RE: [security-services] Editorial comment (or issue?) on core-31

From
PATO,JOE (HP-PaloAlto,ex1) <>
Date
2002-04-15T20:15:59+00:00
ID
Thread
RE: [security-services] Editorial comment (or issue?) on core-31
I agree that this appears to be a clear cut&paste error and one we would
have corrected via an errata sheet after the specs are published. I would
like to have the committee confirm this tomorrow to be an editorial change
rather than a normative change.

- joe

> -----Original Message-----
> From: Eve L. Maler [mailto:]
> Sent: Monday, April 15, 2002 3:15 PM
> Cc: 
> Subject: Re: [security-services] Editorial comment (or issue?) on
> core-31
> 
> 
> I consider this a pretty obvious editorial error that most readers of 
> the spec would ultimately catch.  I have no problem with our 
> fixing it...
> 
> 	Eve
> 
> Philpott, Robert wrote:
> > I just noticed this one a few minutes ago...
> > 
> > Line 1262 of core-31 says the IssueInstant of a RESPONSE is 
> the "time 
> > instant of issue of the REQUEST".  I really do believe this 
> is a cut and 
> > paste error and should really be the "time issue instant of the 
> > response".   It really does change the normative meaning of the 
> > definition so it's not quite just an editorial change.
> > 
> > What harm will occur if this is left as-is for V1.0?  As 
> far as I can 
> > recall, we specify no processing requirements in the spec for the 
> > IssueInstant.  If that's the case, then there probably is 
> no harm in 
> > leaving it and fixing it in V1.1.
> > 
> > But if an authority uses the response creation time, then and some 
> > relying party incorrectly assumes that it is supposed to be 
> the response 
> > instant of the corresponding request, then it might decide 
> to reject the 
> > response because of a mismatch.
> > 
> > Thoughts?
> 
> 
> -- 
> Eve Maler                                    +1 781 442 3190
> Sun Microsystems XML Technology Center   eve.maler @ sun.com
> 
> 
> ----------------------------------------------------------------
> To subscribe or unsubscribe from this elist use the subscription
> manager: <http://lists.oasis-open.org/ob/adm.pl>
>