← Prev in month
← Prev in thread
The need to adopt a policy framework - concerns over the current approach taken on modeling security/auth
Andrew,
Something hadn’t been sitting well with me with the
approaches you’ve taken on these two TNs
Modeling Web services Security
in UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/12217/uddi-spec-tc-tn-wssecurity-20040328.doc
Modeling HTTP Access Auth in
UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/11960/uddi-spec-tc-tn-httpauth-20050321.doc
The problem stems from the fact that we’ve yet to
adopt a policy framework for registry and the approach you’ve taken
though not strictly incorrect is only delaying what in my opinion is the
inevitable – the adoption of a policy framework for UDDI.
Had we one, we wouldn’t take the approach you’ve
taken which as far as I’m concerned is the only reasonable one for you at
this point within the current framework – or lack-thereof. That said, it
isn’t reasonable for us to delay adopting a policy framework – dare
I say WS-PolicyAttachment and WS-Policy.
I’m very concerned about making any recommendations
that should (MUST) be expressed using policy
by any other means. I think we should take a step back; finally take that bold
move and adopt WS-Policy; and recast these two TNs using
WS-Policy/PolicyAttachment.
Luc
Luc Cl幦ent | Senior Program
Manager | Systinet Corporation |
One van de Graaff Drive Burlington, MA 01803
Phone +1 781.362.1330 | Mobile +1 978.793.2162 | Fax +1 781.362.1400 |
← Prev in month
← Prev in thread