OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

wss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Limiting SwA references to CID form?


I would like to confirm whether the WSS SwA profile should support signature references to SwA attachments using Content-Location.
 
Currently the profile allows references using CID scheme URLs as well as URLs that resolve to Content-Location headers in the attachments.
 
The question is whether the profile should restrict references to only CID scheme URLs. Note that this would require attachments to use Content-Id if they are to be signed, impacting other references  from the primary SOAP envelope as well.
 
The reasons in favor of only allowing CID references is that it simplifies the profile, avoiding issues related to URL resolution for Content-Location, possible external redirects etc, and reducing the number of choices. An argument against is that Content-Location may be in use, and is allowed by the SOAP Messages with Attachments specification [1] and is not disallowed by the WS-I Attachment Profile [2]. Note however that SwA strongly encourages use of CIDs.
 
I believe the WSS interops have only included CID scheme references.
 
Does anyone on these lists have a requirement to use Content-Location, or to put it another way, does anyone have an objection to disallowing Content-Location references for signed SwA attachments, and for requiring use of CID scheme URLs?
 
We have these choices: 1) require CID references in the WSS SwA profile 2) Restrict to CID references in the WS-I Basic Security Profile of the WSS SwA profile, or 3) allow both CID and Content-Location references generally
 
Unless there is a strong need, #1 may be best, but we need to determine whether this is appropriate given existing deployments.
 
Please indicate to the list if Content-Location support is necessary for your applications, or guidance on this issue.
 
Thanks

regards, Frederick

Frederick Hirsch
Nokia

[1]  http://www.w3.org/TR/SOAP-attachments#SOAPMultipart
 
[2] http://www.ws-i.org/Profiles/AttachmentsProfile-1.0-2004-08-24.html
 


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]