> [ Security people, sanity-check me..... ]
> Imran,
> Because the key could change, and it'd be a pain for the people running
> the ID server to have to notify all their users to go change their link
> tags.
> But perhaps we could add:
> <link rel='openid.pubkey_signedby' value="93:AC:3A:B8:....." />

I think that's a good idea, as it would allows id servers to sign
their own keys without requiring a third party certificate authority
but still provide a similar level of security.

