OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ws-sx message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Issue PR016: Missing assertion to indicate arbitrary key pair to beused as a security token


Issue PR016

 

From: Jan Alexander
Sent: Saturday, February 10, 2007 10:13 PM
To:
Cc: Marc Goodner; Greg Carpenter
Subject: NEW Issue: Missing assertion to indicate arbitrary key pair to be used as a security token

 

PLEASE DO NOT REPLY TO THIS EMAIL OR START A DISCUSSISON THREAD UNTIL THE ISSUE IS ASSIGNED A NUMBER. 

 

The issues coordinators will notify the list when that has occurred.

 

Protocol:  ws-securitypolicy

 

http://www.oasis-open.org/apps/org/workgroup/ws-sx/download.php/20578/ws-securitypolicy-1.2-spec-ed-01-r10-diff.pdf

 

Artifact:  spec / schema

 

Type: design

 

Title: Missing assertion to indicate arbitrary RSA public key to be used as a security token

 

Description:

 

There is currently no assertion defined in security policy to indicate that an arbitrary key pair needs to be used in the message. There is class of scenarios where the sender needs to send an arbitrary public key to the recipient but such scenario cannot be currently captured by the security policy. The proposal is to add a new KeyValue token assertion to the specification.

 

Related issues:

 

None.

 

Proposed Resolution:

 

See the attached document for the proposed changes.

 

KeyValueToken.pdf



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]