← Prev in month ← Prev in thread

[OASIS Issue Tracker] (EBXMLMSG-86) Confusion about Content-Type for compressed and encrypted payloads

From
OASIS Issues Tracker <>
Date
2015-07-24T13:24:03+00:00
ID
Thread
[OASIS Issue Tracker] (EBXMLMSG-86) Confusion about Content-Type for compressed and encrypted payloads
Sander Fieten created EBXMLMSG-86:
-------------------------------------

             Summary: Confusion about Content-Type for compressed and encrypted payloads
                 Key: EBXMLMSG-86
                 URL: https://issues.oasis-open.org/browse/EBXMLMSG-86
             Project: OASIS ebXML Messaging Services TC
          Issue Type: Improvement
          Components: AS4 Profile
            Reporter: Sander Fieten


On line 262 (PDF version) of the AS4 profile it is stated that "The content type of the compressed attachment MUST be "application/gzip"."

This suggests that for compressed payloads the Content-Type should always be "application/gzip".

On lines 266-267 however it is also stated that  "When compression, signature and encryption are required, any attached payload(s) MUST be compressed prior to being signed and/or encrypted" 

This implies that the rules of the WS-Security SwA profile must be applied after compression. As a result the Content-Type header must be changed to "application/octet-stream"

In the AS4 profile this should be made clear. 



--
This message was sent by Atlassian JIRA
(v6.2.2#6258)
← Prev in month ← Prev in thread