you want and there has been a lot of work on this within the OpenID community.  VeriSign&#8217;s OpenID provider even supports Information Cards in addition to token based authentication. Information Cards provide the means to securely authenticate you assuming you have the technology installed on your machine.  In addition, Information Cards lack the ability to take advantage of one of OpenID&#8217;s main strengths, the destination or URL that a user has proved they own.  The potential for this end-point for services is limitless and may serve as one of the key components driving OpenID use; the ability to move data from somewhere on the Internet that you have proved you own.</li>
<li><strong>Nobody is really adopting OpenID:</strong> I&#8217;m always surprised to hear people say that just because the big players are only OpenID providers (and not consumers) that we&#8217;re failing here.  I always try to remind people that this technology is only three years old and we&#8217;ve made tremendous strides since its inception.  Not only that, the latest <a href="http://janrain.com/blog/2008/07/08/relying-party-stats-as-of-july-1st-2008/">graphs</a> continue to show hyperbolic growth.  These things take time and again, security and usability will be key drivers to OpenID adoption moving forward.</li>
</ul>
<p>I&#8217;m excited to see a lot of interesting efforts from the community to help with usability.  Tom from Barnraiser.org has been doing a <a href="http://www.barnraiser.org/openid_usability_part_1:_the_email_address_versus_the_openid_uri">series</a> of <a href="http://www.barnraiser.org/openid_usability_part_2:_the_authentication_workflow">articles</a> that describe some of these usability issues.  We&#8217;ve seen community efforts such as <a href="http://eaut.org">Email Address to URL Translation</a>, which allows users to enter their email addresses instead of URL&#8217;s and <a href="http://idib.googlecode.com">Identity in the Browser</a> (IDIB) which is hoping to bake OpenID functionality (and increased security) into all of the modern browsers.</p>
<p>On the security front, we&#8217;re seeing traction in the development of the <a href="http://openid.net/specs/openid-provider-authentication-policy-extension-1_0-01.html">OpenID Provider Authentication Policy Extension</a> (PAPE) which will help sites be able to determine which providers they will trust based on the means of authentication the user has used to get access.  Both <a href="http://www.sxip.com">Sxip</a> and <a href="http://janrain.com">JanRain</a> have implemented early prototypes of PAPE on their OpenID providers.</p>
<p>We&#8217;ve got a long way to go here with OpenID and getting it to a point where it can stand in the face of criticism but I&#8217;m confident of this community that has come together through the first three years to get where we are today.  I still firmly believe the best is yet to come.</p>
]]></content:encoded>
			<wfw:commentRss>http://openid.net/2008/08/10/challenges-facing-openid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

