Simple WebID Exploitation via Amazon S3 based Linked Data Deployment

In my last two posts [1][2], I used a simple Turtle document to demonstrate how anyone deploy Linked Data without any of the following hurdles:

1. Domain Ownership
2. Web Server Access and Administrator Privileges
3. Content Negotiation
4. de-referencabe URI (Hyperlink) style selection.

My initial post focused on the task of producing a simple profile document where you make some very basic claims about yourself. In this post, I am going a step further by incorporating additional personal profile claims, en route to demonstrating how Linked Data enables you control your identity via verification of identity claims that you make about yourself. 


1. Create a simple Turtle based profile document and upload it to your S3 bucket -- as outlined in my simple Linked Data Deployment post

2. Use an X.509 Certificate Generator [3][4] to produce a certificate with a WebID (Personal de-referencable URI) in the SubjectAlternativeName (SAN) field -- this is simply a URI that denotes (names) entity "You", the primary topic of the Turtle profile document you've created e.g., <

3. Create a triple (3-tuple) based relationship in your profile document that associates your WebID (Personal URI) with the newly generated certificate's public key components (modulus and exponent)

4. Do the same thing with the certificate's fingerprint (the SHA1 or MD5 hash of the entire certificate).

Certificate Generation Notes

Certificate Generation

For this exercise I deliberately used the Certificate Generator component of the Mac OS X Keychain application. I've attached screenshots and a link to a Google Drive folder [5], but they might not be in perfect sequence to to G+ limitations in this regard. 

I've also included screenshots from our Web hosted Certificate Generator which is also an option for producing X.509 certificates that carry an WebID watermark, with the WebI authentication protocol in mind. 

Actual Profile Document Tweaks

Here are two excerpts from my Turtle based profile document [6] highlighting the relationships that enable your profile document serve as a mirror of identity claims matching those imprinted into the X.509 certificate stored in the local keystore of your personal computing device (desktop, notebook, tablet, or phone).

WebID Protocol Requirements

## WebID Authentication Protocol Requirements Start Here ##

:this cert:key :pubKey .
:pubKey a cert:RSAPublicKey;

# Public Key Exponent -- copy and paste this from your X.509 Certificate viewer

cert:exponent "65537"^^xsd:integer;

# Public Key Modulus -- copy and paste this from your X.509 Certificate viewer

cert:modulusxsd:hexBinary .

## WebID Authentication Protocol Requirements End Here ##

NetID / YouID Protocol Requirements

## NetID / YouID Authentication Protocol Requirements Start Here ##

# Note: NetID / YouID are WebID authentication protocol derivatives that use a Fingerprint (certificate hash) for complete "claims mirror" between your profile document and the X.509 certificate in your local keystore. Thus, instead of looking up public key components it looks up the certificate fingerprint instead. 

:this opl:hasCertificate :cert .

# Certificate Fingerprint -- copy and paste from your X.509 Certificate viewer (remove the spaces).

:cert opl:fingerprint "9BA11059D6EE8C10CF2050DF4091F71D55A81ACF"^^xsd:hexBinary;
opl:fingerprint-digest "sha1" .

## NetID / YouID Authentication Protocol Requirements End Here ##

Identity Verification

Now that your Turtle based profile document has been enhanced with identity claims that mirror those in your local WebID watermarked X.509 certificate, you can verify the effects of this endeavor by performing a simple identity verification check via any of the following:

1. -- our simple Identity Claims Verification Service -- just click on the "check" button, then select your WebID watermarked X.509 certificate and you'll get success of failure

2. -- our simple OpenID+WebID proxy service that enables you experience how WebID eliminates the use of passwords when authenticating against any functional OpenID site, just use the URL pattern:{WebID}

3. -- test against other WebID compliant applications and services. 


1. -- Very simple Linked Data Deployment via a Turtle Document  

2. -- Detailed guided to Linked Data Deployment via a Turtle Document 

3. -- YouID X.509 Certificate Generator

4. -- Other X.509 Certificate Generators

5. -- Google Drive Folder holding screenshots re. use of the Keychain Certificate Generator Assistant and our Web based Generator 

6. -- My actual Turtle based Profile Document published to an Amazon S3 bucket .

#LinkedData #WebID #Web30 #SemanticWeb #Identity #Nymwars #Privacy #PDS
30 Photos - View album
Shared publiclyView activity