HTTPS Client Certificate Authentication - Browser Implementation Guidelines

If the WebID folks including TimBL believe that the only problem is the UI, the most
logical thing to do would be creating a document like the subject line suggests.

There is a risk that the vendors will simply laugh at such a request,  but that's much
better than promising improvements that so far haven't even been acknowledged by
those who are supposed to implement them.

I would personally be very interested in hearing what the "right" session inactivity
timeout for logout is.  Client-side enforced logout requires TCP reset.

Anders

Received on Sunday, 18 May 2014 08:02:14 UTC