<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>“Geneva” Team Blog : HTTP</title><link>http://blogs.msdn.com/card/archive/tags/HTTP/default.aspx</link><description>Tags: HTTP</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>All the bits to employ CardSpace without an SSL certificate are now available</title><link>http://blogs.msdn.com/card/archive/2007/10/26/all-the-bits-to-employ-cardspace-without-an-ssl-certificate-are-now-available.aspx</link><pubDate>Fri, 26 Oct 2007 09:24:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5686292</guid><dc:creator>CardSpaceBlog</dc:creator><slash:comments>2</slash:comments><comments>http://blogs.msdn.com/card/comments/5686292.aspx</comments><wfw:commentRss>http://blogs.msdn.com/card/commentrss.aspx?PostID=5686292</wfw:commentRss><description>&lt;P class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="COLOR: black"&gt;Hi, my name is Tariq Sharif and I am a program manager in the CardSpace team.&amp;nbsp; After we released CardSpace V1 we received feedback from hobbyists, early technology adapters &lt;/SPAN&gt;&lt;SPAN style="COLOR: red"&gt;&lt;FONT color=#000000&gt;and site owners&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt; that getting/setting up a SSL certificate is hard&lt;FONT color=#000000&gt;&amp;nbsp;and&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: red"&gt;&lt;FONT color=#000000&gt; it is not needed for some set of their scenario&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt; and that this is blocking them from accepting information cards on their sites.&amp;nbsp; Based on this feedback, the feature team decided to remove this requirement for the .Net Framework 3.5 release.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;FONT face=verdana,geneva&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="COLOR: black"&gt;In order to invoke Cardspace from a page that does not have an SSL connection you need two updated components.&amp;nbsp; First you will need to install an updated browser specific extension &lt;/SPAN&gt;&lt;SPAN style="COLOR: #943634"&gt;&lt;FONT color=#000000&gt;that will work at an HTTP site&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;.&amp;nbsp; You can download the IE extension from &lt;A class="" href="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx" target=_blank mce_href="http://www.microsoft.com/technet/security/bulletin/ms07-045.mspx"&gt;here&lt;/A&gt; &lt;/SPAN&gt;&lt;FONT color=#000000&gt;&lt;SPAN style="COLOR: #943634"&gt;&lt;FONT color=#000000&gt;or if you have IE7 you probably already have it as part of the &lt;FONT color=#3300ff&gt;&lt;A class="" href="http://blogs.msdn.com/ie/archive/2007/10/09/ie-october-security-update-is-now-available.aspx" mce_href="http://blogs.msdn.com/ie/archive/2007/10/09/ie-october-security-update-is-now-available.aspx"&gt;October&lt;/A&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color=#3300ff&gt;&lt;A class="" href="http://blogs.msdn.com/ie/archive/2007/10/09/ie-october-security-update-is-now-available.aspx" mce_href="http://blogs.msdn.com/ie/archive/2007/10/09/ie-october-security-update-is-now-available.aspx"&gt; security update&lt;/A&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;. Second you will need to install an updated version of Cardspace that does the right thing when a website, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="COLOR: red"&gt;&lt;FONT color=#000000&gt;the&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT color=#000000&gt; relying&lt;/FONT&gt; party, does not have a certificate.&amp;nbsp; Latest version of Cardspace can be downloaded as part of &lt;A class="" href="http://www.microsoft.com/downloads/details.aspx?familyid=333325FD-AE52-4E35-B531-508D977D32A6&amp;amp;displaylang=en" mce_href="http://www.microsoft.com/downloads/details.aspx?familyid=333325FD-AE52-4E35-B531-508D977D32A6&amp;amp;displaylang=en"&gt;.Net Framework 3.5&lt;/A&gt;. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;You can read more technical details about this new functionally here in this &lt;/FONT&gt;&lt;FONT face=verdana,geneva color=#000000&gt;&lt;A class="" href="http://blogs.msdn.com/card/archive/2007/09/25/deploy-cardspace-on-your-site-without-a-ssl-certificate.aspx" mce_href="http://blogs.msdn.com/card/archive/2007/09/25/deploy-cardspace-on-your-site-without-a-ssl-certificate.aspx"&gt;post&lt;/A&gt;&lt;/FONT&gt;&lt;FONT face=verdana,geneva color=#000000&gt; that Ruchi made a couple of weeks ago.&amp;nbsp; Please feel free to drop us any comments on this, as we are always looking for feedback to help us refine this emerging technology.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;Thanks,&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;Tariq Sharif&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=verdana,geneva color=#000000&gt;Program Manager&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5686292" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/card/archive/tags/HTTP/default.aspx">HTTP</category><category domain="http://blogs.msdn.com/card/archive/tags/CardSpace/default.aspx">CardSpace</category><category domain="http://blogs.msdn.com/card/archive/tags/.NET+3.5/default.aspx">.NET 3.5</category></item><item><title>Deploy CardSpace on your site without a SSL certificate</title><link>http://blogs.msdn.com/card/archive/2007/09/25/deploy-cardspace-on-your-site-without-a-ssl-certificate.aspx</link><pubDate>Tue, 25 Sep 2007 03:36:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5109474</guid><dc:creator>CardSpaceBlog</dc:creator><slash:comments>14</slash:comments><comments>http://blogs.msdn.com/card/comments/5109474.aspx</comments><wfw:commentRss>http://blogs.msdn.com/card/commentrss.aspx?PostID=5109474</wfw:commentRss><description>&lt;font face="verdana,geneva" size="2"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;

&lt;/p&gt;&lt;/span&gt;&lt;/font&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;CardSpace in .Net Framework 3.0 required that sites
deploying CardSpace always have a SSL certificate. This meant that every site
that wanted to use CardSpace was forced to deploy an https site.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Based on customer feedback, we have decided to relax this
requirement for the next release of CardSpace (currently available in .NET
Framework 3.5 Beta 2). We realize that there are some sites like blogs which
would like to use CardSpace, but consider the SSL requirement to be a
deployment blocker. Now, if you have a website that you want to add CardSpace
support to, all you need to do is add the object tag to the page and you are
done.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;In addition to requiring .Net Framework 3.5 beta 2 or later,
a new version of icardie.dll is required to use this new feature. This will
ship with Vista SP1 and an upcoming update to IE7.&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;CardSpace does behave differently for http vs. https sites.
When CardSpace is invoked from an http site, CardSpace will inform the user
about the lack of an SSL connection and the security implication of this.
(Also, note the new streamlined look of this window)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&amp;nbsp;

&lt;font face="verdana,geneva" size="2"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/font&gt;
&lt;p class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;font face="verdana,geneva" size="2"&gt;&lt;span style="font-size: 10pt; line-height: 115%;"&gt;&lt;img src="http://blogs.msdn.com/photos/card/images/5109353/original.aspx" title="No SSL screenshot" style="width: 677px; height: 464px;" alt="No SSL screenshot" mce_src="http://blogs.msdn.com/photos/card/images/5109353/original.aspx" align="absmiddle" height="300" width="425"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;In addition, managed card issuers can decide if the card
they issued can be used on sites that do not support SSL. This can be done by
adding the following element to the .crd file.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&amp;lt;wsid:RequireStrongRecipientIdentity xmlns:wsid=
‘http://schemas.xmlsoap.org/ws/2007/01/identity’&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;If this element is specified then the card can only be used
on a site that has a SSL certificate. The card will not ‘light up’ when the
user is on an http site. A point to be noted is that cards that were issued for
last release of CardSpace will light up on http sites as they will lack this
new element. In that case, the IP STS can make a decision on whether to release
a token based on the identity of the recipient sent in the RST message. Another
feature that was added for this release is the support for custom soap faults
(next blog entry will have details on that feature) and that can be leveraged
to provide the user with appropriate error information. Similarly, if a .crd
file with this element is imported into the last release of CardSpace, it will
be ignored.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Some other differences on an http site are:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;1)&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;PPID value is
different as no certificate is available. The method used to calculate the PPID
is the same as described in the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=B94817FC-3991-4DD0-8E85-B73E626F6764&amp;amp;displaylang=en"&gt;&lt;span style="color: purple;"&gt;Identity Selector
Interoperability Profile&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;.&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;
The only difference lies in the calculation of the RP identifier. The RP
Identifier is calculated as follows&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;a.&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;i&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;OrgIdString&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;
= fully qualified DNS host name or the IP address of the server specified in
the URI of the site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;b.&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Encode all the
characters in &lt;i&gt;OrgIdString &lt;/i&gt;into a sequence of bytes, call it &lt;i&gt;OrgIdBytes&lt;/i&gt;,
using Unicode encoding (UTF-16LE with no byte order mark). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;c.&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif'; color: navy;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Hash &lt;i&gt;OrgIdBytes &lt;/i&gt;using
the SHA256 hash function, and use the resulting value as the RP identifier.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 1in;"&gt;&lt;i&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;RP identifier =
SHA256 (OrgIdBytes)&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
For an auditing STS, only the URL of the site is sent to the IP STS as identity
information for the relying party. As described in the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=B94817FC-3991-4DD0-8E85-B73E626F6764&amp;amp;displaylang=en"&gt;&lt;span style="color: purple;"&gt;Identity Selector
Interoperability Profile&lt;/span&gt;&lt;/a&gt; ( Section 4.3.3), if no wsp:AppliesTo is
specified in the relying party’s token policy and the IPSTS requires it, the
following will be sent for a http site&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;lt;wst:RequestSecurityToken&amp;gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in; text-indent: 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;lt;wsp:AppliesTo&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&amp;lt;wsa:EndpointReference&amp;gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 1.5in; text-indent: 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;lt;wsa:Address&amp;gt;http://ip.fabrikam.com&amp;lt;/wsa:Address&amp;gt;
&amp;lt;/wsa:EndpointReference&amp;gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 1in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;lt;/wsp:AppliesTo&amp;gt;
...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;nbsp;&amp;lt;/wst:RequestSecurityToken&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Though a certificate
is not sent to the IP STS, the token returned by the STS can still be encrypted
if the identity provider has a pre-existing relationship with the RP and has
mutually agreed on the use of a known encryption key.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin: 0in 0in 0.0001pt 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;3)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Self issued tokens are not encrypted. Because the token is unencrypted, the
only change most token processing libraries require is to skip the decryption
step, the rest of the token remains unchanged.&amp;nbsp; The token processing
sample at &lt;a href="http://cardspace.netfx3.com/" target="_blank"&gt;&lt;span style="color: windowtext; text-decoration: none;"&gt;http://cardspace.netfx3.com/&lt;/span&gt;&lt;/a&gt;&amp;nbsp;will
be updated with this change.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;4)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
Though the self issued tokens are not encrypted they are still signed as
described in Section 8 in &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=B94817FC-3991-4DD0-8E85-B73E626F6764&amp;amp;displaylang=en"&gt;&lt;span style="color: purple;"&gt;Identity Selector
Interoperability Profile&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Let us know if you have questions or feedback.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Ruchi&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;Software Design Engineer - CardSpace Team&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&amp;nbsp;&lt;/span&gt;&lt;span style="font-size: 10pt; line-height: 115%; font-family: 'Verdana','sans-serif';"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;font face="verdana,geneva" size="2"&gt;&lt;/font&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=5109474" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/card/archive/tags/HTTP/default.aspx">HTTP</category></item></channel></rss>