Paul Crowley paul at
Tue Jun 28 15:00:29 PDT 2005

Brad Fitzpatrick wrote:
> Identity URLs.  But considering that server URLs will likely be https
> (typekey will be), consumers already have to support https, so they might
> as well support https identity URLs too, eh?

That would really be great.  I'm not a huge fan of Verisign-style 
security, but it's definitely the best cryptographic security OpenID can 
offer as defined...
