OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ws-rx message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Analysis of the interactions between WS-RM and security


The attached document is an analysis of some of the interactions between
WS-RM. In it I explain why we don't need to bind WS-RM and WSS together
and why sequence ID forging attacks are nothing more than DOS attacks.
There is also some discussion of deployment models and how this effects
the process of binding the sequence header to the message body via a
signature.

Please take the time to read at least Section I before we discuss i029
on Thursday.

- g


________________________________________________________________________________
BEAWorld 2005: coming to a city near you.  Everything you need for SOA and enterprise infrastructure success.


Register now at http://www.bea.com/4beaworld


Santa Clara 27-29 Sep| London 11-12 Oct| Paris13-14 Oct| Prague18-19 Oct |Tokyo 25-26 Oct| Beijing 7-8 Dec

Interactions of WS-RM with Security.doc



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]