<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: StartCom SSL: Using Certificates and Smart Cards for Login</title>
	<link>http://spreadopenid.org/2008/03/09/startcom-ssl-using-certificates-and-smart-cards-for-login/</link>
	<description></description>
	<pubDate>Thu, 20 Nov 2008 10:31:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
		<item>
		<title>By: Carsten Poetter</title>
		<link>http://spreadopenid.org/2008/03/09/startcom-ssl-using-certificates-and-smart-cards-for-login/#comment-50</link>
		<dc:creator>Carsten Poetter</dc:creator>
		<pubDate>Tue, 22 Apr 2008 16:55:20 +0000</pubDate>
		<guid>http://spreadopenid.org/2008/03/09/startcom-ssl-using-certificates-and-smart-cards-for-login/#comment-50</guid>
		<description>Hm, the website of StartCom SSL is available. Don't know about the provider, though.</description>
		<content:encoded><![CDATA[<p>Hm, the website of StartCom SSL is available. Don&#8217;t know about the provider, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob</title>
		<link>http://spreadopenid.org/2008/03/09/startcom-ssl-using-certificates-and-smart-cards-for-login/#comment-49</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Tue, 22 Apr 2008 15:17:02 +0000</pubDate>
		<guid>http://spreadopenid.org/2008/03/09/startcom-ssl-using-certificates-and-smart-cards-for-login/#comment-49</guid>
		<description>It looks like it might be down now, but http://prooveme.com/ was an interesting implementation of SSL certificate based OpenID.

Of course, the key reason to use SSL (with or without client certificates) is that it allows you to validate the OpenID provider and ensure that man-in-the-middle attacks are more difficult to implement.

But I expect y'all knew that.</description>
		<content:encoded><![CDATA[<p>It looks like it might be down now, but <a href="http://prooveme.com/" >http://prooveme.com/</a> was an interesting implementation of SSL certificate based OpenID.</p>
<p>Of course, the key reason to use SSL (with or without client certificates) is that it allows you to validate the OpenID provider and ensure that man-in-the-middle attacks are more difficult to implement.</p>
<p>But I expect y&#8217;all knew that.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
