OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ebxml-msg message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] (EBXMLMSG-86) Confusion about Content-Type for compressed and encrypted payloads


    [ https://issues.oasis-open.org/browse/EBXMLMSG-86?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=66007#comment-66007 ] 

Theo Kramer commented on EBXMLMSG-86:
-------------------------------------

That should read "[WSSSWA] - Web Services Security SOAP Message with Attachments (SwA) Profile Version 1.1.1, Section 5.5.2 (4) Encryption Processing Rules" states the following 'Set the <xenc:EncryptedData> MimeType attribute to match the attachment MIME part Content-Type header before encryption when the Content-Only URI is specified for the Type attribute value. The MimeType attribute value MAY be set when the AttachmentComplete Type attribute value is specified.'

> Confusion about Content-Type for compressed and encrypted payloads
> ------------------------------------------------------------------
>
>                 Key: EBXMLMSG-86
>                 URL: https://issues.oasis-open.org/browse/EBXMLMSG-86
>             Project: OASIS ebXML Messaging Services TC
>          Issue Type: Improvement
>          Components: AS4 Profile
>            Reporter: Sander Fieten
>
> On line 262 (PDF version) of the AS4 profile it is stated that "The content type of the compressed attachment MUST be "application/gzip"."
> This suggests that for compressed payloads the Content-Type should always be "application/gzip".
> On lines 266-267 however it is also stated that  "When compression, signature and encryption are required, any attached payload(s) MUST be compressed prior to being signed and/or encrypted" 
> This implies that the rules of the WS-Security SwA profile must be applied after compression. As a result the Content-Type header must be changed to "application/octet-stream"
> In the AS4 profile this should be made clear. 



--
This message was sent by Atlassian JIRA
(v6.2.2#6258)


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]