Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's so annoying that OpenID providers either support client certs or using your own domain, but never both!


I have not tried both, so I did not experience this problem. I do know SSL client certs do not work well, and wanted to work on building my own solution that does what StartSSL (an OpenID endpoint with SSL-cert based authentication). Does anyone know of ways to do this?


Nginx supports client certs[1], so I'd say the easiest way to get started is to get some free OpenID server (SimpleID[2] seems maintaned) and configure nginx to require cert authentication to access the login path.

I'd do it myself, if I used OpenID more than once every two months or so.

[1]: http://nategood.com/client-side-certificate-authentication-i...

[2]: http://simpleid.koinic.net/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: