Re: Review - Web Services Security: SOAP Message Security (1 of 3)

"Jean-Jacques Moreau" <[email protected]>
Newsgroups gmane.text.xml.distributed
Organization Canon Research Centre France
Message-ID <[email protected]>
Great review! I have one comment only. JJ.

Marc Hadley wrote:

> *** 410 "The <wsse:Security> header block without a specified S:role  
> MAY be consumed by anyone, but MUST NOT be removed prior to the final  
> destination or endpoint." What does 'consumed' mean. SOAP 1.2 makes it  
> clear that SOAP headers without a role attribute are equivalent to  
> those with a role of  
> "http://www.w3.org/2003/05/soap-envelope/role/ultimateReceiver". In  
> both cases the ultimate receiver of the message is the target of the  
> header block.

An active intermediary could still consume the header block; this 
is part of the processing model. So, unless WSS includes a 
special header block to implement the above assertion, it cannot 
be fulfilled, I think.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.