Support Verisign's OpenID Seatbelt extension

Bug #176848 reported by James Henstridge
2
Affects Status Importance Assigned to Milestone
Canonical SSO provider
Triaged
Wishlist
Unassigned

Bug Description

Verisign produced a Firefox extension known as "Seatbelt" to reduce opportunities for identity theft. Details of the extension can be found here:

    https://pip.verisignlabs.com/seatbelt.do

The extension appears to be configured by a <link> element on the base page of the domain. For example, on https://pip.verisignlabs.com/:

      <link rel="seatbelt.config" type="application/xml" href="https://pip.verisignlabs.com/web/brand/default/seatbelt/seatbeltcfg.xml" />

The configuration file includes the following:
 * descriptive information about the OpenID Provider
 * a link to the login page (so we'd need to do bug 176845 to support this)
 * a link to an XML page that indicates the user's login state.
 * details of the OP's SSL certificate (domain, common name, SHA1 hash of certificate).
 * branding for the login status indicator (colours and images).

Once bug 176845 is implemented, it should be fairly trivial to implement this.

Changed in launchpad:
importance: Undecided → Medium
milestone: none → 1.2.3
status: New → Confirmed
Changed in launchpad:
milestone: 1.2.3 → none
Changed in launchpad-foundations:
status: Confirmed → Triaged
Changed in canonical-identity-provider:
importance: Medium → Wishlist
tags: added: openidrp
jace (jace01)
Changed in canonical-identity-provider:
status: Triaged → Confirmed
status: Confirmed → Fix Released
Colin Watson (cjwatson)
Changed in canonical-identity-provider:
status: Fix Released → Triaged
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.