Below is a literal copy of google doc issue 22:
- Compatibility with existing standards -- geni certificates: add non-standard fields ? investigate and document if needed. (idea: openssl should be okay for creating a certificate)
Jordan: Although it is not directly of concern with the AM API, authentication and authorization are based on certificates and credentials which sometimes are based on existing standards (X.509 for example), sometimes are proprietary formats (XML credentials). It should be explained why the choice for non-open standards has been made. Also, it should be clear how much compatibles are the tokens we used compared to standards.