Next in thread →
Next in month →
RE: [wss] Interesting article this morning...
WSS "run-time" and "configuration-/design-time" specification of Web Service security can be accomplished in overlapping time-periods, with perhaps the former lagging the latter by a few months - and possibly in distinct but related working groups/TCs. However, to succeed in doing so, I agree, that we need to view this as an opportunity of developing a standards solution where there are admittedly dependencies (which can be managed). This is what I hope we can discuss in tomorrow's OASIS WSS-QoP tele-meeting. thanks, Zahid -----Original Message----- From: Hallam-Baker, Phillip [mailto:] Sent: Thursday, October 10, 2002 12:38 PM To: Mishra, Prateek; 'Hallam-Baker, Phillip'; 'Oasis Web Services Security' Cc: Subject: RE: [wss] Interesting article this morning... Prateek, I don't dispute the points you raise. I think we really have to address the QoP issue. However I do not think that that specification is supject to extreeme time pressure the way that WS-Security is. There are many issues we have to address before we have a complete set of infrastructure for Web Services, the other elements of the roadmap for one, QoP, Key Agreement, Timestamp etc. etc. Heck I'll even go for non-repudiation eventually! What concerns me is when a spec is on the critical path of another. Like the situation with PKIX which held up S/MIME for several years. Really what we are arguing about is whether we want to wait until QoP is on the critical path to act, that certainly would be a bad thing. Trying to do a spec that is on critical path gets really quite iffy. Phill ---------------------------------------------------------------- To subscribe or unsubscribe from this elist use the subscription manager: <http://lists.oasis-open.org/ob/adm.pl>
Next in thread →
Next in month →