Re: T2 Minor Inconsistency in Section 12.2

From
Brvola Dhan
Date
2001-07-30T03:35:09+00:00
ID
00a001c11897$9f0de1e0$
Thread
Re: T2 Minor Inconsistency in Section 12.2
Marty:

I am referring to the following sub-section from the Messaging 
Service spec:

12.2 Collaboration Protocol Agreement

The configuration of Security for MSHs may be specified in the 
CPA. Three 
areas of the CPA have security definitions as follows:

· The Document Exchange section addresses 
security to be applied to the payload of the message. The MSH is not responsible 
for any security specified at this level but may offer these services to the 
message sender.

· The Message section addresses security 
applied to the entire ebXML Document, which includes the header and the 
payload.

----- Original Message ----- 

From: "Martin W Sachs" <>

To: "Arvola Chan" <>

Cc: "ebXML Msg" <>

Sent: Sunday, July 29, 2001 7:18 PM

Subject: Re: T2 Minor Inconsistency in Section 
12.2

Arvola,

Unfortunately there are three different "versions" of 
version 1.0 in
circulation:  The copy approved on May 10, the slightly 
reformatted copy,
and the more recent reformatted copy.  Apparently the 
line numbering does
not agree among them.

Please re-post this comment, 
referring to the section number.

Everyone, if you refer to line numbers, 
please be sure you are looking at
the original approved version(labelled 
"normative document" on the ebXML
web site). It would be safest always to 
include section numbers in 
your
comments.

Regards,
Marty

*************************************************************************************

Martin 
W. Sachs
IBM T. J. Watson Research Center
P. O. B. 704
Yorktown Hts, NY 
10598
914-784-7287;  IBM tie line 863-7287
Notes address:  
Martin W Sachs/Watson/IBM
Internet address:  mwsachs @ 
us.ibm.com
*************************************************************************************

Arvola 
Chan <> on 07/26/2001 
07:14:26 PM

To:   ebXML Msg <>
cc:
Subject:  T2 Minor Inconsistency in Section 
12.2

Line 1978 talks about three areas of the CPA that  
have security
definitions. This is followed by only two bullets.

The 
first bullet says "The MSH is not  responsible for any 
security
specified at this level but may offer these  services to the 
message
sender". This seems contradictory. If the MSH offers  these 
services, isn't
it responsible for doing the necessary encryption and  
decryption? What
does "not responsible for any security specified at this 
level"  really
mean?

The second bullet refers to a Message 
section in  the CPA. No such section
can be found in the schema 
(Appendix D in the CPPA  
spec).

-Arvola

------------------------------------------------------------------
To 
unsubscribe from this elist send a message with the single word
"unsubscribe" 
in the body to: