Shibboleth.net discovery interface
Cantor, Scott
cantor.2 at osu.edu
Mon Jan 6 13:02:40 EST 2014
On 1/6/14, 12:54 PM, "Michael Schwartz" <mike at gluu.org> wrote:
>Probably a dumb idea, but why not OFFER OpenID Connect Discovery also:
> http://openid.net/specs/openid-connect-discovery-1_0.html
To the extent that it's based on discovery by e-mail address, the reasons
why that's inherently evil are pretty well known. That's just a Google
trojan horse.
There isn't anything I know of to ask a user to enter that's
understandable and compatible with a non-monopolist identity solution.
Once something exists, I'm happy to discuss it, but I have no idea what it
would be, which is why I haven't proposed anything.
-- Scott
More information about the dev
mailing list