solid-spec icon indicating copy to clipboard operation
solid-spec copied to clipboard

Removed references to TLS as primary auth method

Open jaxoncreed opened this issue 6 years ago • 4 comments

TLS as a primary form of authentication should be deprecated in favor of a oidc. TLS may still be used as a form of credentials under oidc. All concerns about needing completely decentralized identity systems will be solved with an eventual implementation of DiD.

jaxoncreed avatar May 14 '19 16:05 jaxoncreed

Not opposed, just checking if this has been checked with @timbl?

RubenVerborgh avatar May 14 '19 16:05 RubenVerborgh

@RubenVerborgh I'm going to submit this for discussion at the w3c working group meeting too, so we'll have plenty of time for input.

jaxoncreed avatar May 14 '19 17:05 jaxoncreed

:+1: and if this PR will not land this month it should at least get marked with at risk

elf-pavlik avatar May 14 '19 23:05 elf-pavlik

Feedback we got from @timbl and @kidehen (in my own words): webid-tls should still be mentioned as a 'MAY' for client-storage, and as a 'SHOULD' for user-IDP login method ('openid + TLS bridge')

michielbdejong avatar Jun 27 '19 13:06 michielbdejong