OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ebxml-cppa message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: RE: Security - question about nonrepudiation


Chris,

	I understand the CPP/A is where the details are, but what I was
wondering about is, if within the CPP (doc properties) the technical details
are already expressed.  The BPSS provides the abstract requirements and the
other tags within the CPP/A provide the technical details.  The
nonrepudiation tags do not force any additional "things" to be done.  

	Tim

-----Original Message-----
From: christopher ferris [mailto:chris.ferris@east.sun.com]
Sent: Tuesday, July 31, 2001 3:09 PM
To: Collier, Timothy R
Cc: ebxml-cppa@lists.oasis-open.org
Subject: Re: Security - question about nonrepudiation


Tim,

I don't think so, because the CPP/A covers the technical
dsetails of the digital signing (algorithm, etc.) whereas the
BPSS just indicates that the document should be signed, not how.

Cheers,

Chris

"Collier, Timothy R" wrote:
> 
> All,
> 
>         If two parties agree on complimentary roles within a process
> specification, and agree on the document properties (in particular
signing)
> don't the nonrepudiation elements in the delivery channel characteristics
> become superfluous?  After all, the parties have agreed on a process
> specification that includes acknowledgement of receipt, and they have
agreed
> on which documents have signatures attached (in the document exchange).
To
> me NRR sounds like a requirement on the BP, and NRO is a document
> requirement for digital signature.
>         I have heard that the delivery channel is an implementation
> convenience, which is ok, but it seems even for that the authenticated tag
> covers the digital signature requirement. And the implementation already
is
> monitoring the runtime process according to the BPSS.
>         Do you think the nonrepudiation tags in the delivery channel
express
> unique requirements that are not already covered?
> 
>         Tim
> 
> ------------------------------------------------------------------
> To unsubscribe from this elist send a message with the single word
> "unsubscribe" in the body to: ebxml-cppa-request@lists.oasis-open.org



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Powered by eList eXpress LLC