OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

wss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [wss] SwA profile Issue 364 action for TC members


 
>I don't think WSS should define any MUST's; that's WS-I's job.

I think I have to disagree with your definition of the division of responsibility between the OASIS TC and the WS-I BSP WG.  In fact there are lots and lots of places where the OASIS WSS specifications say you MUST do something.  And there are several places where even WS-I has decided to not enforce a MUST.

> Why?  It doesn't specify a single interoperable mandatory-to-implement signing mechanism or security token.

This may be true but the choice of security token is a well-defined extensibility point of WSS that is there to permit different applications to agree on one or more tokens that they will use.  

Are you proposing this should be an SwA extensibility point?  If so what are the alternate choices?


/paulc


________________________________

From: Rich Salz [mailto:rsalz@datapower.com]
Sent: Sat 07/05/2005 5:31 PM
To: Brian LaMacchia
Cc: Frederick.Hirsch@nokia.com; wss@lists.oasis-open.org
Subject: RE: [wss] SwA profile Issue 364 action for TC members



> What do you believe should be the mandatory-to-implement processing
> behavior for XML attachments?

I don't think WSS should define any MUST's; that's WS-I's job.

> The SwA profile needs to specify a
> single, interoperable, mandatory-to-implement behavior for processing
> XML attachments that does not depend on any knowledge about the behavior
> of intermediaries.

Why?  It doesn't specify a single interoperable mandatory-to-implement
signing mechanism or security token.

        /r$

--
Rich Salz                  Chief Security Architect
DataPower Technology       http://www.datapower.com
XS40 XML Security Gateway  http://www.datapower.com/products/xs40.html


---------------------------------------------------------------------
To unsubscribe from this mail list, you must leave the OASIS TC that
generates this mail.  You may a link to this group and all your TCs in OASIS
at:
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]