OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

wss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Proposed Interop2 Scenarios


Here are four proposed scenarios to test the remaining aspects of the X.509
profile. Please comment. I will be working in parallel on detailed writeups.

Scenario #4 Session Key

Simulate a previously exchanged symmetric session key. (agreed out of band
for the Interop)

Just like scenario #3 (sign and encrypt the body) except use a ReferenceList
in the Security Header to indicate the encrypted data (in place of
EncryptedKey)

Scenario #5 Overlapping Signatures

Use one key to sign the body and a second key to sign both the body and a
timestamp in the header.

Scenario #6 Encrypt and Sign

Just like scenario #3 except first encrypt and then sign. Signature and
EncryptedKey elements appear in the opposite order.

Scenarion #7 Signed Token

Just like scenario #3 except signature also covers signing token. Security
Token Reference is is used with STR Dereference Transform.

Comments?

Chris and Hal




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]