[WSS4J] Question about WS STR-Transformation
Dittmann Werner <[email protected]> Tue, 13 Jan 2004 09:39:25 +0100
| Newsgroups | gmane.text.xml.wss4j |
|---|---|
| Message-ID | <79D5F4B2D775204D9C7852EE41C547730141A551@mchh2a1e.mchh.siemens.de> |
Dims, all, while working on the STR-Transform as specified in the WSS specification I found some unclear or incomplete statements about the usage of the STR-Transform. - The main specification (dated August 27) describes the usage of STR-TRansform for BinarySecurityToken (refer to chapter 8.3) as well as for SAML assertions. Tokens in a binary format are wrapped in a BinarySecurityToken. - The X.509 Profile does not specify the usage of STR-Transform to sign a BinarySecurityToken, instead it defines to reference the BST directly and sign it (refer to chapter 3.3.2). It uses STR-Transform for KeyIdentifier only. - The interop specification (Scenario 7) uses STR-Transform for a BST Is/was there any discssion about when to use STR-Transform, when to use direct signature of a BST (or SAML assertion - this is also an unclear point)...? When we introduce STR-Transform in WSS4J we shall define when to use it, e.g. when we use a BST and/or a KeyIdentifier etc. IMO most users of WSS4J are not willing to dig into the WSS specifications just to figure it out. My idea is to define 2 or 3 cases that the user can control by setting parameters in the WSDD of the WSS4J Axis drivers and the rest is done by WSS4J. Any ideas? Regards, Werner ------------------------------------------------------- This SF.net email is sponsored by: Perforce Software. Perforce is the Fast Software Configuration Management System offering advanced branching capabilities and atomic changes on 50+ platforms. Free Eval! http://www.perforce.com/perforce/loadprog.html