AW: [WSS4J] Question about WS STR-Transformation
Dittmann Werner <[email protected]> Wed, 14 Jan 2004 08:25:56 +0100
| Newsgroups | gmane.text.xml.wss4j |
|---|---|
| Message-ID | <79D5F4B2D775204D9C7852EE41C547730141A555@mchh2a1e.mchh.siemens.de> |
Dims,
thanks for the link. Now some points got
more clear, in particular that STR Transform shall
work for all reference types. At least Merlin's
test vectors show that.
While looking at the test vectors I also found
use cases that are not yet covered in WSS4J.
E.g. including the security token, e.g. X509
certificate in the message and reference it
with X509IssuerSerial. This is IMO good for testing
but not so usefull in "real" live - having a signed
X509IssuerSerial information is enough to get the
correct certificate from some certificate store.
Now I have to see how to incorporate the STR Transform
into WSS4J in the flexible and controllable manner, but
as always its a "SMOP" (Small Matter Of Programming) :-).
Some questions about the STR Transform implementation
are still open:
- does the result of the STR Transform replaces the
whole SecurityTokenReference element including its
descendants or does it replace only the relevant
reference elements inside the STR, e.g. Reference
or X509IssuerSerial and their descendants, and leave
the STR element untouched?
IMO thats not very clear from the specs. Examples would
be helpful :-) (similar to those in the c14n
specs).
- if STR Transform is applied to e.g. an X509IssuerSerial
reference we have to distinguish two main cases:
a) the X509 certificate is included in the message as
BinarySecurityToken
b) the X509 certificate is in some certificate store.
While performing the STR Transform, then for
´
Case a): replace the relevant SecurityToken
element with the BST directly without modification.
(This is clearly specified. However, there were some
discussion if the the token shall be decoded into
binary data or left as Base64 encoded data.)
Case b): wrap the "binary data" in a BST. AFAIK X509
certificates an be represented in several ways as
"binary data": ASN.1 encoded, PKCS format, maybe others.
IMO, its not enough to just state "binary data", in most
cases some more specification is necessary.
Regards,
Werner
> -----Ursprüngliche Nachricht-----
> Von: Davanum Srinivas [mailto:dims-/[email protected]]
> Gesendet: Dienstag, 13. Januar 2004 14:13
> An: Dittmann Werner; [email protected]
> Betreff: Re: [WSS4J] Question about WS STR-Transformation
>
>
> Werner,
>
> by the time i joined the WSS-TC things had already
> solidified, can you browse the archives and let
> me know specific questions that i can post the list that
> would be great...
>
> http://www.google.com/search?q=STR-TRANSFORM+site%3Alists.oasi
> s-open.org
>
> Thanks,
> dims
>
> --- Dittmann Werner <[email protected]> wrote:
> > Dims, all,
> >
> > while working on the STR-Transform as specified in the WSS
> > specification I found some unclear or incomplete statements
> > about the usage of the STR-Transform.
> >
> > - The main specification (dated August 27) describes the usage
> > of STR-TRansform for BinarySecurityToken (refer to chapter 8.3)
> > as well as for SAML assertions. Tokens in a binary format are
> > wrapped in a BinarySecurityToken.
> >
> > - The X.509 Profile does not specify the usage of STR-Transform
> > to sign a BinarySecurityToken, instead it defines to reference
> > the BST directly and sign it (refer to chapter 3.3.2). It uses
> > STR-Transform for KeyIdentifier only.
> >
> > - The interop specification (Scenario 7) uses STR-Transform for
> > a BST
> >
> > Is/was there any discssion about when to use STR-Transform, when
> > to use direct signature of a BST (or SAML assertion - this is also
> > an unclear point)...?
> >
> > When we introduce STR-Transform in WSS4J we shall define when
> > to use it, e.g. when we use a BST and/or a KeyIdentifier etc.
> > IMO most users of WSS4J are not willing to dig into the
> > WSS specifications just to figure it out.
> >
> > My idea is to define 2 or 3 cases that the user can control by
> > setting parameters in the WSDD of the WSS4J Axis drivers and
> > the rest is done by WSS4J.
> >
> > Any ideas?
> >
> > Regards,
> > Werner
> >
> >
> > -------------------------------------------------------
> > This SF.net email is sponsored by: Perforce Software.
> > Perforce is the Fast Software Configuration Management
> System offering
> > advanced branching capabilities and atomic changes on 50+ platforms.
> > Free Eval! http://www.perforce.com/perforce/loadprog.html
> > _______________________________________________
> > wss4j-devel mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/wss4j-devel
>
>
> =====
> Davanum Srinivas - http://webservices.apache.org/~dims/
>
-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html