Andrew: please consider the attached –
a document I put together hurriedly so please excuse the flaws. I disagree that
your mapping is consistent with PolicyAttachment – albeit it is close. Let’s
review your approach and compare it with the attached. I think we will find
divergence in the approach.
Can we discuss this tomorrow during the
call?
Luc
From: Rogers, Tony
[mailto:]
Sent: Monday, May 23, 2005 15:58
To: Andrew Hately; Luc Clement
Cc:
Subject: RE: [uddi-spec] The need
to adopt a policy framework - concerns over the current approach taken on
modeling security/auth
We definitely need a liaison with the WS Policy WG. Is anyone in the TC
also in WS Policy?
Tony
-----Original
Message-----
From: Andrew Hately
[mailto:]
Sent: Tue 24-May-05 2:30
To: Luc Clement
Cc:
Subject: Re: [uddi-spec] The need
to adopt a policy framework - concerns over the current approach taken on
modeling security/auth
>>
I’m
very concerned about making any recommendations that should (MUST) be expressed
using policy by any other means.
I think we should take a step back; finally take that bold move and adopt
WS-Policy; and recast these two TNs using WS-Policy/PolicyAttachment.
<<
Regardless
of the framework, one of the challenges is that these Technical Notes are
proposing composable/reusable policy pieces. I believe they are
compatible with WS-Policy as they exist today and we would just need to
reference WS-Policy files and we should probably do so. If you are
proposing something deeper in terms of policy framework integration such as
changing the concept of UDDI searching to be based on something deeper than
tModel concept searches, we should discuss this tommorow.
In
my opinion the challenge is not picking the framework or language, it is
getting these reviewed by people who can articulate if we've got the write
reusable policy pieces that would be composable.
Should
we form a liasion with the W3C policy working group to move this forward?
Regards,
Andrew Hately
IBM Software Group, Emerging Technologies
"Luc Clement"
<>
05/22/2005 10:18 PM
To
Andrew Hately/Austin/IBM@IBMUS
cc
<>
Subject
[uddi-spec] The need to adopt a policy
framework - concerns over the current approach taken on modeling
security/auth
Andrew,
Something
hadn’t been sitting well with me with the approaches you’ve taken
on these two TNs
Modeling Web services Security in UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/12217/uddi-spec-tc-tn-wssecurity-20040328.doc
Modeling HTTP Access Auth in UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/11960/uddi-spec-tc-tn-httpauth-20050321.doc
The
problem stems from the fact that we’ve yet to adopt a policy framework
for registry and the approach you’ve taken though not strictly incorrect
is only delaying what in my opinion is the inevitable – the adoption of a
policy framework for UDDI.
Had
we one, we wouldn’t take the approach you’ve taken which as far as
I’m concerned is the only reasonable one for you at this point within the
current framework – or lack-thereof. That said, it isn’t reasonable
for us to delay adopting a policy framework – dare I say
WS-PolicyAttachment and WS-Policy.
I’m
very concerned about making any recommendations that should (MUST) be expressed
using policy by any other means.
I think we should take a step back; finally take that bold move and adopt
WS-Policy; and recast these two TNs using WS-Policy/PolicyAttachment.
Luc
Luc Cl幦ent | Senior Program Manager | Systinet Corporation |
One van
de Graaff Drive Burlington,
MA 01803
Phone +1 781.362.1330 | Mobile
+1 978.793.2162 | Fax +1 781.362.1400 |
Proposed framework for policy in UDDI.doc