Prateek,
I don't dispute the points you raise. I think we really have to
address the QoP issue. However I do not think that that specification is
supject to extreeme time pressure the way that WS-Security is.
There are many issues we have to address before we have a complete
set of infrastructure for Web Services, the other elements of the roadmap
for one, QoP, Key Agreement, Timestamp etc. etc. Heck I'll even go for
non-repudiation eventually!
What concerns me is when a spec is on the critical path of another.
Like the situation with PKIX which held up S/MIME for several years.
Really what we are arguing about is whether we want to wait until
QoP is on the critical path to act, that certainly would be a bad thing.
Trying to do a spec that is on critical path gets really quite iffy.
Phill