> è±èªãäžåŸæã§ä»æ§ãããŸãæŸããªãã®ã§ããã"#" ã«ç¶ãã URL ã¯ãã£ã¡ã§ïŒèªå¶ã®éšåïŒã§åé€ããŠããŸã£ãŠè¯ãã®ãïŒãªã©ãšãèããŠããŸ
> ã
ç§ã¯ JanRain ã® PHP ã«è§Šããããšã¯ãªãã®ã§ããã
ãã®è©±ã¯OpenID 2.0 ã«ãªã£ãŠåæã§è©±ãããã£ãŠããŸããã
7.2 normalization ã® 3 ãåèã«ãªããŸãã
<snip>
ãããªããã°ãå
¥åã¯HTTP URLãšããŠæ±ãããã¹ãã§ã;
ããããã"http"ã"https"ã¹ããŒã ãå«ãŸãªããªãããã®Identifierã¯æåå"http://"ãå
é ã«ã€ããããªããã°ãªããŸããããããã®URLãfragmentããŒããå«ããªããããã¯fragmentãåºåãæå"#"ãšåãããŠåãé€ãããªããã°ãªããŸãããæŽãªãæ
å ±ã®çºã«Section
11.5.2 (HTTP and HTTPS URL Identifiers)ãèªãã§ãã ããã
</snip>
http://lab.koshigoe.jp/en2ja/openid-authentication-2_0.html#normalization
2008/4/2 LDU05653 <LDU0...@gmail.com>:
--
Takatsugu Shigeta
ãã®normalization ã¯ãŠãŒã¶ã Identity URLãå
¥åã㊠OpenID
ã®èªèšŒã»ãã·ã§ã³ãéå§ãããšãã«è¡ããã®ã§ãèªèšŒãããã£ãŠãã©ã£ãŠãã identity_url ã«å¯ŸããŠå®è¡ãããã®ã§ã¯ãªãã§ããã
--
Tatsuhiko Miyagawa
ãäºåã«ç»é²ããç©ããäœãæå³ããŠããã®ãããããªãã®ã§ãããUser-Supplied Identifier ã®ããšã ãšããã°ããŠãŒã¶ã
yahoo.co.jp ã®ããã« Directed Identity ãå
¥åããå Žåããããã Claimed Identity
ãšã¯ç°ãªãå€ã«ãªãã®ãåœç¶ãªã®ã§ã¯ã
--
Tatsuhiko Miyagawa
Perl ã§ã¯ç¡ããPython ã§ãã
> JanRain ã®ä»ã® èšèªã® Ruby ã Perl ã®ãã¢ãå®è¡ãããš ãã©ã°ã¡ã³ãã¯ä»ããŠããªãããã§ã
åèïŒ
http://wiki.openid.net/OpenIDChanges#Explicitly_allow_fragments_on_OpenID_identifiers
The OpenID provider can send a URL with a fragment as the claimed
identifier. The full URL (with the fragment) is the user's identifier,
so relying parties store the URL with the fragment.
ãšããã¯ã¿ãªãããã£ããã£ãŠãããšããããã©ã°ã¡ã³ãä»ãã§æ ŒçŽããŠãããšã
ã§ããã
The URL without the fragment should be used when the URL has to be displayed.
衚瀺ãããšãã¯ãšã£ã¡ããã°ããããããšã
åæŸ
ãŸããèšã£ãŠããŸãã°ãã®éãã ãšæããŸã ^^;
>
> ãšããã¯ã¿ãªãããã£ããã£ãŠãããšããããã©ã°ã¡ã³ãä»ãã§æ ŒçŽããŠãããšã
>
> ã§ããã
>
> The URL without the fragment should be used when the URL has to be displayed.
>
> 衚瀺ãããšãã¯ãšã£ã¡ããã°ããããããšã
>
å ã«åŽæ ãããèšããã
ãã®ãå¥ã®ãŠãŒã¶ã«å²ãåœãŠããããªå Žåãã¯ãç»é²ãããããŒã¿ãšäžèŽãããããšãåºæ¥ãŸããã®ã§ RP ã§ãªãžã§ã¯ãåŠçãè¡ããŸããããšã³ããŠãŒã¶
> ãã©ã°ã¡ã³ããåãæšãŠããã®ã¯ããããŸã§ãŠãŒã¶æäŸèå¥åã§ãã£ãŠãClaimed Identifier ãšããŠåãæ±ãããšã¯ã§ããŸããã
>
> ãã®ä»æ§ã¯ãOPãããURLãå¥ã®ãŠãŒã¶ã«å²ãåœãŠããããªå Žå(URL RecyclingïŒã«å¯Ÿå¿ããããã«2.0ã§è¿œå ãããã»ãã¥ãªãã£æ©èœã§ãã
ã«ã¯äºç±ãå€ããŸããããïŒ
ããèšãäºè±¡ãèµ·ããªãããã« OP ãæ ä¿ããŠããèš³ã§ã¯ç¡ããšèšãããšã§ãããïŒ
ãå¥ã®ãŠãŒã¶ã«å²ãåœãŠããããªå Žåããæ³å®ãããŠãããšèšãããšã¯ã容æã«æ³åã§ããŸã
ããšãã°éŽæšäžéãããææã䞻匵ãã http://www.example.com/suzuki/ ãææŸããéŽæšæ¬¡éãããåã OP ã§åã
ããã«ID ãååŸããå Žåããã©ã°ã¡ã³ããªã©ã®æ å ±ããªããšäžæã§ããããšãæ ä¿ã§ããŸãã
# URL Recycling ã¯å€åããèšãããšã§ãããïŒ
## éŽæšäžéãããšé޿𿬡éãããåããµãŒãã¹ãå©çšããå Žåã©ããªããè峿ããŸã ^^
Claimed Identifier ã¯ãšã³ããŠãŒã¶ãææããŠãããšäž»åŒµããã¢ãã¬ã¹ã§ãããã¯åŒãåãã®éãããšã³ããŠãŒã¶ã®èªç±ã§ãããšæãã
ãŸã
OP ã¯ããã® User-Supplied Identifie ãéŽæšäžéãããéŽæšæ¬¡éããã®ã©ã¡ãã®ç©ã§ããããšã RP ã«ç¥ãããã°ãããš
èšãããšã ãšæããŸã(ãã£ãŠãŸããïŒ)
# ãã®éã«äœ¿ãããã®ãããã©ã°ã¡ã³ããªã©ã®èå¥åãªãã ãšæããŸã..
ã§ãããUser-Supplied Identifier 㯠ãã®å Žåããã©ã°ã¡ã³ããªãã§æããšæ³åããããšãåºæ¥ãŸãããïŒ
Yahoo! JAPAN ãªã©ã¯ãUser-Supplied Identifier ã«ãhttps://me.yahoo.co.jp/a/
XXXXX39TV.B8ViMk8P4qVtiTEciC ããšã䜿ããšèšã£ãŠããæ§ã§ãïŒãããã颚ã«èŠããŸãïŒ
# ãããèªåã®èãæ¹ã®ãããããšããã..
## èªåã® Claimed Identifier ãš User-Supplied Identifier ã®èšãåããæ£ãããªãæ°ããã..
ã§ãåæŸããã®ããã£ãããããã«ã衚瀺ãããšãã¯ãšã£ã¡ããã°ããããããšãããšèããŸãã
èªå¶ã® RP ã§ã¯ãåŽæããã®ãã£ãããããã«ã䞻匵èå¥å(Claimed Identifier)ã調ã¹ããããããŒã¿ããŒã¹ã«ç»é²ãããæ§ã«ã
ãããšèããŸã
éŽæšäžéããã®ç¥ããªããã¡ã« Claimed Identifier ãéŽæšæ¬¡éããã®ç©ãšãªã£ãå Žåãå¿é ã«ãªã£ãŠããŸããã..
ãŸãã Yahoo! JAPAN ã®å Žåãäœãã®ããã·ã¥ã«ãªã£ãŠãããããªã®ã§éè€ããããšã¯èãã«ããã®ã§ãããã..
--
JanRain ã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯ããããã getDisplayIdentifier() 颿°ã§ 衚瀺çšã® Identifer ãæäŸãã
ããšãåºæ¥ãããã§ã
ãããããã® getDisplayIdentifier() ã§åž°ã Identifier ããã©ã°ã¡ã³ããä»ããŠããŸã
æåã®çåç¹ã¯ããã§ãRuby ãªã©ã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯è¡šç€ºãããªããã©ã°ã¡ã³ããèªå¶ã® RP ã§çް工ããŠãè¯ãã®ãïŒã§ããããã衚瀺ãããšã
ã¯ãšã£ã¡ããã°ããããããšããã®æ¹åã§äœæ¥ããããšæããŸã
Miyagawa ããã«æåã«ããããŠé ãããšããããšã³ããŠãŒã¶ã User-Supplied Identifier ãèªå¶ã® RP ã«ç»é²ã
ãå ŽåãClaimed Identifier ãšéãäºãåæã«ãOP ã«ç¢ºèªãã«è¡ãããããªãã® Identifier 㯠 Claimed
Identifier(ããã§èšããã©ã°ã¡ã³ãä»ã)ãšç»é²ãããŸãããªã©ãšããã°è¯ãããªïŒ
ãã®"ç»é²äœæ¥"ãçµãã£ããšã¯ããã°ã€ã³èªèšŒã®ã¿ã§ãã®ã§ãUser-Supplied Identifier ããClaimed
IdentifierãOP Identifier (ã§ãã£ãŠãŸããïŒ)ã® yahoo.co.jp ã§ãå©çšã§ããããã«ããŸã
ãããªæãã§ççŸã®ãªãéçšãåºæ¥ãã®ããªã..
æ£æã§ãããããããç¹ãªã©ææããŠé ãããšå©ãããŸã
ä»ã¯ãURL Recycling ããã Claimed Identifier ã User-Supplied Identifie ãåäžãªäž»
匵ããããå Žåãã©ãåŠçããã°ãããïŒãæ°ã«ãªããŸã
IdP ãã©ãæ±ããïŒæ¬¡ç¬¬ãªã®ããª..
# éŽæšäžéãããææã䞻匵ãã User-Supplied Identifie ãªã®ã§æ¬¡éããã¯ã©ãããã..
## ãAuthentication 2.0 以éã®ã¿å¯Ÿå¿ããšãã¹ããªã®ã..
ãã®èŸºã仿§ãèªã¿åããªãäžç²æãªãã§ããã
openid-ja ã®çæ§ãããå°ããä»ãåãããŠé ãããšå©ãããŸã
ãã©ã°ã¡ã³ããã€ããŠããããåºå¥ã§ããŸããã
> ãŸãããŠãŒã¶ã«èŠãããèŠããªãã®è©±ã§ããããŸãã
> RP ãå©çšããŠãã ID ãšãšã³ããŠãŒã¶ãèªåã§æã£ãŠãã ID ãšå·®ç°ããã£ãŠã¯å°ãã®ã§ã¯ïŒãšããããšã§ã
Yahoo!ã®å Žåã¯ãŠãŒã¶ãå ¥åããã®ã¯yahoo.co.jpã§ãããå·®ç°ãããã®ãããããåœç¶ã§ããã
--
Tatsuhiko Miyagawa
ããã«ã¡ã¯ã
èããããããããŒãã ã£ãã®ã§ãã¡ãã£ãšæè«ã§ããããé·æã§æ£æã§ããæžããŠã¿ãŸãã
ãŸããyahoo.co.jpã®åäœãèŠãŸãã
Yahooã®OpenID(op identifierãããªãã§ã)ãå
¥åãããšãRPããã¯openid.claimed_id,
openid.identityãšãã«åäžã®ãã©ã°ã¡ã³ãç¡ãã®å€ã§éä¿¡ãããŸãããããOPããã¯openid.claimed_idã«ãã©ã°ã¡ã³ããä»äžãããŠåž°ã£ãŠããŸããã©ã€ãã©ãªãèªãã§ã¯ããŸãããããããããã®å€ãè¿ããŠããŸãã
ããã§ãåæŸããã®ã¡ãŒã«ã«ããåç §å ãã¿ããšãOPã¯OpenID Identity URLã«ãã©ã°ã¡ã³ããè¶³ããŠãè¯ãããšèšã£ãŠããã
ããããããUser-supplied
IdentifierãšããŠå©çšãããšãRPã¯ãã©ã°ã¡ã³ããé€å»ããŠDiscoveryããªããã°ãªããªããããã«ããããããyahoo.co.jpã®ãããªOPã¯Auth
responseã®openid.claimed_idã«ãã©ã°ã¡ã³ããä»äžããŠããã
ãšããããšã§ãç§ã¯äžèšã®ããã«èããŠããŸã
â 倧åæ
ãRPã¯å
¥åãããUser-supplied IdentifierããæŽŸçããIdentifierã®äžã§ãã£ãšãäžææ§ãé«ããã®ãèšé²ãã¹ãã§ãããã
ãOPãçŽæ¥è¿ããŠããå€ãèšé²ãã¹ãã§ãããã
ãšèããŠããŸãã
â User-supplied IdentifierãXRIã ã£ãã
èå¥åãXRIã®å ŽåãèãããšãUser-supplied
Identifierã¯ãããŸã§ãã®æç¹ã§ãŠãŒã¶ãææããŠãããšæã£ãŠããIdentifierã§ããã°è¯ããŠãReassignableã§ãPersistentã§ãè¯ãããã§ããURLã®å Žåã¯User-supplied
Identifierã¯æ£èŠåãããŠãã©ã°ã¡ã³ããé€å»ãããŠãšãããŸãããXRIã®å Žåã¯Canonical
IDã§ããšãããŸããCanonical
IDã¯Persistentãªãã®ã ãšãããŸããXRIã«ãããPersistentãšã¯ãæéãšç©ºéãã®2軞ã«ãããŠGloba
Uniqueãã€not-reassignableãšããããšã§ãã®ã§ãRPã¯Auth
requestäžã®openid.claimed_id(Canonical ID)ããã®ãŸãŸèŠããŠããã°ãããšãUser-supplied
IdentifierãReassginableãªãã®ã§ææè
ãç§»ã£ãŠãããšããŠããæ¬è³ªçãªãŠãŒã¶ãŒã®éããèæ
®ããããšãã§ããŸãã
â User-supplied IdentifierãURLã ã£ãã
äžæ¹ãUser-supplied IdentifierãURLã ã£ãå Žåã¯ã»ã»ã»æ£èŠåãããŠãã©ã°ã¡ã³ãé€å»ãããŠClaimed
Identifierã«ãªããŸãããããã£ãŠçµå±ãLDU05653ããã®ä»°ãããã«IDçºè¡å
ã®ããªã·ãŒã«ãã£ãŠReassignableã§ããããhttp://example.com/suzukiãææããéŽæšãããè§£çŽããŠID
recycleããŠå¥ã®éŽæšããã«äœ¿ãããŠããããããªå Žåã§ããã€ãŸããããã§OPãäžæçºè¡ããªã·ãŒãåã£ãŠãããªãã°ãclaimed
identifierãèšé²ããŠããŸãã°è¯ããšæããŸããauth responseã®openid.claimed_idã§ããã
ããããªããæ¬è³ªçã«ã¯ãã¡ã€ã³åèªäœãReassinableãªã®ã§ãURLã®Claimed
Identifierãã®ãã®ã¯æ¬è³ªçã«Reassinableã§ããã»ã»ã»ïŒãã ãæç³»åçã«ã¯ææããæ¬è³ªãªãŠãŒã¶ã¯äžæã§ããïŒ
â OPãçºè¡ããOpenID URLãReassignableã ã£ãã
æ¬è³ªçãªURL Claimed Identifierã®Reassinableæ§ã¯ãããããšããŠã次ã«OPãOpenID URL(user
id)ã®åå©çšçºè¡ããªã·ãŒãæ¡ã£ãŠããå ŽåãèããŸãã
RPã¯User-supplied Identifierãæ£èŠåããŠåŸãããClaimned
Identifierããã®ãŸãŸèšæ¶ãããšããã§ãæç³»åçã«å¥ã®ã¿ã€ãã³ã°ã§ã®æææš©ãæã€ãŠãŒã¶ãšãéå»ã«æææš©ãæã£ãŠãããŠãŒã¶ãšã®åºå¥ã¯ã€ããŸãããããããªãããä»åã®yahoo.co.jpã®å®è£
ã§ã¯ãAuth
responseã®openid.claimed_idã®å€ã«ã¯ç®¡ççªå·ãšããšãããã©ã°ã¡ã³ããä»äžãããŠããããã®ä»å æ
å ±ã«ããäžææ§ãæ
ä¿ããŠãããšäºæ³ãããªãã°ãAuth
responseã®openid.claimed_idããã©ã°ã¡ã³ããä»ãããŸãŸèšé²ããŠããã¹ããšãããåŽæããã®ä»°ãæ¹æ³ã«ãã¹ãã ãšæããŸãã
ããæç¹ã§ã®ææè
ã®OpenID URLãïŒOpenID URL +
ææè
åºæçªå·ïŒãšããæ¬è³ªçãªãŠãŒã¶ãžãããã³ã°ãã§ããã®ã¯OPã ãã§ããããOPã®è¿ããå€ãèšé²ãã¹ãã§ããã
ãã®æ¬¡ã¯OP-local Identifierã§ããã»ã»ã»ãããŸã§èãããšé ãå£ããããªã®ã§ãä»åã¯ãããŸãããã
â çµè«ïŒ
0. OPã¯Auth responseã®openid.claimed_idã§global uniqueãªãã®ãè¿ãã¹ãã§ããã
1. OPã¯å¯èœãªéããªãµã€ã¯ã«äžèœãªOpenID URLãæäŸãã¹ãã§ããããããããããã©ã°ã¡ã³ãã«ãã£ãŠè¡šçŸãããŠãŒã¶ãžæäŸããããšã¯ç¡æå³ã§ããã
2. å°ãªããšãOPã¯Auth responseäžã®openid.claimed_idã§ã¯æéãšç©ºéçã«äžæãªOpenID
URLãè¿ãã¹ãã§ããããã®éã®OpenID URLã«ã¯ãã©ã°ã¡ã³ããå©çšããŠãè¯ãã
3. RPã¯äžèšã®0ã«å ããŠ1ã2ãæºãããOPããã®Auth responseäžã®openid.claimed_idãèšé²ãã¹ãã§ããã
4. ãã¡ã€ã³åã®Reassignableæ§ãopenid.claimed_idã®global uniqueæ§ã«äžãã圱é¿ã¯ãããããã«è«Šããã
ãªããšããããåæOPã®çºè¡ããOpenID URLãªããŠäœ¿ãæ°ã«ããªããŸããã
ã ã£ãŠãèªåãæã£ãŠããOpenID
URLãåå²ãåœãŠãããŠãããŸããŸèªåãå©çšããŠããRPãµã€ãã®ã¢ã«ãŠã³ãã«ãã©ããã®èª°ãã«ãã°ã€ã³ããã¡ããå¯èœæ§ããããã§ãããã
ãã®ãããã®ãã¹ããã©ã¯ãã£ã¹ãèããäžã§ããäžå®ã®æéãæã¡åºããããªå¿
èŠãããã®ãããããŸãããã
--
=katsu
http://xri.net/=katsu/(+contact)
http://xri.net/=katsu/(+blog)
ããã§ããã
> â User-supplied IdentifierãURLã ã£ãã
> äžæ¹ãUser-supplied IdentifierãURLã ã£ãå Žåã¯ã»ã»ã»æ£èŠåãããŠãã©ã°ã¡ã³ãé€å»ãããŠClaimed
> Identifierã«ãªããŸããã
ã¡ãããŸããæ£èŠåããã®ã¯*RPã* discovery ãããšãã«ãã©ã°ã¡ã³ããé€å»ããã®ã§ãã£ãŠãOP ããããã£ãŠãã Claimed
Identifier ãæ£èŠåããŠã¯ãããŸããã
> RPã¯User-supplied Identifierãæ£èŠåããŠåŸãããClaimned
> Identifierããã®ãŸãŸèšæ¶ãããšããã§ãæç³»åçã«å¥ã®ã¿ã€ãã³ã°ã§ã®æææš©ãæã€ãŠãŒã¶ãšãéå»ã«æææš©ãæã£ãŠãããŠãŒã¶ãšã®åºå¥ã¯ã€ããŸããã
Claimed Identifier ããã®ãŸãŸèšæ¶ããã°ããã©ã°ã¡ã³ããã€ããŠããŸããããŠãŒã¶ã®åºå¥ãã€ããŸãã
> ããããªãããä»åã®yahoo.co.jpã®å®è£
ã§ã¯ãAuth
> responseã®openid.claimed_idã®å€ã«ã¯ç®¡ççªå·ãšããšãããã©ã°ã¡ã³ããä»äžãããŠããããã®ä»å æ
å ±ã«ããäžææ§ãæ
ä¿ããŠãããšäºæ³ãããªãã°ã
äºæ³ãããªãã°ããšãããããã®ããã®ãã©ã°ã¡ã³ã仿§ãªã®ã ãšæããŸããã
> ããæç¹ã§ã®ææè
ã®OpenID URLãïŒOpenID URL +
> ææè
åºæçªå·ïŒãšããæ¬è³ªçãªãŠãŒã¶ãžãããã³ã°ãã§ããã®ã¯OPã ãã§ããããOPã®è¿ããå€ãèšé²ãã¹ãã§ããã
ãã®ãšããã§ããã
> 1. OPã¯å¯èœãªéããªãµã€ã¯ã«äžèœãªOpenID URLãæäŸãã¹ãã§ããããããããããã©ã°ã¡ã³ãã«ãã£ãŠè¡šçŸãããŠãŒã¶ãžæäŸããããšã¯ç¡æå³ã§ããã
äžèšã®çç±ã«ããç¡æå³ã§ã¯ãªããšæããŸããã§ããéããªãµã€ã¯ã«äžèœãª URL
ãæäŸããã®ããã¹ããã©ã¯ãã£ã¹ã§ããããšã«ã¯åæããŸããããã㯠OP ã® requirement
ã§ã¯ãããŸãããããã¯ïŒå¹Žãããåã«æ¬å®¶ã§è©±é¡ã«ãªã£ãŠããŸãã®ã§ãèå³ãããã°ã©ããã
http://openid.net/pipermail/general/2007-May/002407.html
> ãªããšããããåæOPã®çºè¡ããOpenID URLãªããŠäœ¿ãæ°ã«ããªããŸããã
> ã ã£ãŠãèªåãæã£ãŠããOpenID
> URLãåå²ãåœãŠãããŠãããŸããŸèªåãå©çšããŠããRPãµã€ãã®ã¢ã«ãŠã³ãã«ãã©ããã®èª°ãã«ãã°ã€ã³ããã¡ããå¯èœæ§ããããã§ãããã
ãã©ã°ã¡ã³ããé€å»ããŠæ ŒçŽããŠããŸããããªå®è£
ã® RP ãäœ¿ãæ°ã«ãªããªãããšããã»ããæ£ããã®ã§ã¯ïŒ
ãããå©çšè
åŽãã©ã®ããã«ãã§ãã¯ããã°ããã®ãããšããã®ã¯è峿·±ãåé¡ãããããŸãããã
--
Tatsuhiko Miyagawa
On 4/5/08, Tatsuhiko Miyagawa <miya...@gmail.com> wrote:
> > â User-supplied IdentifierãURLã ã£ãã
> > äžæ¹ãUser-supplied IdentifierãURLã ã£ãå Žåã¯ã»ã»ã»æ£èŠåãããŠãã©ã°ã¡ã³ãé€å»ãããŠClaimed Identifierã«ãªããŸããã
>
> ã¡ãããŸããæ£èŠåããã®ã¯*RPã* discovery ãããšãã«ãã©ã°ã¡ã³ããé€å»ããã®ã§ãã£ãŠãOP ããããã£ãŠãã Claimed Identifier ãæ£èŠåããŠã¯ãããŸããã
ããããªãããããèªã¿éããŠãŸãããOP ã§èªèšŒããåã« normalize ãã㊠(ãã©ã°ã¡ã³ãé€å»ããŠ) Claimed
Identifier ã«ãªãããšããã®ã¯æ£ããã§ããã§ããªãµã€ã¯ã«ãããŠããå Žåããã®å€ãå©çšããŠããŸããšïŒãã©ã°ã¡ã³ãããªãã®ã§ïŒãã®æç¹ã§ä»¥åã®ææè
ãšåäžäººç©ãã©ãã
RP ã«ã¯ããããªãããšããã®ãæ£ããã§ããã
# katsu ããã®è©±ã¯ãã®ïŒç®æã ããªãããããããªãšæã£ãŠããã®ã§ããåã«ç§ãèªã¿éããŠãŸããããããŸããã
--
Tatsuhiko Miyagawa
> > ããããªãããä»åã®yahoo.co.jpã®å®è£
ã§ã¯ãAuth
> > responseã®openid.claimed_idã®å€ã«ã¯ç®¡ççªå·ãšããšãããã©ã°ã¡ã³ããä»äžãããŠããããã®ä»å æ
å ±ã«ããäžææ§ãæ
ä¿ããŠãããšäºæ³ãããªãã°ã
>
>
> äºæ³ãããªãã°ããšãããããã®ããã®ãã©ã°ã¡ã³ã仿§ãªã®ã ãšæããŸããã
ãã£ãšããããã«ãããªä»æ§ãæžããŠãããŸããã
æ ¹æ¬çã«ç¥ããã«é·æãæžããŠããŸããŸããã»ã»ã»
> äžèšã®çç±ã«ããç¡æå³ã§ã¯ãªããšæããŸããã§ããéããªãµã€ã¯ã«äžèœãª URL
> ãæäŸããã®ããã¹ããã©ã¯ãã£ã¹ã§ããããšã«ã¯åæããŸããããã㯠OP ã® requirement
> ã§ã¯ãããŸãããããã¯ïŒå¹Žãããåã«æ¬å®¶ã§è©±é¡ã«ãªã£ãŠããŸãã®ã§ãèå³ãããã°ã©ããã
> http://openid.net/pipermail/general/2007-May/002407.html
>
ããããšãããããŸããèŠãŠã¿ãŸããã
>
> > ãªããšããããåæOPã®çºè¡ããOpenID URLãªããŠäœ¿ãæ°ã«ããªããŸããã
> > ã ã£ãŠãèªåãæã£ãŠããOpenID
> > URLãåå²ãåœãŠãããŠãããŸããŸèªåãå©çšããŠããRPãµã€ãã®ã¢ã«ãŠã³ãã«ãã©ããã®èª°ãã«ãã°ã€ã³ããã¡ããå¯èœæ§ããããã§ãããã
>
>
> ãã©ã°ã¡ã³ããé€å»ããŠæ ŒçŽããŠããŸããããªå®è£
ã® RP ãäœ¿ãæ°ã«ãªããªãããšããã»ããæ£ããã®ã§ã¯ïŒ
ããã§ã¯åæOPã¯çµå±ç®¡çãè¡ãå±ããŠãããããã©ã°ã¡ã³ãä»äžããŠããããšéè€ãããŠããããšãããã§ããããšãããã©ããããããªãOPã®ããšãæããŠããŸãã
ã§ããä»°ããšãããããªRPã¯äœ¿ãæ°ã«ã¯ãªããªãã§ããããããã©ã€ãšã¿ãªã®å ŽåããŠãŒã¶ãŒããããèªèããã®ã¯ç°¡åã§ã¯ãªãããã§ããã»ã»ã»
ãã®åŸã«èªå·±ã¬ã¹ããŠããŸããŸããããåã®ã»ãã§ãã§ãŒãºãåéãããŠããŸãããééãã§ã¯ãããŸããããããŸããã
> Authentication
> 2.0ã®Terminologyã ããèŠãŠããè§£éããŠããŸãããããŸãè±èªã¯åŸæã§ã¯ãããŸããããããã«ããŠããã®è¡šçŸã¯åŸ®åŠã§ããã
> Claimed Identifier:
> * The Identifier obtained by normalizing (Normalization) the
> User-Supplied Identifier, if it was an URL.
ãããªãã§ãããã仿§æžã§ã¯ãClaimed Identifier ãšããèšèããèªèšŒããã»ã¹ãéããŠäœ¿ãããŠããŠã
Claimed Identifier: An Identifier that the end user claims to own; the
overall aim of the protocol is verifying this claim.
ãšãªã£ãŠããŠãæåã«å
¥åãããæ£èŠåããã Claimed Identifier
ã確ãã«ãã®ãŠãŒã¶ã®ãã®ã§ãããã確èªããã®ããã®ãããã³ã«ã§ããããšãªã£ãŠããŸãããå®éã«ã¯ã
7.2 This final URL MUST be noted by the Relying Party as the Claimed
Identifier and be used when requesting authentication (Requesting
Authentication).
11.5 The Claimed Identifier in a successful authentication response
SHOULD be used by the Relying Party as a key for local storage of
information about the user. The Claimed Identifier MAY be used as a
user-visible Identifier. When displaying URL Identifiers, the fragment
MAY be omitted.
ã®ïŒã€ã®å Žé¢ã§ Claimed Identifier
ãç°ãªãå€ã«ãªã£ãŠããã±ãŒã¹ïŒãã®ã¹ã¬ããã§ãããã話é¡ã«ãªã£ãŠããäŸã ãšãã©ã°ã¡ã³ãæç¡ïŒãããã®ã§ããããæ··ä¹±ãçããããŠãããšããæ°ãããŸããã
OpenID 1.x ã§ã¯ URL ã® Identification ã ãã ã£ããããã³ã«ã«ãAuthentication
ã远å ããããã«ããã®èª¬æãšãããçšèªã®äœ¿ãæ¹ãçŽãããããã®ã«ãªã£ãŠãããã®ãããããŸããã
--
Tatsuhiko Miyagawa
ããã§ããã
çžå€ããããæ£æã§ããããããªæãã§ãããã
äžå匷ãªç¹ã¯ææããŠé ãããšå©ãããŸã
-----
ã»ãªãµã€ã¯ãªã³ã°ããã ID ãå«ããID ã®äžææ§ãæ ä¿ããéšåãäžéæãªã®ã§ãæç³»åãæ±ãå¿ èŠã®ããã·ã¹ãã ãæ§ç¯ããéã«ãã·ã¹ãã åŽã§æ
ä¿ããå¿ èŠãããã®ã§ã¯ãªãã®ãïŒ
->ããã¡ãã§æå®ãã"ç©"ã ID ãšããŠå©çšããŠããããšããããããã (1.1) ãèªç±åºŠãäžãã£ãåãé£è§£ã«ãªã£ã (2.0)
 <-ãOP ãèšå®ãã ID ããPR ãä»»æã®æç¹ã§äžæã§ããã確èªããè¡ããªãã®ã§ã¯ïŒ
 <-ãäžå®æéããšã« RP åŽã§ ID ãç¶ç¶çã«å©çšãããŠããç©ã確èªããå¿ èŠããããïŒ
ã»ã·ã¹ãã å éšã§æ±ãæ å ±ãšãšã³ããŠãŒã¶ãèŠèªã§ããæ å ±ã«å·®ç°ãããããã®ä¹é¢ã倧ããå Žåã¯ãã€ã³ã¿ãŒãããã®å©çšã«äžæ £ããªãšã³ããŠãŒã¶ãæ³å®ã
ã«ããã®ã§ã¯ãªããïŒ
->ãOP ã RP ã®æéã«ãã衚瀺æ å ±ãªã©ã«å·®ç°ãããããšã³ããŠãŒã¶ãæ··ä¹±ããããããããªã
 <-ãæåã®çåç¹ã§ãOP ã衚æããæ å ±ãšãRP ãå ¥æã衚瀺ãã¹ãæ å ±ã®å·®ç°ã容èªãããŠãããæç¢ºãªæéããªãã®ã§ã¯ïŒ
<-ãæ³å®ãšããŠéšéãµãŒããªã©ã§ ID ã管çããå Žåã管çè ã®è³è³ªã«é¢ããŠåé¡ããå Žåã®å¯ŸåŠãªã©ã«ã³ã¹ããããããããããªãïŒ
-----
以äžãäºç¹ãšãããã«é¢é£ããæžæ¡ã§ã
以äžã¯è£è¶³ã§ã
 # ã«ç¶ãæã¯ãè¡éïŒãŒããïŒã瀺ããŸãã®ã§èªã¿é£ã°ããŠãã ãã
-----
æåã®éšåã¯ãæ®éã®ã¡ãŒã«ã¢ãã¬ã¹ãªã©ã§ãåãã§ãããïŒ
URL ãã¡ãŒã«ã¢ãã¬ã¹ã§ãåå©çšã¯ãããŸã
åæ§ã«ãå©çšããåŽã§èª€çšããªãããã«ãçæããã·ã¹ãã èšèšãããã°ããã®ã ãšæããŸãããã³ã¹ããããã¿ãŸã
# çããã°çãã»ã©å€ãé£ããåå©çšãèªèãããã®ã¯ããã®ãµã€ãã«èšªåããããã¡ãŒã«ãéã£ãŠããã§ããã..
--
次ã«ãæåã®çåç¹ãšæŽŸçããçåã§ãããããªã·ãŒã®æºãåãããåºæ¥ãã°ããã®ã§ã¯ïŒãšæããŸã
ãã¯ã€ããªã¹ããã¬ãŒãã£ã³ã°ãªã©ã§ããªã·ãŒã®å·®ç°ã®å°ãªããšãããéžæã§ããããã«ãªãã°è¯ãããç¥ããŸãã
# OP ã®è©äŸ¡ãã€ã³ãã现ååãããŠãRP ã¯ãã®è©äŸ¡ãã€ã³ããå©çšã§ããã°è¯ããããããŸãã
# ããããéå®ããããŠãŒã¶ã«ãµãŒãã¹ãæäŸãã RP ã®è©äŸ¡ã¯ã©ããªãã®ãå€ããŸãã
Yahoo! JAPAN ã® ID ã®æ§ãªå ŽåãURL ã®ã¹ããŒã ããã¯ãšãª/ãã©ã°ã¡ã³ããã®ããéšåãŸã§ãäžæã§æãã確èªã§ããŸãã
ã§ãããYahoo! ã®ãã©ã°ã¡ã³ãã®æ§ãªãåçŽåãããæ¡ã®å°ãªãæ°åãªã©ã¯èªèããããã®ã«ã衚瀺ãããªãã®ã§èŠèªã§ããŸãã
äžæ¹ãOpenID.ne.jp ã® ID ã®æ§ãªå Žåããšã³ããŠãŒã¶ãŒã¯ URL ãäžç®ã§ç¢ºèªããããšãåºæ¥ãŸããã
RP ã¯ããã® ID ã確èªããæç¹ã§ãéå»ã® ID ãšã®é£ç¶ããäžææ§ã確èªã§ãããäžæãªã®ã§ã¯ïŒãšèšãç¹ã§ã
# 誀解ãæããã«èšãã°ãéå»ãYahoo! JAPAN ã§ç³»åäŒæ¥ãéãã ID ã®æµåºããã£ããšèšæ¶ããŠããŸãããID ã®æ³åæ§ãäžæãªä»¥
äžãç¡æ¡ä»¶ã§ä¿¡çšããããšã¯åºæ¥ãªãã§ããã..
## ãã¡ãããçŸç¶ã§ã¯ãã®æ§ãªããšã¯ãªããšèã ID ãªã©ãç»é²ããŠããŸãã®ã§æªãããã!
ã©ã¡ããããšã³ããŠãŒã¶ã«èª€è§£ãäžããå Žåãæãã®ã§ã¯ãªãããšèããŠããŸããŸã
ãŸããOP ãä¿¡çšã§ãããåŠãïŒRP ãä¿¡çšããŠãããããåŠãïŒã«åž°çµããŠããŸãããç¥ããŸãã
-----
Cookie ãªã©ãå©çšããã7.1. Initiation ãã§èšããUser-Supplied Identifier ã®åæå€
ã"yahoo.co.jp"ãªã©ãšããå Žåãæçã§ã¯ãããŠã¹ã®ã¯ãªãã¯ãäºåããã ãã§èªèšŒããããšãåºæ¥ãŸã
ãã°ã€ã³èªèšŒã®å©äŸ¿æ§åäžã«ã¯æ¬ ãããŸããã®ã§ããããçŸåšæ§ç¯äžã®ã·ã¹ãã ã«çµã¿èŸŒãããšæã£ãã®ãçºç«¯ã§ã
ä»åŸã®Internet Explorer ã Mozilla FireFox ãªã©ã®ãŠãŒã¶ã»ãšãŒãžã§ã³ããªã©ããŸããŸã䟿å©ã«äœ¿ããããã«ãªããš
ããããŸã
-----
# openid-japan.orgããªã©ã«ã¯ãRP ãªã©ã®æ§ç¯ã¬ã€ããªã©æåŸ ãããã§ã ^^