IRC Log for #openid on 2008-02-25

Timestamps are in UTC.

  1. [00:17:08] * priidu_ ( Quit (Remote closed the connection)
  2. [00:17:31] * MrTopf ( Quit (Read error: 113 (No route to host))
  3. [00:30:50] * ViperMaul^ ( has joined #OpenID
  4. [00:32:00] * shigeta (n=shigeta@ has joined #openid
  5. [00:32:10] * ViperMaul ( Quit (Read error: 104 (Connection reset by peer))
  6. [00:32:30] * ViperMaul^ is now known as ViperMaul
  7. [00:40:35] * jcollie ( has joined #openid
  8. [00:52:43] * charlenopires (n=charleno@ has joined #openid
  9. [00:57:32] * ricky (n=ricky@fedora/ricky) Quit ("Reboot for a bit...")
  10. [01:03:54] * ricky (n=ricky@fedora/ricky) has joined #openid
  11. [01:06:07] * ricky (n=ricky@fedora/ricky) has left #openid
  12. [01:33:23] * SignpostMarv ( Quit ("Leaving")
  13. [02:20:00] * charlenopires (n=charleno@ Quit ("To Saindo")
  14. [04:29:34] * stub ( has joined #openid
  15. [05:16:18] * priidu_ ( has joined #openid
  16. [06:15:58] * shigeta (n=shigeta@ Quit (Read error: 110 (Connection timed out))
  17. [06:39:26] * shigeta (n=shigeta@ has joined #openid
  18. [08:06:07] * bortzmeyer ( has joined #openid
  19. [08:06:48] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 110 (Connection timed out))
  20. [08:09:08] * stub ( has joined #openid
  21. [08:27:52] * priidu_ ( Quit (Remote closed the connection)
  22. [09:51:12] * danieljohnlewis ( has joined #openid
  23. [09:59:41] * Makenshi ( has joined #openid
  24. [10:03:44] * shigeta (n=shigeta@ Quit ("Leaving...")
  25. [10:10:42] * stub (n=stub@canonical/launchpad/stub) Quit ("Leaving.")
  26. [11:20:02] * a9913 (n=a9913@unaffiliated/a9913) has joined #openid
  27. [11:59:38] * a9913 (n=a9913@unaffiliated/a9913) Quit ("Leaving")
  28. [12:31:50] * shigeta ( has joined #openid
  29. [12:37:38] * priidu ( has joined #openid
  30. [12:54:36] * priidu ( Quit (Connection timed out)
  31. [13:06:43] * jcollie ( Quit ("Ex-Chat")
  32. [13:13:23] * TedThibodeauJr ( Quit ()
  33. [13:20:37] * priidu_ ( has joined #openid
  34. [13:30:21] * MrTopf ( has joined #openid
  35. [13:33:38] * vahur ( has left #openid
  36. [13:44:11] * stub (n=stub@canonical/launchpad/stub) has joined #openid
  37. [13:45:24] * Prometheus ( has joined #openid
  38. [13:45:40] <Prometheus> Any suggestions for an openid provider, what do you guys prefer and why? :)
  39. [13:45:58] <Prometheus> It seems that I'm in need of a new openid provider since I seem to have lost the password for my mylid one :/
  40. [13:47:33] <Makenshi> Prometheus, did you try and contact your current provider to resolve it?
  41. [13:48:01] * idnar (i=mithrand@unaffiliated/idnar) Quit (Read error: 110 (Connection timed out))
  42. [13:48:06] <Makenshi> I am currently using Verisign Labs PIP as they support x.509 and cardspace, and so far it has been very reliable
  43. [13:48:30] <CGamesPlay> does Firefox support cardspace?
  44. [13:48:30] <Prometheus> I haven't actually tried contacting them yet about it, I figured that might be a bit too much of a hassle, really, but I suppose I could try that
  45. [13:49:02] <Makenshi> CGamesPlay, no, however there are extensions that implement it
  46. [13:49:07] <CGamesPlay> hmm
  47. [13:49:32] <Makenshi> Prometheus, I would be interested to know how you get on as I am trying to compile a list of providers, and support is one of the areas I am interested in
  48. [13:50:08] <Prometheus> Makenshi: sure, I can give it a spin
  49. [13:50:15] <Prometheus> although I'm not sure where I would mail netmesh
  50. [13:50:19] <Prometheus> I suppose info@netmesh
  51. [13:50:24] * priidu_ ( Quit (Remote closed the connection)
  52. [13:50:38] * idnar (i=mithrand@unaffiliated/idnar) has joined #openid
  53. [13:51:27] <Makenshi> Prometheus, thanks. I am particularly interested in how easy it is to get support, and the quality of the response
  54. [13:51:41] <Prometheus> alright
  55. [13:52:09] <Prometheus> of course, the question is how will I prove my authenticity ;)
  56. [13:52:24] <Makenshi> I am considering setting up an openid provider using one-time sms for authentication, I just need to find a free (possibly ad-supported) sms service
  57. [13:53:01] <Makenshi> Prometheus, hopefully you have registered your email address with your account
  58. [13:53:15] <Prometheus> I have
  59. [13:53:28] <Prometheus> but the support address requires authentication
  60. [13:53:40] <Prometheus> so I guess I'll just send to their general info
  61. [13:53:56] <Makenshi> That is rather silly :) Is there no "lost password" option anywhere?
  62. [13:54:33] <Prometheus> nope
  63. [13:54:36] <Prometheus> not that I can find one
  64. [13:55:07] <Prometheus> which is kind of why I was thinking about getting a new provider :P
  65. [13:55:41] <Prometheus> I tend to change my passwords quite often, and being cryptic as they are, I also tend to forget them every now and then
  66. [13:55:50] <Prometheus> thus forgotten password that would send it to my mail would be nice
  67. [13:57:41] <Makenshi> Personally I prefer using something other than a password for authentication, such as a certificate or infocard
  68. [13:58:06] <Makenshi> This is why openid is so handy.. I can use whatever method I like for authenticating myself with my provider
  69. [13:59:14] <Prometheus> right, I would too
  70. [13:59:31] <Prometheus> but one password for every site isn't such a bad option either :)
  71. [14:00:09] <Prometheus> anyhow, I just sent them a mail, we'll see if they care :)
  72. [14:00:17] <Prometheus> if not, I'll just change provider to something else, not a biggie really
  73. [14:00:59] <Makenshi> It is a lot easier to get someone's password than it is to break a system like rsa or a smart card
  74. [14:01:23] <Prometheus> by far
  75. [14:14:52] * jcollie (n=jcollie@ has joined #openid
  76. [14:15:11] * danieljohnlewis ( Quit (Read error: 104 (Connection reset by peer))
  77. [14:15:41] * danieljohnlewis ( has joined #openid
  78. [14:15:51] * TedThibodeauJr ( has joined #openid
  79. [14:42:52] * shigeta ( Quit ()
  80. [15:02:30] <PibbRelay> <samsm> If you are using delegation, it is pretty easy ... get accounts everywhere, keep the one you like.
  81. [15:03:28] <PibbRelay> <samsm> Not that the debate isn't worthwhile, I just like to bring up delegation whenever possible. :)
  82. [15:03:57] <Makenshi> Of course, I use delegation for mine so I can easily change if I want to
  83. [15:04:28] <PibbRelay> <samsm> Excellent. :)
  84. [15:07:35] <Prometheus> using delegation as well
  85. [15:07:53] <Prometheus> it's just that I hate losing passwords :(
  86. [15:08:01] <Prometheus> and having to change provider because of something like that sucks
  87. [15:08:15] <Prometheus> but if the password isn't resettable or changeable by any easy means, oh well
  88. [15:14:56] * ViperMaul ( Quit (Read error: 110 (Connection timed out))
  89. [15:24:16] <Prometheus> Makenshi: verisign works as a server/delegate, right?
  90. [15:35:47] <Makenshi> Prometheus, yes
  91. [15:36:01] <Prometheus> cool, I guess I'll give it a spin :)
  92. [15:37:44] * a9913 (n=a9913@unaffiliated/a9913) has joined #openid
  93. [15:42:08] * MrTopf ( Quit ()
  94. [15:44:47] <Prometheus> does verisign have the openid.server url somewhere posted?
  95. [15:44:59] <Prometheus> I couldn't find it for the life of me, luckily simon willison had it posted
  96. [15:46:21] * Prometheus ( Quit ()
  97. [15:50:50] * stub (n=stub@canonical/launchpad/stub) Quit (Read error: 110 (Connection timed out))
  98. [15:52:57] * jrbot ( Quit (Read error: 110 (Connection timed out))
  99. [15:52:57] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) Quit (Read error: 110 (Connection timed out))
  100. [16:08:19] * priidu_ ( has joined #openid
  101. [16:15:37] * MrTopf ( has joined #openid
  102. [16:25:32] * bortzmeyer ( has left #openid
  103. [16:31:58] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) has joined #openid
  104. [16:33:20] * jrbot ( has joined #openid
  105. [16:44:23] * a9913 (n=a9913@unaffiliated/a9913) Quit (Read error: 113 (No route to host))
  106. [16:46:38] * ViperMaul ( has joined #OpenID
  107. [16:53:51] <donomo> its a function of the RP to interpret server/delegate.
  108. [16:54:16] <donomo> im not sure the Identity Prodiver is even aware of the original url.
  109. [16:54:55] <donomo> Provider, not expert scuba diver :)
  110. [16:59:13] * Navarr ( Quit ("Yeah.. I'll see ya around...")
  111. [17:01:22] * charlenopires (n=charleno@ has joined #openid
  112. [17:05:00] * forsaken ( Quit (Success)
  113. [17:09:30] * danieljohnlewis ( Quit ()
  114. [17:12:04] * charlenopires (n=charleno@ Quit ("To Saindo")
  115. [17:21:15] * Prometheus ( has joined #openid
  116. [18:13:30] * ViperMaul ( Quit (Read error: 110 (Connection timed out))
  117. [18:22:09] * ViperMaul ( has joined #OpenID
  118. [18:43:06] * charlenopires (n=charleno@ has joined #openid
  119. [19:04:56] * pvandewyngaerde ( has joined #openid
  120. [19:26:24] * priidu_ ( Quit (Remote closed the connection)
  121. [19:34:44] * jcollie (n=jcollie@ Quit ("Ex-Chat")
  122. [20:21:17] * coderpath ( has joined #openid
  123. [20:28:26] <coderpath> I'm looking into the possibility of setting up an openid server for my work. We're using Windows Active Directory to manage names & passwords. Is there an OpenID server out there for Windows that's open source?
  124. [20:29:39] <_keturn> you can find a number of protocol implementations that run on windows, but no open source full server solution that integrates with Active Directory
  125. [20:30:59] <johill> you can probably have an easier path by enabling ldap and authenticating against that. or use e.g. dovecot's auth server which can also talk ntlm
  126. [20:31:27] * priidu ( has joined #openid
  127. [20:32:21] * forsaken (n=eric@ has joined #openid
  128. [20:34:19] <coderpath> johill: not sure what you're saying. Setup an LDAP server to hook into AD then have an OpenID server use the LDAP server to authenticate?
  129. [20:36:42] <johill> AD can be LDAP, yeah
  130. [20:36:56] <coderpath> _keturn: what about a decent unix-based OpenID server?
  131. [20:37:08] <coderpath> johill: ah. gotcha. cool :)
  132. [20:38:35] <johill> so if you use dovecot which talks ntlm, ldap and more you can actually just query the passwords with a simple line-based interface to a socket
  133. [20:38:44] <johill> and use whatever you want to implement the openid server
  134. [20:38:55] <johill> I don't think there are "OpenID servers" per se because it's always tied to the httpd
  135. [20:39:09] * jcollie ( has joined #openid
  136. [20:43:43] * alinka (n=anna_dov@ has joined #openid
  137. [20:43:47] * alinka (n=anna_dov@ has left #openid
  138. [20:47:33] <Makenshi> coderpath, still there?
  139. [20:47:44] <Makenshi> Have a look at
  140. [20:47:45] <coderpath> Makenshi: yep :)
  141. [20:48:40] <Makenshi> Just before I left my last place, I implemented OpenID with a bit of a hack..
  142. [20:49:00] <coderpath> Makenshi: ah...that looks like what I'm looking for :)
  143. [20:49:40] <Makenshi> I set up a jabber server with Ignite Openfire using AD, and then set up a simple page that delegated to the iDP at
  144. [20:50:14] <coderpath> I think I'm getting my terminology confused. I'm wanting to become an OpenID provider for my users who are already using AD to login to their exchange email.
  145. [20:50:48] <Makenshi> That is what the aforementioned software is for
  146. [20:51:01] <Makenshi> I am not sure if it supports OpenID 2, though
  147. [20:51:18] <coderpath> Makenshi: excellent. thx :) That'll keep me busy for a bit.
  148. [20:51:55] <coderpath> I suppose people just roll their own using a web framework.
  149. [20:53:03] <Makenshi> There are commercial products too, like Atlassian Crowd
  150. [20:53:21] <johill> (wiki) will have an openid provider too in the next version
  151. [20:53:24] <johill> it also supports ldap auth
  152. [20:53:35] <coderpath> Makenshi: yes I've seen that, but it's not cheap.
  153. [20:53:38] <johill> (in addition to an openid RP anyway)
  154. [20:54:23] <coderpath> johill: cool. I'll have a look at that too
  155. [20:54:38] <Makenshi> Crowd is open source too
  156. [20:57:28] <coderpath> Makenshi: Crowd is open source? I thought it was a commercial product?
  157. [20:57:55] <Makenshi> Yes.. Commercial software can be open source too.. it is a very common misconception to think otherwise
  158. [20:58:07] <Makenshi> OSC Radiator is another example
  159. [20:59:11] <coderpath> Makenshi: ah...well...guess you learn something new everyday ;)
  160. [21:11:39] * priidu ( Quit (Remote closed the connection)
  161. [21:21:35] * forsaken (n=eric@ Quit (Connection reset by peer)
  162. [21:49:05] * CGamesPlay (n=cgames@allegro/user/CGamesPlay) Quit (Read error: 110 (Connection timed out))
  163. [22:01:44] * pvandewyngaerde ( Quit (Remote closed the connection)
  164. [22:03:41] * charlenopires (n=charleno@ Quit (Read error: 110 (Connection timed out))
  165. [22:07:57] * charlenopires (n=charleno@ has joined #openid
  166. [22:08:41] * TedThibodeauJr ( Quit ()
  167. [22:32:22] * ViperMaul ( Quit (Remote closed the connection)
  168. [22:33:28] * ViperMaul ( has joined #OpenID
  169. [22:35:31] * ViperMaul^ ( has joined #OpenID
  170. [22:36:05] * ViperMaul ( Quit (Read error: 104 (Connection reset by peer))
  171. [22:42:54] * ViperMaul ( has joined #OpenID
  172. [22:43:42] * ViperMaul^ ( Quit (Read error: 104 (Connection reset by peer))
  173. [22:54:05] * ViperMaul ( Quit (Remote closed the connection)
  174. [22:54:22] * ViperMaul ( has joined #OpenID
  175. [22:58:53] * coderpath ( Quit (Remote closed the connection)
  176. [23:12:02] * CGamesPlay (n=cgames@allegro/user/CGamesPlay) has joined #openid
  177. [23:21:16] * pkulak ( has joined #openid
  178. [23:22:42] <pkulak> Does anyone here have some time to talk with me about the ruby-openid OpenID 2.0 implementation?
  179. [23:29:13] <_keturn> pkulak: sure, what's up?
  180. [23:31:04] <pkulak> Thanks! So, I'm using ruby-openid 2.0.4 and from what I've read, and going through the source, it's supposed to support Directed Identity. Yet, when I use as the url I get back "No service endpoints found." I'm just wondering if I'm missing something.
  181. [23:32:05] <_keturn> huh. it works at
  182. [23:32:42] <pkulak> Darn, so it's not something obvious then.
  183. [23:33:03] <_keturn> if you feed it your specific identifier, does that work?
  184. [23:33:32] <pkulak> It does for Haven't tried Yahoo, hang on...
  185. [23:36:57] <pkulak> You're right. Seems to be with anything from Yahoo.
  186. [23:37:16] <pkulak> Could it be because I'm coming from localhost?
  187. [23:37:55] <_keturn> well, it's true that yahoo doesn't like a localhost return_to, but if the message is "no service endpoints found", then you're not even getting that far
  188. [23:38:14] <pkulak> Let me make sure that's still the message.
  189. [23:39:17] <pkulak> Yeah, that's still it.
  190. [23:39:47] <_keturn> it could be an https thing. does the https form of your myopenid identifer work? (also, are there logs?)
  191. [23:41:48] <pkulak> Https works for myopenid, and I don't see anything in my logs, but it doesn't look like ruby-openid really logs anything
  192. [23:42:21] <pkulak> You don't happen to know where that error message is generated, do you?
  193. [23:42:24] <pkulak> I can't find it in the source.
  194. [23:44:49] <_keturn> you could also try running 'examples/discover' , that might narrow things down a bit
  195. [23:48:49] * TedThibodeauJr ( has joined #openid
  196. [23:49:09] <pkulak> How exactly do you run that? From the terminal or the console...
  197. [23:54:19] * MrTopf ( Quit ()
  198. [23:56:39] * Prometheus ( Quit ()
  199. [23:59:40] <_keturn> the terminal

These logs were automatically created by OpenIDlogbot on using a modified version of the Java IRC LogBot.