> Could you provide a simple example with a paramter from each category ?
Sure
1. Parameter set by server: type of document returned (e.g.,
WS-Security, or just the signature, or a signed document)
2. Parameter with server default: what canonicalization to use
3. Parameter client can specify: A "validity period" for
the signature.
4. Parameter client must specify: which key (of the ones that the
client is authorized to use) to use for signing
Now, as I look at it, I think #2 and #3 might be the same thing.
I was trying to distinguish between "there is a default that will be
applied if the client doesn't specify the parameter" versus "optional
behavior that will not be done if the client doesn't specify the
parameter."
/r$
--
Rich Salz Chief Security Architect
DataPower Technology http://www.datapower.com
XS40 XML Security Gateway http://www.datapower.com/products/xs40.html
XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html