OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xri message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xri] Secure XRD Proposals


Per service signature usecase may be theoretical, but XRI resolution stands for per XRD signature usecase for an XRDS.
 
=nat

差出人: Eran Hammer-Lahav [eran@hueniverse.com]
送信日時: 2008年12月19日 6:21
宛先: Peter Davis; Brian Eaton
CC: Dirk Balfanz; Sakimura Nat; xri@lists.oasis-open.org
件名: Re: [xri] Secure XRD Proposals

Can you provide a “real world” use case?

EHL


On 12/18/08 12:50 PM, "Peter Davis" <peter.davis@neustar.biz> wrote:



On Dec 18, 2008, at 2:47 PM, Brian Eaton wrote:

> On Thu, Dec 18, 2008 at 11:25 AM, Peter Davis
> <peter.davis@neustar.biz> wrote:
>> I can see use cases for each service element being signed. This is
>> essentially the detached signature model provided in XMLDsig.
>
> What are those use cases?

circumstances where the relying party to the XRD needs to interact
with 'certified' providers of a given service, and establishing a
network connection to a bogus service is expensive/inefficient (wrt
network usage), or might otherwise cause harm to either the relying
party or the user.

In these cases, it is not sufficient to simply sign the set of
services, as there may be several certified entities (for either
identical services or different ones), and the XRD signature is too
broad in scope for such circumstances.

=peterd


---------------------------------------------------------------------
To unsubscribe from this mail list, you must leave the OASIS TC that
generates this mail.  Follow this link to all your TCs in OASIS at:
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]