Uploaded image for project: 'OASIS ebXML Messaging Services TC'
  1. OASIS ebXML Messaging Services TC
  2. EBXMLMSG-97

7.11.2 X.509 tokens in Pull requests targeted to default role

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: New
    • Priority: Major
    • Resolution: Unresolved
    • Component/s: Core Spec
    • Labels:
      None

      Description

      When sending a UserMessage, the following parameter configures the use of X.509 or Username tokens on that message:

      PMode[1].Security.X509.*
      PMode[1].Security.UsernameToken.*

      This applies to the user message. So if the user message is pulled, it applies to the pulled user message, not to the pull request.

      Section 7.10 describes that Pull requests can be authorized using a secondary WS-Security header targeting the "ebms" role. This is configured using the following parameters:

      PMode.Initiator.Authorization.*

      This option is supported in AS4 (section 2.1.1) ebHandler as Authorization option 1.

      Section 7.11.2 states that PullRequests can also be secured using WS-Security tokens targeting the default "role". Section 7.10 actually has an example that contains two WS-Security headers, targeting different roles. AS4 ebHandler refers to this as Authorization Option 2. In the Core Specification it is not clear how this header is configured.

      See the next separate issue on AS4 and securing pull requests.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              pvde Pim van der Eijk
            • Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated: