0

Yahoo and website identity

So I'm trying to clean up the "Warning: This website has not confirmed its identity with Yahoo! and might be fraudulent" message for a site that we developed, so I followed some suggestions located via Google and the FAQ's on YDN, but am still having issues.

Basically I have a site that has two places to login from, but I am feeding both the XRDS header and the XRDS meta tag from both. Here are the urls:

Users can login from here:
https://www.egive-usa.com/

and here:
https://www.egive-usa.com/account/login/

Both of these use the following XRDS:
https://www.egive-usa.com/account/login/xrds/

But I'm still getting the warning. I figure I'm just missing something really small here!

Thanks!

by
  • R
  • Feb 17, 2009
5 Replies
  • QUOTE (rballou05 @ Feb 17 2009, 09:40 AM) <{POST_SNAPBACK}>
    So I'm trying to clean up the "Warning: This website has not confirmed its identity with Yahoo! and might be fraudulent" message for a site that we developed, so I followed some suggestions located via Google and the FAQ's on YDN, but am still having issues.

    Basically I have a site that has two places to login from, but I am feeding both the XRDS header and the XRDS meta tag from both. Here are the urls:

    Users can login from here:
    https://www.egive-usa.com/

    and here:
    https://www.egive-usa.com/account/login/

    Both of these use the following XRDS:
    https://www.egive-usa.com/account/login/xrds/

    But I'm still getting the warning. I figure I'm just missing something really small here!

    Thanks!



    Hi,

    The warning message is displayed if Yahoo can't find your site's return_to URL in your site's XRDS file.

    The X-XRDS-Location link tag in on https://www.egive-usa.com returns "Internal Server Error" pretty frequently (the failures seem intermittent).
    https://www.egive-usa.com/account/xrds/

    After trying a few times, I did manage to fetch your XRDS, and the return_to URL is:
    <URI>http://www.egive-usa.com/account/</URI>

    However, in the OpenID request, you're setting it to be:
    https://www.egive-usa.com:443/account/login/


    You'll need to make them match before the error goes away. For performance reason, Yahoo caches your site's XRDS, so it might take awhile for any changes that you make to the XRDS to be recognized.

    A very nice writeup about the warning is here:


    http://blog.nerdbank.net/2008/06/why-yahoo...penid-site.html

    Thanks
    Allen
    0
    • R
    • Feb 24, 2009
    QUOTE (atom @ Feb 18 2009, 11:07 AM) <{POST_SNAPBACK}>
    Hi,

    The warning message is displayed if Yahoo can't find your site's return_to URL in your site's XRDS file.

    The X-XRDS-Location link tag in on https://www.egive-usa.com returns "Internal Server Error" pretty frequently (the failures seem intermittent).
    https://www.egive-usa.com/account/xrds/

    After trying a few times, I did manage to fetch your XRDS, and the return_to URL is:
    <URI>http://www.egive-usa.com/account/</URI>

    However, in the OpenID request, you're setting it to be:
    https://www.egive-usa.com:443/account/login/


    You'll need to make them match before the error goes away. For performance reason, Yahoo caches your site's XRDS, so it might take awhile for any changes that you make to the XRDS to be recognized.

    A very nice writeup about the warning is here:


    http://blog.nerdbank.net/2008/06/why-yahoo...penid-site.html

    Thanks
    Allen


    Got it to work!

    I updated our code so that it all XRDS references point to the correct location (https://www.egive-usa.com/account/login/xrds/) and updated the XRDS itself to point to https://www.egive-usa.com:443/account/login/ (which I also verified is the return_to as mentioned). I also updated the realm that I was passing as it redirects when accessed (which is mentioned as being problematic in the article).

    Thanks everyone for your help!
    0
  • Hi,

    We are having someone have a look at your site to see if we can figure out what's going on. We'll let you know when we figure it out. Hang tight.

    Thanks,

    Tom
    Yahoo! Developer Network
    0
  • Who do i contact for identity theft on yahoo i did not set up website and Facebook Layouts
    0
  • QUOTE (YUVI @ Dec 21 2009, 01:21 AM) <{POST_SNAPBACK}>
    Who do i contact for identity theft on yahoo i did not set up website and Facebook Layouts


    You can do so through our help system at http://help.yahoo.com/l/us/yahoo/helpcentral/
    0

Recent Posts

in OpenID General Discussion