Top Navigation
i

Dangerous or safe to use OpenID as contain managed security

I'm curious. What are the pros/cons to using OpenID provider in
this manner? It seems elegant, but since it doesn't appear to be a
well documented Architecture pattern (can't find a lot of references
on Web), I'm concerned about the approach for a high volume Web facing
consumer application. In particular in TomCat using the example posted at http://blog.facilelogin.com/2008/11/openid-authenticator-for-tomcat.html

Any additional information available that I may have missed?
Thoughts? Opinions?

Tomcat OpenID Authenticator

Tomcat OpenID Authenticator mentioned in your reference adds OpenID authentication to your web app at the container level - and still the web app decides which level of security it requires.

Thanks & regards.
-Prabath

cloud bb