IRC Log for #openid on 2008-01-24
Timestamps are in UTC.
- [00:44:02] * shigeta (n=shigeta@ has joined #openid
- [01:07:13] * jibot (i=andy@ Quit (
- [01:07:13] * Acro (i=acro@unaffiliated/acro) Quit (
- [01:07:13] * keturn ( Quit (
- [01:21:00] * keturn (n=kevint@pdpc/supporter/sustaining/keturn) has joined #openid
- [01:23:28] * dbounds ( has joined #openid
- [01:23:47] <dbounds>
- [01:24:25] * michelp ( Quit (Remote closed the connection)
- [01:52:13] * michelp ( has joined #openid
- [02:15:01] * Didac ( Quit (Read error: 110 (Connection timed out))
- [02:19:56] * Mitsurugi ( has joined #openID
- [02:30:58] * PibbRelay (n=supybot@nat/janrain/x-6d073d368b303719) Quit (Read error: 104 (Connection reset by peer))
- [02:34:25] * PibbRelay (n=supybot@nat/janrain/x-144020c9b27700db) has joined #openid
- [03:04:44] * jrbot ( Quit (Read error: 110 (Connection timed out))
- [03:04:47] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) Quit (Read error: 110 (Connection timed out))
- [03:30:04] * idnar_ ( has joined #openid
- [03:30:26] * idnar (i=mithrand@unaffiliated/idnar) Quit (Nick collision from services.)
- [03:40:31] * idnar (i=mithrand@unaffiliated/idnar) has joined #openid
- [03:44:04] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) has joined #openid
- [03:45:33] <PibbRelay>
<CrazySane> How's it going?
- [03:48:39] * jrbot ( has joined #openid
- [03:49:05] * idnar_ (i=mithrand@unaffiliated/idnar) Quit (Read error: 110 (Connection timed out))
- [03:50:14] * KevinMarks (n=KevinMar@nat/google/x-8d9f3dd7237a448a) Quit ("The computer fell asleep")
- [03:50:26] * KevinMarks (n=KevinMar@nat/google/x-c31ad54a8ec3e961) has joined #openid
- [04:07:18] * KevinMarks (n=KevinMar@nat/google/x-c31ad54a8ec3e961) Quit (Read error: 110 (Connection timed out))
- [04:15:29] * stub ( has joined #openid
- [04:19:26] <PibbRelay>
<Joel> Anybody alive in here?
- [04:20:03] * Sociophobe (i=Sociopho@ has joined #OpenID
- [04:27:08] <PibbRelay>
<Joel> I answered my own question. Joined the dev@ mailing list and now I can send patches.
- [04:32:55] * PibbRelay (n=supybot@nat/janrain/x-144020c9b27700db) Quit (Read error: 104 (Connection reset by peer))
- [04:36:45] * PibbRelay (n=supybot@nat/janrain/x-7d628b515d4a0af0) has joined #openid
- [04:57:26] <PibbRelay>
<CrazySane> I'm here
- [05:41:46] * SvenDowideit (n=SvenDowi@twiki/developer/SvenDowideit) has joined #openid
- [06:24:17] * shigeta_ (n=shigeta@ has joined #openid
- [06:31:33] * PibbRelay (n=supybot@nat/janrain/x-7d628b515d4a0af0) Quit (Read error: 104 (Connection reset by peer))
- [06:37:56] * shigeta (n=shigeta@ Quit (Read error: 110 (Connection timed out))
- [06:38:21] * PibbRelay (n=supybot@nat/janrain/x-56f21fcd5c6fdcfc) has joined #openid
- [07:16:38] * PibbRelay (n=supybot@nat/janrain/x-56f21fcd5c6fdcfc) Quit (Connection reset by peer)
- [07:20:56] * polyonymous ( Quit (Read error: 110 (Connection timed out))
- [07:23:06] * polyonymous ( has joined #openid
- [07:25:08] * Mitsurugi ( Quit (Read error: 104 (Connection reset by peer))
- [07:39:25] * Mitsurugi ( has joined #openID
- [08:53:02] * Prometheus^ ( has joined #openid
- [08:53:30] * Prometheus^ ( Quit (Remote closed the connection)
- [08:58:16] * PibbRelay (n=supybot@nat/janrain/x-f3b995378b609ddf) has joined #openid
- [08:58:49] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 113 (No route to host))
- [09:33:22] * Mitsurugi ( Quit (
- [09:33:22] * PibbRelay (n=supybot@nat/janrain/x-f3b995378b609ddf) Quit (
- [09:33:22] * johnjay (n=r2d2@ Quit (
- [09:33:22] * Tobsn ( Quit (
- [09:34:03] * PibbRelay (n=supybot@nat/janrain/x-f3b995378b609ddf) has joined #openid
- [09:34:03] * Mitsurugi ( has joined #openid
- [09:34:03] * johnjay (n=r2d2@ has joined #openid
- [09:34:03] * Tobsn ( has joined #openid
- [09:48:07] * PibbRelay (n=supybot@nat/janrain/x-f3b995378b609ddf) Quit (Success)
- [10:03:22] * hillsy ( has joined #openid
- [10:03:54] * stub ( has joined #openid
- [10:27:03] * hillsy ( Quit ("Leaving")
- [10:30:08] * quirim ( Quit (Read error: 110 (Connection timed out))
- [10:35:08] * idnar (i=mithrand@unaffiliated/idnar) Quit (Read error: 110 (Connection timed out))
- [10:42:03] * stub (n=stub@canonical/launchpad/stub) Quit (
- [10:42:03] * ricky (n=ricky@fedora/ricky) Quit (
- [10:42:03] * amir (n=Miranda@gentoo/developer/amir) Quit (
- [10:42:03] * rje`cf ( Quit (
- [10:42:03] * ianloic ( Quit (
- [10:42:03] * XRIBot (n=XRIBot@ Quit (
- [10:42:03] * walkah ( Quit (
- [10:42:14] * polyonymous ( Quit (
- [10:42:14] * jrbot ( Quit (
- [10:42:14] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) Quit (
- [10:42:14] * miyagawa ( Quit (
- [10:42:14] * lopnor_ ( Quit (
- [10:42:14] * DJCapelis (n=djc@blender/coder/DJCapelis) Quit (
- [10:42:23] * shigeta_ (n=shigeta@ Quit (
- [10:43:23] * shigeta_ (n=shigeta@ has joined #openid
- [10:43:53] * MrTopf (n=cs@ has joined #openid
- [10:44:02] * polyonymous ( has joined #openid
- [10:44:02] * jrbot ( has joined #openid
- [10:44:02] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) has joined #openid
- [10:44:02] * DJCapelis (n=djc@blender/coder/DJCapelis) has joined #openid
- [10:44:02] * miyagawa ( has joined #openid
- [10:44:02] * lopnor_ ( has joined #openid
- [10:44:09] * stub (n=stub@canonical/launchpad/stub) has joined #openid
- [10:44:09] * walkah ( has joined #openid
- [10:44:09] * ricky (n=ricky@fedora/ricky) has joined #openid
- [10:44:09] * rje`cf ( has joined #openid
- [10:44:09] * amir (n=Miranda@gentoo/developer/amir) has joined #openid
- [10:44:09] * ianloic ( has joined #openid
- [10:44:09] * XRIBot (n=XRIBot@ has joined #openid
- [11:07:16] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 113 (No route to host))
- [11:07:27] * gaurav_ (n=aviiiiii@ has joined #openid
- [11:07:58] <gaurav_>
hello if any body work on moodlw module of openid?
- [11:08:11] <gaurav_>
- [11:12:59] * gaurav_ (n=aviiiiii@ Quit (Read error: 104 (Connection reset by peer))
- [11:23:20] * shigeta_ (n=shigeta@ Quit ("Leaving...")
- [11:30:16] * gaurav_ (n=aviiiiii@ has joined #openid
- [12:10:14] * gaurav_ (n=aviiiiii@ Quit (Read error: 104 (Connection reset by peer))
- [13:09:24] * Sociophobe- (i=Sociopho@ has joined #OpenID
- [13:16:38] * TimothyP (n=timothy@ has joined #openid
- [13:17:15] <TimothyP>
Hi, I'm trying to install the php libraries for OpenId on an ubuntu server. In the past I did it with pear, but I can't find the information on openidenabled anymore
- [13:22:12] <TimothyP>
the old site was better :p
- [13:26:38] * Sociophobe (i=Sociopho@ Quit (Read error: 110 (Connection timed out))
- [13:33:01] <tjohns>
TimothyP: Are you sure, because there was a discussion on dev about a week ago about trying to get the OpenID library into PEAR.
- [13:38:41] * shigeta ( has joined #openid
- [13:39:44] * fzlogik ( has joined #openid
- [13:40:33] <TimothyP>
yes I'm very sure, me and a person from Janrain spent a few hours debugging a previous installation and we used pear throughout
- [13:40:43] <TimothyP>
but that was months ago
- [13:41:10] <TimothyP>
the server worked fine for a few months but we had to switch to new servers last week :)
- [13:41:19] <TimothyP>
so need to reinstall openid
- [13:41:24] <fzlogik>
I'm currently in the process of writing a library to integrate OpenID with Wicket (a java web app framework), but I've stumbled upon something that concerns me a little: when an openid response is received, the nonce needs to be validated (to prevent against replay attacks, I guess). however, the openid4java library currently checks the local-system time to test the validity of this nonce.
- [13:41:39] <fzlogik>
is this correct behaviour, or should the library be querying the identity provider for its current timestamp instead?
- [13:42:25] * priidu (n=aa@ has joined #openid
- [13:43:26] <fzlogik>
if it is the correct behaviour, this seems to assume that every server is synchronized - is this mandatory in the spec? (I couldn't see anything relating to this... though I haven't searched too deeply). my machine was off by about 2 minutes, which caused nonce validation to fail... obviously in a production environment, where these guarantees can't be made (we have to account for -any- identity provider, after all)...
- [13:43:49] <fzlogik>
if the library should in fact check the identity provider's timestamp, I'd be happy to help out and commit a patch to openid4java.
- [13:48:39] <fzlogik>
sigh, and now my connection's going to drop.
- [13:49:13] * Sociophobe- (i=Sociopho@ has left #OpenID
- [13:49:42] * fzl0gik ( has joined #openid
- [13:55:29] <fzl0gik>
anyway, I'm pretty sure a decent solution would be to write a NonceVerifier that's able to look up a time-delta for identity providers. a simple mapping from String -> Long, where the String is the identity provider URL and the Long is calculated from the system's local time and the 'Date:' field in the HTTP response header.
- [13:55:52] <fzl0gik>
chances are that Date: field is optional, so if it's not present, the best the NonceVerifier can do is assume a zero time delta.
- [13:57:46] <tjohns>
fzl0gik: There's no requirement that the servers clocks are in sync, per se.
- [13:58:23] <tjohns>
At least not perfectly
- [13:58:57] <tjohns>
They're supposed to be reasonably within sync +/- some (undefined) time-delta
- [14:01:02] <fzl0gik>
openid4java seems to assume 60 seconds is a reasonable difference. hmm.
- [14:01:25] <fzl0gik>
well, I'll definitely have a look into how it might be possible to improve it by inspecting the returned 'Date:' field.
- [14:02:24] <tjohns>
Another idea (I'm just brainstorming here) is to compute a delta associated with each server when first associating
- [14:02:35] <tjohns>
So, if the first nonce is 6 hours off, it's probably safe to assume that all future nonces will be 6 hours off.
- [14:02:51] <tjohns>
That avoids having to deal with the Date: header
- [14:03:42] <fzl0gik>
oh, there's a nonce passed in the association phase? yes - that's a better solution then. :)
- [14:04:10] <tjohns>
I'm not sure, one sec, I'll check.
- [14:05:02] <tjohns>
Nope, looks like there isn't
- [14:05:08] <tjohns>
But even then, it doesn't make a difference
- [14:05:17] <tjohns>
The time is only necessary in order to prune the nonce database
- [14:05:37] <tjohns>
So, you could even wait until the first assertion arrives and still not be worried
- [14:05:46] * fzlogik ( Quit (Read error: 110 (Connection timed out))
- [14:09:47] * tjohns ( Quit ()
- [14:13:50] * stub ( has joined #openid
- [14:34:45] * TimothyP (n=timothy@ Quit ("Leaving")
- [14:45:38] * priidu (n=aa@ Quit (Read error: 110 (Connection timed out))
- [14:59:36] * potato ( has joined #openid
- [15:00:18] * potato is now known as quirim
- [15:13:06] * benj3one ( has joined #openid
- [15:14:33] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 110 (Connection timed out))
- [15:33:02] * stub (n=stub@canonical/launchpad/stub) has joined #openid
- [15:35:32] * ichigo ( has joined #openid
- [15:36:13] * stu2 ( has joined #openid
- [15:36:13] * stub (n=stub@canonical/launchpad/stub) Quit (Nick collision from services.)
- [15:36:28] * stu2 is now known as stub
- [15:39:44] * SteveA_ ( has joined #openid
- [15:43:46] * SteveA (n=steve@canonical/launchpad/SteveA) Quit (Read error: 110 (Connection timed out))
- [16:12:09] * priidu_ (n=aa@ has joined #openid
- [16:21:05] * Mitsurugi ( Quit (" · tecnologia lliure per a un món lliure")
- [16:37:25] * fzlgik ( has joined #openid
- [16:48:42] * fzlgik is now known as fzlogik
- [16:49:10] * fzlogik is now known as cgdavies
- [16:52:27] * fzl0gik ( Quit (Read error: 110 (Connection timed out))
- [16:53:28] * priidu_ (n=aa@ Quit (Read error: 113 (No route to host))
- [16:55:17] * priidu_ (n=aa@ has joined #openid
- [17:15:34] * cgdavies` ( has joined #openid
- [17:18:07] * SignpostMarv ( has joined #openid
- [17:25:38] * priidu_ (n=aa@ Quit (Read error: 113 (No route to host))
- [17:31:22] * cgdavies ( Quit (Read error: 110 (Connection timed out))
- [17:59:53] * VxJasonxV (n=jason@xmms2/troll/VxJasonxV) Quit (Read error: 113 (No route to host))
- [18:14:07] * shigeta ( Quit ("Leaving...")
- [18:28:15] <Tobsn>
- [18:28:33] <Makenshi>
Do i need to make an account just so I can delete it?
- [18:28:49] <Tobsn>
- [18:29:13] <Makenshi>
I'd rather not
- [18:35:49] * SignpostMarv ( Quit ("Leaving")
- [18:54:19] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 113 (No route to host))
- [19:02:33] * pvandewyngaerde ( has joined #openid
- [19:47:09] * tjohns ( has joined #openid
- [19:56:49] * cgdavies` ( Quit ("Leaving")
- [20:38:03] * Cody`macbook ( Quit ("Leaving")
- [20:38:26] <donomo>
Tobsn: thanks for the link. couldn't agree more
- [20:39:11] * pvandewyngaerde ( Quit (Remote closed the connection)
- [20:40:13] <Tobsn>
- [20:48:37] * idnar (i=mithrand@unaffiliated/idnar) has joined #openid
- [21:02:31] * Mitsurugi ( has joined #openID
- [21:15:36] * NASA ( has joined #openid
- [21:18:53] * VxJasonxV (n=jason@xmms2/troll/VxJasonxV) has joined #openid
- [21:35:50] * tjohns ( Quit ()
- [21:49:49] * Roebot ( has joined #openid
- [21:52:54] * pvandewyngaerde ( has joined #openid
- [21:57:26] * T0bsn (n=Tobsn@ has joined #openid
- [21:59:09] * pvandewyngaerde ( Quit (Remote closed the connection)
- [22:02:31] * T0bsn (n=Tobsn@ Quit ()
- [22:05:02] * NA5A ( has joined #openid
- [22:14:38] * Roebot ( Quit (Read error: 104 (Connection reset by peer))
- [22:15:17] * NASA ( Quit (Read error: 110 (Connection timed out))
- [22:26:40] * NA5A ( Quit ("Ate")
- [22:32:09] * terrell ( has joined #openid
- [22:49:29] * trel1023 ( Quit (Read error: 110 (Connection timed out))
- [22:56:58] * idnar (i=mithrand@unaffiliated/idnar) Quit (Nick collision from services.)
- [22:57:01] * idnar_ (i=mithrand@unaffiliated/idnar) has joined #openid
- [23:16:24] * idnar_ is now known as idnar
- [23:28:40] * Roebot ( has joined #openid
- [23:43:30] * MrTopf (n=cs@ Quit ()
- [23:45:21] * Cody`macbook ( has joined #openid
- [23:55:05] * shrapnel ( has joined #openid
These logs were automatically created by OpenIDlogbot on
using a modified version of the Java IRC LogBot.