[WSS4J] Question about WS STR-Transformation

Dittmann Werner <[email protected]> Tue, 13 Jan 2004 09:39:25 +0100
Newsgroups gmane.text.xml.wss4j
Message-ID <79D5F4B2D775204D9C7852EE41C547730141A551@mchh2a1e.mchh.siemens.de>
Dims, all,

while working on the STR-Transform as specified in the WSS
specification I found some unclear or incomplete statements
about the usage of the STR-Transform.

- The main specification (dated August 27) describes the usage
  of STR-TRansform for BinarySecurityToken (refer to chapter 8.3)
  as well as for SAML assertions. Tokens in a binary format are 
  wrapped in a BinarySecurityToken.

- The X.509 Profile does not specify the usage of STR-Transform
  to sign a BinarySecurityToken, instead it defines to reference
  the BST directly and sign it (refer to chapter 3.3.2). It uses
  STR-Transform for KeyIdentifier only.

- The interop specification (Scenario 7) uses STR-Transform for
  a BST

Is/was there any discssion about when to use STR-Transform, when
to use direct signature of a BST (or SAML assertion - this is also
an unclear point)...?

When we introduce STR-Transform in WSS4J we shall define when
to use it, e.g. when we use a BST and/or a KeyIdentifier etc.
IMO most users of WSS4J are not willing to dig into the 
WSS specifications just to figure it out. 

My idea is to define 2 or 3 cases that the user can control by
setting parameters in the WSDD of the WSS4J Axis drivers and 
the rest is done by WSS4J.

Any ideas?

Regards,
Werner


-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html