Re: OpenID login to be disabled on translate.zanata.org

Matthew Miller <[email protected]>
Newsgroups gmane.linux.redhat.internationalization,gmane.linux.redhat.fedora.internationalization
Message-ID <[email protected]>
On Tue, May 22, 2018 at 10:19:17PM -0400, Ding Yi Chen wrote:
> Our recent analysis has shown that some OpenID providers return
> HTTP-based OpenID identities, even when the login is initiated via
> HTTPS. This introduces an element of risk to OpenID authentication
> and also forces the use of looser firewall rules. For the security of
> the service, we have decided to discontinue OpenID support. Local
> username/password authentication is still supported.

I don't think Fedora's OpenID login has this flaw. Would it be possible
to allow OpenID login for white-listed providers which are known to be
well-behaved?


-- 
Matthew Miller
<[email protected]>
Fedora Project Leader
_______________________________________________
trans mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]/message/GXUVRIOYY4FYCDPSAXRFZWFZTGEUMQRL/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.