<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Revising OpenID for WordPress</title>
	<atom:link href="http://www.cryptosmith.com/archives/325/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cryptosmith.com/archives/325</link>
	<description>Authentication, crypto, information security, and life with gadgets - Rick Smith</description>
	<lastBuildDate>Thu, 19 Nov 2009 04:27:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Dr. Rick Smith</title>
		<link>http://www.cryptosmith.com/archives/325/comment-page-1#comment-7191</link>
		<dc:creator>Dr. Rick Smith</dc:creator>
		<pubDate>Sun, 21 Sep 2008 18:17:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.cryptosmith.com/?p=325#comment-7191</guid>
		<description>&lt;strong&gt;Regarding &#039;owner delegation&#039;&lt;/strong&gt; - if I understand it correctly, it establishes a single OpenID redirection based on the blog&#039;s main URL (like www.cryptosmith.com for this one). 

I generally have two separate logins for any system on which I serve as administrator: one for routine activities (writing and editing posts) that has minimal author rights and another that has full administrative rights. 

In any case, I have already hand-built some OpenID redirection pages that do what I need, so I probably won&#039;t use the redirection features.

&lt;strong&gt;Regarding WordPress as an OpenID provider - &lt;/strong&gt;there is definitely a use case for it. When I was first playing with OpenID I wanted to be my own provider if only to try to minimize the parts I was using. I&#039;d just hate to have someone use this to &lt;strong&gt;authenticate their bank account. &lt;/strong&gt;
</description>
		<content:encoded><![CDATA[<p><strong>Regarding &#8216;owner delegation&#8217;</strong> &#8211; if I understand it correctly, it establishes a single OpenID redirection based on the blog&#8217;s main URL (like <a href="http://www.cryptosmith.com" rel="nofollow">http://www.cryptosmith.com</a> for this one). </p>
<p>I generally have two separate logins for any system on which I serve as administrator: one for routine activities (writing and editing posts) that has minimal author rights and another that has full administrative rights. </p>
<p>In any case, I have already hand-built some OpenID redirection pages that do what I need, so I probably won&#8217;t use the redirection features.</p>
<p><strong>Regarding WordPress as an OpenID provider &#8211; </strong>there is definitely a use case for it. When I was first playing with OpenID I wanted to be my own provider if only to try to minimize the parts I was using. I&#8217;d just hate to have someone use this to <strong>authenticate their bank account. </strong></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Norris</title>
		<link>http://www.cryptosmith.com/archives/325/comment-page-1#comment-7190</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Sun, 21 Sep 2008 17:35:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.cryptosmith.com/?p=325#comment-7190</guid>
		<description>Thanks for the thorough analysis of the plugin... this definitely helps in prioritizing where I spend my development efforts.  A few specific notes:

 - I&#039;ve not tested SSL specifically in the new release, but I&#039;m using FORCE_SSL_LOGIN with it successfully, so it appears to be working.  I&#039;ll make sure and test FORCE_SSL_ADMIN as well.

 - I didn&#039;t create the &quot;/author/&quot; convention, that&#039;s built in to WordPress.  You can change it with a small amount of code though - see &lt;a href=&quot;http://wordpress.org/support/topic/144217?replies=8#post-842311&quot; rel=&quot;nofollow&quot;&gt;this post&lt;/a&gt;.

 - Could you clarify your concern about &quot;owner delegation&quot; and being &quot;stuck with only one user ID&quot;.  Are you referring to the fact that you can only delegate to a single OpenID, rather than having multiple delegates, in case one fails?

 - I agree that using WordPress as a standalone OpenID provider is probably not the best idea.  Perhaps I&#039;ll put some stronger language in there explaining why it&#039;s dangerous.  Nonetheless, I can&#039;t deny that there is a use-case for it, and as you said all the pieces were basically in place.  However, I have no intentions of going out of my way to make it a fully-featured provider (audit log, multiple personas, etc), given that I think it&#039;s a bad idea anyway.</description>
		<content:encoded><![CDATA[<p>Thanks for the thorough analysis of the plugin&#8230; this definitely helps in prioritizing where I spend my development efforts.  A few specific notes:</p>
<p> &#8211; I&#8217;ve not tested SSL specifically in the new release, but I&#8217;m using FORCE_SSL_LOGIN with it successfully, so it appears to be working.  I&#8217;ll make sure and test FORCE_SSL_ADMIN as well.</p>
<p> &#8211; I didn&#8217;t create the &#8220;/author/&#8221; convention, that&#8217;s built in to WordPress.  You can change it with a small amount of code though &#8211; see <a href="http://wordpress.org/support/topic/144217?replies=8#post-842311" rel="nofollow">this post</a>.</p>
<p> &#8211; Could you clarify your concern about &#8220;owner delegation&#8221; and being &#8220;stuck with only one user ID&#8221;.  Are you referring to the fact that you can only delegate to a single OpenID, rather than having multiple delegates, in case one fails?</p>
<p> &#8211; I agree that using WordPress as a standalone OpenID provider is probably not the best idea.  Perhaps I&#8217;ll put some stronger language in there explaining why it&#8217;s dangerous.  Nonetheless, I can&#8217;t deny that there is a use-case for it, and as you said all the pieces were basically in place.  However, I have no intentions of going out of my way to make it a fully-featured provider (audit log, multiple personas, etc), given that I think it&#8217;s a bad idea anyway.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
