RE: [security-services] [Fwd: Re: OpenID Mobile Profile?]

From
Scott Cantor <>
Date
2009-02-03T15:39:18+00:00
ID
002f01c98615$8f820d70$ae862850$@
Thread
RE: [security-services] [Fwd: Re: OpenID Mobile Profile?]
Paul Madsen wrote on 2009-02-03:
> FYI, the OpenID folks are contemplating an artifact mechanism to deal with
> mobile client limitations

I can't recall the last time I ran into a phone browser that didn't handle
POST fine, at least on a device anybody would actually use to access the
web.

> The difference between this flow and the SAML artifact binding is that
> in case of SAML, the artifact/ticket is created by the RP and OP goes
> and fetch the request from RP.

I don't think they understand that the binding goes either way...

-- Scott