Scott Johnson | 23 Mar 2013 02:20
Picon
Favicon

[OpenID] General questions for developing an OpenID portal

 

Hello,

 

  I’ve been reading up on the docs for both DotnetAuth and OpenID lately.  I have a few questions as I’m not fully understanding the different pieces that would be necessary to code to create my own OpenID provider and portal.  I was hoping someone can tell me specifically what pieces I need to code for what I need to do below.

 

  I do have very specific technical reasons why I need to develop my own OpenID portal in my product line. 

 

My current product manages user IDs. 

 

What I need my program to do is create a page of links(portal), eg. Google Apps, Moodle, etc… on a page that a user can click on which will then pass them through to the site with their currently logged in credentials (SSO).

 

I know I’ll need to code an identity provider.  But will I need to code a relaying party for the local portal to work?

 

Thanks for your insight; it’s much appreciated!

 

_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Nat Sakimura | 15 Mar 2013 22:49
Picon
Gravatar

[OpenID] German eID Card now used with OpenID

I just came across with this article of March 4. 

I cannot read German so google translating it. I do not know the fidelity of it, but apparently the combination of German eID and OpenID was app approved by the State Procurement Agency for authorization certificates (VfB) so that official website operator can authenticate the users with their eID card their legally. Correct me if I am wrong. Perhaps a German reader can further explain what it is. I am also interested in how they implemented the authorization certificate / terminal certificate portion. 

http://www.itespresso.de/2013/03/04/kartenleser-pruft-identitat-fur-openid-per-personalausweis/

Best, 

--
Nat Sakimura (=nat)
Chairman, OpenID Foundation
http://nat.sakimura.org/
<at> _nat_en
_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Nat Sakimura | 20 Jan 2013 05:11
Picon
Gravatar

[OpenID] Google Declares War on the Password

FYI.

Google Declares War on the Password  http://t.co/nLDloxui "USB-based
Yubico log-on devices"

=nat via iPhone
Don Thibeau | 14 Jan 2013 16:02

[OpenID] The OpenID Foundation (OIDF) community board member election call for nominations


The OpenID Foundation (OIDF) community board member election call for nominations will open on Monday, January 7.

All members of the OpenID Foundation are eligible to nominate themselves, second the nominations of others who self-nominated, and vote for candidates. If you are receiving this email, you are an OIDF member in good standing and will receive an email on January 7 advising you that the election is open and how to participate.

Voting and nominations are conducted using the OpenID you registered when you joined the Foundation. You will need to log in with your OpenID membership credentials at https://openid.net/foundation/members/ to participate in the nomination and voting. Please send an email to help <at> oidf.org if you experience problems participating in the election.

The Foundation plays an important role in the evolution of Internet identity technologies. Those elected will help determine what role the OIDF should play in helping facilitate faster and broader adoption of open standard identity systems.

Board participation requires a substantial ongoing investment of time and energy. It is a volunteer effort that should not be undertaken lightly. Should you be elected, expect to be called upon to serve both on the board and on its committees where the work of the foundation is conducted. If you’re committed to OpenID and advancing open digital identity and are a person who works well with others, we encourage your candidacy. The OIDF’s Executive Committee has suggested a few questions candidates may want to publicly address in their candidate statements:

  1. What are the key opportunities you see for the OpenID Foundation in 2013?
  2. How will you demonstrate your commitment to the work of the foundation in terms of resources, focus and leadership?
  3. What would you like to see accomplished over the next year, and how do you personally plan to make these things happen?
  4. What resources can you bring to the foundation to help the foundation attain its goals?
  5. What current or past experiences, skills, or interests will inform your contributions and views?

Candidates can address these questions in their election statements on various community mailing lists, especially openid-general <at> lists.openid.net.

Last year two community board members were elected to 2-year terms and so are not standing for election:

  • Greg Keegstra
  • Axel Nennker

Other current community board members may seek re-election. They are:

  • Nat Sakimura
  • Mike Jones
  • John Bradley
  • Kick Willemse
  • George Fletcher

For the purposes of the 2013 election, there are 6 confirmed sustaining members: Google, Microsoft, PayPal, Ping Identity, Symantec, and Verizon. Thus, we will be electing 5 community members to the Board of Directors to bring the total number of community members to 7. To preserve the staggered election structure so that half of the community board members will be elected every year, the 4 candidates (half the number of community members, rounded up) receiving the most votes will be elected for 2-year terms and the candidate receiving the next amount of votes will be elected for a 1-year term, resulting in 3 board members being elected in the subsequent election given a stable number of sustaining members. In the case of a tie between the candidates receiving the 4th and 5th number of votes, both will receive 1-year terms. In order to be eligible for election, a candidate must be seconded by at least three other members.

The election will be conducted on the following schedule:

  • Nominations open: Monday, January 7, 2013
  • Nominations close: Monday, January 21, 2013
  • Election begins: Wednesday, January 23, 2013
  • Election ends: Wednesday, February 6, 2013
  • Results announced by: Wednesday, February 13, 2013
  • New board terms start: Wednesday, February 27, 2013

Times for all dates are Noon, U.S. Pacific Time.

Please forward questions, comments and suggestions to me at don <at> oidf.org.

Regards,

Don Thibeau
Executive Director
The OpenID Foundation

P.S. Members should also know that the foundation will be holding a vote to approve a second set of Implementer’s Drafts of the OpenID Connect specifications soon. An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification. We expect the candidate specifications to be ready for the 45 day public review period soon. Watch the announcements at http://openid.net/ and your mailbox for announcements about this upcoming review and vote.







Don Thibeau



_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Don Thibeau | 15 Nov 2012 16:25

[OpenID] Comments New Jersey's decision to allow voting by e-mail.

Comments New Jersey's decision to allow voting by e-mail.
http://www.crypto.com/blog/njvoting/
https://freedom-to-tinker.com/blog/felten/new-jersey-voting-in-the-aftermath-of-hurricane-sandy/ orhttp://tinyurl.com/b4eevle
https://freedom-to-tinker.com/blog/appel/oral-arguments-124-in-nj-voting-machine-lawsuit/ orht tp://tinyurl.com/axzqq5o

Don Thibeau



_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Peter Williams | 3 Nov 2012 16:48
Picon
Favicon
Gravatar

Re: [OpenID] One developer's first encounter with account chooser (openid connect?)

I was never originally very excited by user-centric identity or the notion of the self-signed CA of SSL website (earlier) - coming partly from the highly indoctrinated, yes-sire, no sire,  govt world of centralized security policy management, big sticks, mega-money, and reams of audit paperwork that nicely masks over the (typically wide) cracks  - to suit the desired governance doctrine of the day.
 
But, over the years, folks of the cryptoanarchy lilt did persuade me to recognize their cause - mostly because no harm has actually emerged. And, a certain novel trust doctrine emerged furthermore - based on low assurance crypto, and low-assurance key distribution. It scales in a manner which I think W3C founder-class thinkers once-called “webby”.
 
Anyways, I don't hear much about “user centric” identity today. Perhaps the funding has gone away, as most folks seem to be taking a trickle of silver coin hoping for the talons of gold on offer from Augustus’ treasury. So I thought I’d go retro and just now consider the openid pitch of a few years ago (remembering who used to say what, back then). If one plays with those discarded ideas NOW - using modern forms of the technology - what can one now do? Note I way sne, not we - hoping to capture the individual as a person, distinguished from you as some corporate “subscriber”.
 
I asked myself: is there a role for user centric identity any longer in the openid community? If so, what can one build in a day? (See http://wp.me/p1fcz8-35W  for my own effort). Since the UCI term has no real meaning these days, I interpreted it in the sense of a DARPA working in the early internet: get to “survivability”, for the individual.
 
Is “UCI” really dead, in openid land? Or is there a new word for it?
 
Sent from Windows Mail
 
From: Peter Williams
Sent: ‎October‎ ‎27‎, ‎2012 ‎12‎:‎39‎ ‎AM
To: openid-general <at> lists.openid.net
Subject: RE: One developer's first encounter with account chooser (openid connect?)
 
Well I should give apologies to Google, as there IS a local login function in its account creator wordpress integration. Though ...it did take a week to find it. If you type a local account name into the box labeled "email", it does a classical local login (with local password challenge). 
 
 
_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Peter Williams | 24 Oct 2012 19:48
Picon
Favicon
Gravatar

[OpenID] assurance concepts for OAUTH

I'm taking a good long hard look at OAUTH, these days, mostly because Microsoft have integrated it (much like signed DUA and signed DSA chaining operations from CCITT's X.500 1988 work) into both their Azure Directory tenant services and their data service API frameworks, more generally. This tells me there is a certain maturity - a signal that I'd be prudent to note.
 
One thing I note as I read is an omnipresent assumption - that is really just not warranted. Much of the terminology and the design features implied by wording would have it that oauth tokens are directly consumed by resources, with application-layer access control guards.
 
From everything Ive learned over the last 5 years of token-passing schemes deployment, it is rare - outside webby/scripting php/asp.net type software - that legacy resource systems for lines-of business type software directly consume the tokens. Rather, they have their proprietary/legacy guards and expect to continue to use them - now supported by a translation unit converts such as oauth tokens into the proprietary/legacy token.
 
For example, a SID claim in an oauth token may well be what drives the ACL function of a windows-centric guard, when accessing a file resource. A trusted process (in assurance theory) converts the oauth token to the SID, and the SID and the ACL rules are enforced by the reference monitor all of whose integrities are secured by the kernel of a CC-evaluated OS. Typically, the process must also translation authorization constructs, from layer-7 group constructs to properly-designed resource-centric groups maintained by such as a AD GC server. For all I know, this may all be driven by an OAUTH/Kerberos-ticket handoff.
 
Folks may want to bear in mind the assured world, when writing. Not everything is a php script working with name/value pairs.
 
 
 
 
_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
nieuws groep | 22 Oct 2012 00:08
Picon
Favicon

[OpenID] EU OpenID Summit 21th November The Hague Netherlands - 45 free seats available

All,

The OpenID Foundation is hosting an EU OpenID workshop as a joint event with the Identity.Next Conference on November 21th.  It will be held in The Hague, The Netherlands. The OpenID Foundation runs a series of workshops like this one for business decision makers, as well as running other OpenID summits that are more technical.

The event is for the owners of consumer websites, citizen oriented government sites, and enterprise SaaS services to discuss how to improve login systems by using techniques such as OAuth, OpenID and an Account Chooser.

Please join us on Thursday, November 21th, 2012 from 11:00 until 15:00 GMT.

We have 45 free seats available to visit the OpenID summit on the second day. The Identity.Next event is a two day event, people are also able to attend to first day with only a one-day entrance fee. Check the identity.next website for more information about the conference (www.identitynext.com).

REGISTER NOW! Registration is open at the following link for the 45 free one-day seats (select general admission (one day):

http://idnext12.eventbrite.com/?discount=IDNEXT12-OPENID

Location:
New Babylon Center
Koningin Julianaplein 30 - 2595, The Hague
The Netherlands

DRAFT AGENDA:

11.00-11.30 Introduction OpenID foundation Nat Sakimura

11.30 -12.15 The OpenID connect Protocol and Mobile Demonstration John Bradley

13.30 – 14.15  Improving the user experience of sign-in using an Account Chooser Nat Sakimura

14.15 – 15.00 Business benefits for relying party’s accepting OpenID Kick Willemse

 

 

 


_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Peter Williams | 17 Oct 2012 20:59
Picon
Favicon
Gravatar

[OpenID] a developers first encounter with account chooser (openid connect?)

In a word: frustrating. http://wp.me/p1fcz8-2YW. It was frustrating on multiple levels, some of them political, some about clearly over zealous monitoring of RP matters, and some due to and obvious lack of willingness to listen to mature RP communities and their requirements for adoption. But, whats new.
 
Obviously the code is fixable, but one worries about the very "idea" - there seems a desperation in the desire to remove local IDPs - including those granting access to privileged administrator configuring (broken) federated logon!
 
To be fair, the default Microsoft ASP.NET web app project built by the released version of visual studio 20102 doesn't work, either - when taking up the federated (OAUTH/openid) login option and its display of a set of IDPs, configured locally. It doesn't even compile, link and load! Thus, I have not even so far as work with its attempt to showcase Openid Connect, or see if things interwork yet with Google's implementation, etc.
 
 
 
_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Peter Williams | 17 Oct 2012 21:03
Picon
Favicon
Gravatar

[OpenID] One developer's first encounter with account chooser (openid connect?)

In a word: frustrating. http://wp.me/p1fcz8-2YW. It was frustrating on multiple levels.
 
Obviously the code is fixable, but one worries about the very "idea" - there seems a desperation in the desire to remove local IDPs - including those granting access to privileged administrator configuring (broken) federated logon!
 
To be fair, the default Microsoft ASP.NET web app project built by the released version of visual studio 20102 doesn't work, either - when taking up the federated (OAUTH/openid) login option and its display of a set of IDPs, configured locally. It doesn't even compile, link and load! Thus, I have not even so far as work with its attempt to showcase Openid Connect, or see if things interwork yet with Google's implementation, etc.
 
Sent from Windows Mail
 
_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general
Mike Jones | 5 Oct 2012 01:34
Picon
Favicon

[OpenID] OpenID Meeting at IETF 85

 

 

From: openid-specs-ab-bounces <at> lists.openid.net [mailto:openid-specs-ab-bounces <at> lists.openid.net] On Behalf Of John Bradley
Sent: Tuesday, October 02, 2012 8:45 PM
To: openid-specs-ab <at> lists.openid.net Group
Cc: openid-connect-interop <at> googlegroups.com; openid-specs-backplane <at> lists.openid.net; openid-board <at> lists.openid.net; marketing <at> lists.openid.net
Subject: [Openid-specs-ab] OpenID Meeting at IETF 85

 

OpenID Meeting

People interested in OpenID ConnectAccount Chooser, and how they relate to IETF specifications such as OAuth, JSON Web Token (JWT), and JSON Object Signing and Encryption (JOSE) are meeting at IETF #85.  We will meet at 1:00 on Sunday, November 4th, and have the room all afternoon.  An overview of the specifications and status will be provided and open issues and next steps will be discussed.

 

Register at http://connect-ietf-85.eventbrite.com

_______________________________________________
general mailing list
general <at> lists.openid.net
http://lists.openid.net/mailman/listinfo/openid-general

Gmane