Search the web
Sign In
New User? Sign Up
WS-RM-Workshops · WS-RM-Workshops Discussions
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Re: [WS-Security-Workshops] Proposed updates to SC+RM scenarios doc   Message List  
Reply | Forward Message #83 of 119 |

Folks, haven’t heard much feedback from participants – is everyone ok with making these changes?

 

thanks

 


From: Kirill Gavrylyuk [mailto:kirillg@...]
Sent: Tuesday, April 05, 2005 12:52 PM
To: WS-Security-Workshops@yahoogroups.com; WS-RM-Workshops@yahoogroups.com
Subject: [WS-Security-Workshops] Proposed updates to SC+RM scenarios document

 

Based on the comments received so far on the document, we propose the following updates to the SC+RM scenarios. What do folks think?

 

  1. Ordering elements inside Security header. An issue was raised around scenarios text prescribing specific elements order inside Security header, for example requiring Timestamp to be the first element. We believe the best way to proceed is to remove any ordering requirements text from the scenarios doc – follow what WS-Security and BSP prescribes.

 

  1. SignatureConfirmation. We introduced SignatureConfirmation on the secure session initiation (RST/RSTR handshake). Given that this is a protection mechanism applicable to the entire message exchange, it would make sense to use it on all messages.

 

  1. Encrypted Signature. Scenarios document currently prescribes encrypting signatures on RST/RSTR and app messages, but not WS-RM infrastructure messages. Similar to #2, given that encrypting signature is a protection mechanism that is applicable to the entire exchange, it would make sense to either do it for all messages or not do it for any.

 

Attached is the scenarios document with the proposed changes applied, marked with change bars. thanks

 

 

 



Thu Apr 7, 2005 1:03 am

kirillg_public
Offline Offline
Send Email Send Email

Forward
Message #83 of 119 |
Expand Messages Author Sort by Date

Folks, haven't heard much feedback from participants - is everyone ok with making these changes? thanks ________________________________ From: Kirill Gavrylyuk...
Kirill Gavrylyuk
kirillg_public
Offline Send Email
Apr 7, 2005
1:04 am

Thanks Jan, ... wsse11:SignatureConfirmation from all messages, because this has no status in any current WSS specification. Secure RM needed a way to prevent...
Kirill Gavrylyuk
kirillg_public
Offline Send Email
Apr 7, 2005
8:57 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help