<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Certificate Odyssey</title>
	<atom:link href="http://self-issued.info/?feed=rss2&#038;p=70" rel="self" type="application/rss+xml" />
	<link>http://self-issued.info/?p=70</link>
	<description>Musings on Digital Identity</description>
	<lastBuildDate>Tue, 13 Jul 2010 21:17:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Cardspace Community Bloggers</title>
		<link>http://self-issued.info/?p=70&#038;cpage=1#comment-55902</link>
		<dc:creator>Cardspace Community Bloggers</dc:creator>
		<pubDate>Mon, 19 May 2008 21:40:42 +0000</pubDate>
		<guid isPermaLink="false">http://self-issued.info/?p=70#comment-55902</guid>
		<description>&lt;strong&gt;Worrying rumour...&lt;/strong&gt;

Word from Redmond is that, inspired by this salesmanship fiasco, in order to demonstrate their corporate...</description>
		<content:encoded><![CDATA[<p><strong>Worrying rumour&#8230;</strong></p>
<p>Word from Redmond is that, inspired by this salesmanship fiasco, in order to demonstrate their corporate&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vittorio Bertocci</title>
		<link>http://self-issued.info/?p=70&#038;cpage=1#comment-51822</link>
		<dc:creator>Vittorio Bertocci</dc:creator>
		<pubDate>Wed, 07 May 2008 00:46:32 +0000</pubDate>
		<guid isPermaLink="false">http://self-issued.info/?p=70#comment-51822</guid>
		<description>Hi Andy,
I blogged about this exact point back in September: you can read the post at http://blogs.msdn.com/vbertocci/archive/2007/09/25/windows-cardspace-will-work-without-https-too.aspx
The option of using CardSpace without SSL is very handy for RPs which do not have strong requirements, and the subject authentication is still performed via asymmetric cryptography (checking the signature of the incoming token; see the post above) hence it maintains the good properties that the approach entails.
If you want to chat about this in more depth feel free to drop me a line!

Cheers,
V.</description>
		<content:encoded><![CDATA[<p>Hi Andy,<br />
I blogged about this exact point back in September: you can read the post at <a href="http://blogs.msdn.com/vbertocci/archive/2007/09/25/windows-cardspace-will-work-without-https-too.aspx" rel="nofollow">http://blogs.msdn.com/vbertocci/archive/2007/09/25/windows-cardspace-will-work-without-https-too.aspx</a><br />
The option of using CardSpace without SSL is very handy for RPs which do not have strong requirements, and the subject authentication is still performed via asymmetric cryptography (checking the signature of the incoming token; see the post above) hence it maintains the good properties that the approach entails.<br />
If you want to chat about this in more depth feel free to drop me a line!</p>
<p>Cheers,<br />
V.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Dale</title>
		<link>http://self-issued.info/?p=70&#038;cpage=1#comment-51332</link>
		<dc:creator>Andy Dale</dc:creator>
		<pubDate>Mon, 05 May 2008 14:25:08 +0000</pubDate>
		<guid isPermaLink="false">http://self-issued.info/?p=70#comment-51332</guid>
		<description>While I understand the convenience of the non-ssl implementation... How much does it compromise the overall security pattern?


Presumably there was a reason that the SSL only decision was made to start with.</description>
		<content:encoded><![CDATA[<p>While I understand the convenience of the non-ssl implementation&#8230; How much does it compromise the overall security pattern?</p>
<p>Presumably there was a reason that the SSL only decision was made to start with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Becoming an RP with the Pamela Project (pt. 2) &#124; drstarcat.com</title>
		<link>http://self-issued.info/?p=70&#038;cpage=1#comment-51188</link>
		<dc:creator>Becoming an RP with the Pamela Project (pt. 2) &#124; drstarcat.com</dc:creator>
		<pubDate>Mon, 05 May 2008 01:42:03 +0000</pubDate>
		<guid isPermaLink="false">http://self-issued.info/?p=70#comment-51188</guid>
		<description>[...] as installing an SSL certificate is NOT something to be done by mere mortals (see Mike&#8217;s post here&#8211;and HE&#8217;S not even [...]</description>
		<content:encoded><![CDATA[<p>[...] as installing an SSL certificate is NOT something to be done by mere mortals (see Mike&#8217;s post here&#8211;and HE&#8217;S not even [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
