Please take our Survey
logo       

Choosing A Webhost:
A web hosting service is a type of Internet hosting service that allows individuals and organizations to provide their own website accessible via the World Wide Web. Web hosts are companies that provide space on a server they own for use by their clients as well as providing Internet connectivity, typically in a data center. Web hosts can also provide data center space and connectivity to the Internet for servers they do not own to be located in their data center, called colocation. more...

AW: STR-Transform question: msg#00216

apache.webservices.fx.devel

Subject: AW: STR-Transform question

Pete,

when we did the interop tests some time ago we did not encounter
this problem. Did you check your implementation with
other interop implementations except WSS4J?

Otherweise we can disable the input c14n and make this as
a switch-on/switch-off option. In additon, STRTransform is
AFAIK not used that much, if at all, in "real-world" applications.

Regards,
Werner

> -----Ursprüngliche Nachricht-----
> Von: Pete Hendry
> [mailto:peter.hendry-aXhhQsCQISd54TAoqtyWWQ@xxxxxxxxxxxxxxxx]
> Gesendet: Dienstag, 20. September 2005 10:35
> An: wss4j-dev-28n8OjmUYWfNLxjTenLetw@xxxxxxxxxxxxxxxx
> Betreff: STR-Transform question
>
>
> I am currently performing interop testing against WSS4J with our own
> WS-Security implementation. I have come up against a couple of issues
> (with the configuration for axis - something for another
> email) but now
> have scenarios 1-6 working fine. Scenario 7 uses the STR-Transform. I
> cannot get this to work and have traced the WSS4J
> STRTransform class to
> work out why.
>
> The algorithm described in section 8.3 of the WS-Security
> specification
> for STR-Transform is a little unclear about how the C14N
> algorithm is to
> be applied. It implies that it possibly should be applied to
> the input
> node *before* the rest of the algorithm is applied. WSS4J
> appears to use
> this interpretation. The STRTransform class first runs the
> input through
> the Canonicalizer and then follows the STRTransform processing rules
> which end with the result again being run through the Canonicalizer.
> However, I do not believe that was the intention of the algorithm. It
> should only Canonicalize the output node.
>
> There is an errata for this very issue which clarifies this point. It
> states that
>
> ------
> Lines 1034-1036 of WSS 1.0 state:
> "The transform takes a single mandatory parameter, a
> <ds:CanonicalizationMethod> element, which is used to
> serialize the input
> node set."
>
> should be
>
> "The transform takes a single mandatory parameter, a
> <ds:CanonicalizationMethod> element, which is used to
> serialize the output
> node set."
>
> Line 1056 of WSS 1.0 states:
> "process the dereferenced node set Ri' instead."
>
> should be
>
> "process the dereferenced node set Di' instead."
> -------
>
> I believe the WSS4J STRTransform is incorrectly C14Ning the
> input node
> when it should only C14N the output node. This is causing my interop
> test to fail.
>
> Pete
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail:
> wss4j-dev-unsubscribe-28n8OjmUYWfNLxjTenLetw@xxxxxxxxxxxxxxxx
> For additional commands, e-mail:
> wss4j-dev-help-28n8OjmUYWfNLxjTenLetw@xxxxxxxxxxxxxxxx
>
>


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
qplus.devel/200...    network.jabber....    debian.qa-packa...    encryption.gpg....    python.dabo.dev...    uclinux.devel/2...    science.mathema...    recreation.pesc...    kernel.ck/2004-...    mozilla.devel.e...    tex.latex.prosp...    ietf.multi6/200...    bbc.cvs/2002-11...    xfree86.newbie/...    jakarta.taglibs...    altlinux.hardwa...    comedi/2002-05/...    horde.bugs/2004...    games.diplomacy...    finance.e-gold....    web.dom.test-su...    lang.ruby.rails...    os.netbsd.devel...    video.gstreamer...   
Home | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe

Navigation