Version 83, Modified on Tuesday, 15 November 2005 11:01:46 AM -0000
The previous version of the issues list (Version 82) is at http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14858/OASIS%20Web%20Services%20Security%20Issues%20List%2082.htm . An archive of the discussion list can be found here: http://lists.oasis-open.org/archives/wss/.
If you identify items that are missing or need correction please contact Vijay Gajjala.
Links to issue categories :
| Open issues requiring discussion by the TC |
| Pending issues requiring editors to incorporate resolutions and upload updated documents |
| Pending Review issues requiring TC review of documents and subsequent closure |
|
338 |
Technical |
Open |
Hal: Proposed new work - WSS Templates |
http://lists.oasis-open.org/archives/wss/200410/msg00060.html
No change in status in the last meeting. |
TC |
| 444 | Process | Pending | Request to remove the WS-Security 1.0 errata from WSS page or fix it |
http://lists.oasis-open.org/archives/wss/200509/msg00112.html
Status: 2005-10-04: Editors to provide an updated errata page with the X.509 token URI that ends with #X509 replaced with a URI that ends with #X509v1 Status: 2005-10-18: After e-mail from Thomas http://lists.oasis-open.org/archives/wss/200510/msg00037.html TC instructed editor's to ensure changes in http://lists.oasis-open.org/archives/wss/200503/msg00025.html are present in the errata. This subsumes the status from 2005-10-04. |
Editors |
|
WSS ID |
Type |
Status |
Issue |
Resolution |
Owner(s) |
|
3 |
Technical |
Closed, Duplicate of 67? |
Proposal to Label Tokens to Indicate Their Semantics |
F2F Topic - Ronald Monzillo and
Anthony Nadalin will send out a proposed set of changes. |
Closed |
|
14 |
Technical |
Closed |
State that the recipient SHOULD authenticate the assertion issuer and ensure that the assertion has not been modified |
http://lists.oasis-open.org/archives/wss/200212/msg00037.html
|
Closed |
|
28 |
Technical |
Closed |
SAML Binding: Include the use of the URI attribute (on SecurityTokenReference) from the SS TC submission |
http://lists.oasis-open.org/archives/wss/200302/msg00017.html |
Closed |
|
29 |
Technical |
Closed |
SAML Binding: Should there be a reference form that carries what amounts to a SAML assertion Query such that the sender does not need to have acquired the assertion (to be able to apply it to a request)? |
http://lists.oasis-open.org/archives/wss/200212/msg00037.html |
Closed |
|
30 |
Technical |
Closed |
How should XML be explained. |
http://lists.oasis-open.org/archives/wss/200306/msg00025.html.
|
Closed |
|
35 |
Technical |
Closed, Related to 290? |
Is it necessary to support the HexBinary encoding of tokens? |
Closed in Draft 4 of Core
specs. |
Closed |
|
44 |
Technical |
Closed |
SAML Cannonicalization |
http://lists.oasis-open.org/archives/wss/200212/msg00037.html |
Closed |
|
53 |
Technical |
Closed for v1 Open (post-v1) |
Section 6.1 Usernames and
Passwords, beginning at line 422, defines the use of the <wsse:UsernameToken> element "as a way of
providing a username and optional password information". The definition
of this token makes no mention of its potential value in defining the key to
support the signing or encryption of the attached SOAP message. I
realize that the |
http://lists.oasis-open.org/archives/wss/200301/msg00073.html
|
Closed |
|
59 |
Technical |
Closed |
Various editorial comments on XrML binding |
http://lists.oasis-open.org/archives/wss/200302/msg00019.html
|
Closed |
|
63 |
Technical |
Closed |
XML Token Wrapper |
http://lists.oasis-open.org/archives/wss/200302/msg00017.html |
Closed |
|
67 |
Technical |
Closed |
Resolve usage labels. |
http://lists.oasis-open.org/archives/wss/200306/msg00025.html Hal to begin editing a Usage Label document, which may transition into a
profile. |
Closed |
|
84 |
Technical |
Close |
Comment on Core Spec and Interop
Scenario #3 - Decryption Transform. Ordering semantics of the <wsse:Security> header can not
be used in all cases to determine the encryption and signature ordering.
Perhaps we should require use of the Decryption Transform on all |
Hal has written an email: http://www.oasis-open.org/archives/wss/200305/msg00022.html Needs to be reviewed. Hal proposed text for issue: http://lists.oasis-open.org/archives/wss/200306/msg00003.html
. Tony to propose edits and/or provide history. Status: This was not resolved completely. Latest draft ( |
Close |
|
86 |
Technical |
Closed |
Non-repudiation proposal to be included as part of WS-Security. |
http://lists.oasis-open.org/archives/wss/200304/msg00016.html. Resolution: Defer till after v1. Resolution date:
Jun-17-03. |
Closed |
|
87 |
Technical |
Closed |
Add a profile for XKMS to WS-Security. |
Currently no owner for this. |
Closed |
|
92 |
Technical |
Closed |
Should we support "multiple recipient" case for encryption? A possible use of multiple EncryptedKey elements in different security headers is to enable multiple roles, possessing distinct private asymmetric keys, to get access to the same data, encrypted with the same symmetric key. In this scenario, the intermediary, should perform the decryptions indicated in the Security header labeled with its role, passing the result to its local application. The problem is there is no way to distinguish this case versus Super encryption case where multiple encryption headers might also exist. |
http://lists.oasis-open.org/archives/wss/200305/msg00022.html
not a separate issue, part of the order of decryption issue. No one
commented. |
Closed |
|
103 |
Editorial |
Closed |
ValueType attribute: docs should state "ValueType attribute is RECOMMENDED for BinarySecurityToken and RECOMMENDED for Reference with non-local URI". Rework the example in 7.2. |
Merlin: http://lists.oasis-open.org/archives/wss/200306/msg00088.html
|
Closed |
|
127 |
Technical |
Closed |
Peter Dapkus: Spec should address the issue of non-visibly used namespaces |
http://lists.oasis-open.org/archives/wss/200307/msg00070.html Resolution: Consensus on two points: http://lists.oasis-open.org/archives/wss/200311/msg00058.html |
Closed |
|
165 |
Technical |
Closed |
Passing binary data in SAML Assertion Token |
http://lists.oasis-open.org/archives/wss-comment/200309/msg00000.html |
Closed |
|
196 |
Editorial |
Closed |
WSS:
Soap message security: General: Also, why use qualified names instead of URIs for identifying encoding types. Ron: editors |
W3C XMLP WG Feedback http://lists.oasis-open.org/archives/wss-comment/200310/msg00016.html TC to review http://lists.oasis-open.org/archives/wss/200311/msg00016.html Too late to accommodate with changes. In the last two calls we have had unanimous agreement to not address this in V1 (if at all -- needs further research) TC voted to switch to URIs. |
Closed |
|
242 |
Editorial |
Closed |
Update SAML profile to use new URLs |
Editors to make this change |
Closed |
|
243 |
Editorial |
Closed |
Update XrML profile to use new URLs |
Editors to make this change |
Closed |
|
244 |
Editorial |
Closed |
Update Kerberos profile to use new URLs |
Editors to make this change |
Closed |
|
245 |
Editorial |
Closed |
Rename SAML profile document |
Editors to make this change |
Closed |
|
246 |
Editorial |
Closed |
Rename XrML profile document |
Editors to make this change |
Closed |
|
247 |
Editorial |
Closed |
Rename Kerberos profile document |
Editors to make this change |
Closed |
|
249 |
Technical |
Closed |
the saml token profile depends on non-global attributes in keyidentifier/wsse schema does not support keyIdentifier element extensibility - |
http://lists.oasis-open.org/archives/wss/200401/msg00120.html Resolution: |
Closed |
|
250 |
Technical |
Closed |
Should ValueType attribute of STR reference element be moved to top level STR definition? - post v1 review period |
http://lists.oasis-open.org/archives/wss/200401/msg00121.html
|
Closed |
|
251 |
Technical |
Closed |
keyIdentifier valuetypes of Username and X509 profiles are defined relative to wsse schema - post v1 review period |
http://lists.oasis-open.org/archives/wss/200401/msg00122.html
|
|
|
252 |
Editorial |
Closed |
Trivial editorial bug on SOAP Message Security - post v1 review period |
http://lists.oasis-open.org/archives/wss/200401/msg00117.html |
Closed |
|
253 |
Editorial |
Closed |
minor editorial comment on SOAP Message Security - post v1 review period |
http://lists.oasis-open.org/archives/wss/200401/msg00116.html |
Closed |
|
254 |
Editorial |
Closed |
comments on core spec- Line 853 (Table) Soap message
security 011504 - merged: |
http://lists.oasis-open.org/archives/wss/200401/msg00104.html
Resolution: Move to Errata |
Closed |
|
255 |
Editorial |
Closed |
Editorial comments on core spec - post v1 review period |
http://lists.oasis-open.org/archives/wss/200401/msg00101.html |
Closed |
|
256 |
Technical |
Closed |
STR attributes are not protected. |
http://lists.oasis-open.org/archives/wss/200402/msg00042.html
|
Closed |
|
257 |
Technical |
Postponed Duplicate |
STR attrubutes are not protected |
http://lists.oasis-open.org/archives/wss/200402/msg00042.html |
Closed |
|
259 |
Editorial |
Closed |
Editorial comments on Username Token profile - post v1 review period. |
http://lists.oasis-open.org/archives/wss/200401/msg00113.html |
Closed |
|
260 |
Editorial |
Closed |
Editorial comments on X.509 Token profile - post v1 review period. |
http://lists.oasis-open.org/archives/wss/200401/msg00114.html
|
Closed |
|
261 |
Editorial |
Closed |
How do we handle the sender voucher scenario for SAML |
http://lists.oasis-open.org/archives/wss/200402/msg00034.html
|
Closed |
|
262 |
Editorial |
Closed |
Comments on sender voucher signed section in SAML interop draft. |
http://lists.oasis-open.org/archives/wss/200402/msg00032.html Resolution: document ok until SAML discussions require change. http://lists.oasis-open.org/archives/wss/200402/msg00042.html |
Closed |
|
263 |
Technical |
Closed |
Open enumerations - post v1 review period. |
http://lists.oasis-open.org/archives/wss/200402/msg00011.html |
Closed |
|
264 |
Editorial |
Closed |
Post review period comments: Errors in WSS core and username/x.509 profile examples. |
http://lists.oasis-open.org/archives/wss/200403/msg00034.html Resolution: Editors placed text in Errata |
Closed |
|
265 |
Technical |
Closed |
Encryption of wsse: security header |
http://lists.oasis-open.org/archives/wss/200403/msg00011.html
|
Closed |
|
266 |
Technical |
Closed |
Manesh: Are AttributeStatements
the only statements pertinent to the SAML TP? |
http://lists.oasis-open.org/archives/wss/200403/msg00074.html |
Closed |
|
267 |
Editorial |
Closed |
Typos in Sender-Vouches and Holder-of-Key examples listed in Saml interop document. |
http://lists.oasis-open.org/archives/wss/200404/msg00007.html |
Closed |
|
268 |
Technical |
Closed |
How do we secure SOAP attachments? |
http://lists.oasis-open.org/archives/wss/200404/msg00004.html
|
Closed |
|
269 |
Editorial |
Closed |
Need clarification on the URIs for type attributes. |
http://lists.oasis-open.org/archives/wss/200404/msg00034.html |
Closed |
|
270 |
Process |
Closed |
Comments from Wells Fargo: support from SAML 1.1 token profile |
http://lists.oasis-open.org/archives/wss/200404/msg00054.html |
Closed |
|
271 |
Technical |
Closed |
Comments from Wells Fargo: Username token does not provide a mechanism for indicating its type or domain |
http://lists.oasis-open.org/archives/wss/200404/msg00054.html
|
Closed |
|
272 |
Editorial |
Closed |
SAML interop scenario doc should use 1.1 for version. |
http://lists.oasis-open.org/archives/wss/200404/msg00061.html |
Closed |
|
273 |
Technical |
Closed |
Should we have conditions in SAML tokens? Should their presence indicate that they should always be processed? |
http://lists.oasis-open.org/archives/wss/200404/msg00061.html
|
Closed |
|
274 |
Technical |
Closed |
Format attribute vs NameQualifier attribute of NameIdentifier |
http://lists.oasis-open.org/archives/wss/200404/msg00061.html |
Closed |
|
275 |
Editorial |
Closed |
SAML token profile, Interop - dateTime formats - need clarification |
http://lists.oasis-open.org/archives/wss/200404/msg00076.html |
Closed |
|
276 |
Editorial |
Closed |
Problem with document URLs |
http://lists.oasis-open.org/archives/wss/200404/msg00082.html |
Closed |
|
277 |
Technical |
Closed |
Kerberos profile: Ticket granting ticket should be removed from Kerberos profile |
http://lists.oasis-open.org/archives/wss/200404/msg00093.html
|
Closed |
|
278 |
Technical |
Closed |
Kerberos profile: Deriving Session Keys from master secret |
http://lists.oasis-open.org/archives/wss/200404/msg00094.html
|
Closed |
|
279 |
Technical |
Closed |
XrML: Multiple grants |
http://lists.oasis-open.org/archives/wss/200404/msg00097.html
|
Closed |
|
280 |
Process |
Closed |
What if any IP issues apply for SAML interop? |
http://lists.oasis-open.org/archives/wss/200405/msg00001.html
|
Closed |
|
281 |
Editorial |
Closed |
X509 Token profile - sample still uses QNames. (BinarySecurityToken attributes) |
http://lists.oasis-open.org/archives/wss/200405/msg00003.html
|
Closed |
|
282 |
Technical |
Closed |
Password based key derivation - revisited |
http://lists.oasis-open.org/archives/wss/200402/msg00060.html
|
Closed |
|
283 |
Technical |
Closed |
User To User Kerberos |
http://lists.oasis-open.org/archives/wss/200405/msg00018.html
|
Closed |
|
284 |
Editorial |
Closed |
SAML virtual interop scenario typos |
http://lists.oasis-open.org/archives/wss/200405/msg00021.html
|
Closed |
|
285 |
Technical |
Closed |
Transforms for securing attachments |
http://lists.oasis-open.org/archives/wss/200405/msg00022.html
|
Closed |
|
286 |
Technical |
Closed |
The examples should be made consistent so that the assertion always has the same subject identified and issuer. Should specify how the issuer is specified |
Issue raised during SAML interop |
Closed |
|
287 |
Technical |
Closed |
Need to use namespace qualified mustUnderstand for interop |
Issue raised during SAML interop. |
Closed |
|
288 |
Technical |
Closed |
When using a signature to bind an on msg assertion to its soap msg, why is it necessary to use an STR to reference the assertion from signedInfo of the signature. |
Issue raised during SAML interop |
Closed |
|
289 |
Editorial |
Closed |
minor typo in the interop document. Lines 705-708 should be contained
within the ds:Transform. |
Issue raised during SAML interop |
Closed |
|
290 |
Technical |
Closed |
Inconsistency in the KeyIdentifier encoding type default between core and SAML specifications. Core defines default of Base64Binary while SAML spec defines default to be xsi:string. |
Issue raised during SAML interop Resolution: Core also defines the unencoded string so the profiles will not have to redefine that themselves. Any profile that does not have Base 64 will have to change, only one exists presently (SAML). Action: Ron to write up and send to list |
Closed |
|
291 |
Technical |
Closed |
Clarify that the SAML token profile only covers SAML 1.1 |
Issue raised during SAML interop |
Closed |
|
292 |
Technical |
Duplicate |
Interop scenario #3 has an
enveloped signature that signs the assertion (referenced using the AssertionID) and a detached signature signing the assertion
as well as the message body. One option is to sign the assertion referenced
via a SecurityTokenReference. Another option is to
have referenced the assertion directly using the AssertionID
attribute. What is the right option? |
Issue raised during SAML interop |
Closed |
|
293 |
Technical |
Closed |
Does the x509 token profile standardize an interoperable encapsulation of an X.509 V1 certificate in a BinarySecurityToken |
http://lists.oasis-open.org/archives/wss/200405/msg00067.html
|
Closed |
|
294 |
Procedural |
Closed |
XrML trademark issues |
http://lists.oasis-open.org/archives/wss/200405/msg00068.html
|
Closed |
|
295 |
Technical |
Closed |
Ramana Turlapati: Comments on SAML Token profile - sender vouches scenario is too complex. |
http://lists.oasis-open.org/archives/wss/200406/msg00052.html
|
Closed |
|
295b |
Technical |
Closed |
Ramana Turlapati:
Profile does not cover SAML "Bearer" tokens. Is this scoped for
future? |
http://lists.oasis-open.org/archives/wss/200406/msg00052.html
|
Closed |
|
296 |
Technical |
Closed |
Anthony Nadlin: Comments on SAML Token profile and ID usage. |
http://lists.oasis-open.org/archives/wss/200406/msg00058.html
|
Closed |
|
297 |
Technical |
Closed |
Attachment Profile Question/Comment |
http://lists.oasis-open.org/archives/wss/200406/msg00067.html |
Closed |
|
298 |
Technical |
Closed |
X509 TP: IssuerSerial - What are the advantages of IssuerSerial as opposed to using SubjectKeyInfo |
http://lists.oasis-open.org/archives/wss/200406/msg00104.html
|
Closed |
|
299 |
Editorial |
Closed |
Frederick Hirsch: SOAP security errata 1.0 comments |
http://lists.oasis-open.org/archives/wss/200406/msg00111.html |
Closed |
|
300 |
Editorial |
Closed |
Frederick Hirsch: X.509 Token profile errata comments |
http://lists.oasis-open.org/archives/wss/200406/msg00112.html |
Closed |
|
301 |
Editorial |
Closed |
Frederick Hirsch: Username Token profile errata comments |
http://lists.oasis-open.org/archives/wss/200406/msg00113.html |
Closed |
|
303 |
Editorial |
Closed |
Attachment profile question: Sec 2.2.1 MIME Part CipherReference Transform line 265 says: The <xenc:CipherReference> must
have a <ds:Transforms> child element, |
http://lists.oasis-open.org/archives/wss/200407/msg00007.html
|
Closed |
|
304 |
Editorial |
Closed |
REL Profile Lines 294-298: Use of MAY |
http://lists.oasis-open.org/archives/wss/200407/msg00010.html |
Closed |
|
302 |
Editorial |
Closed |
Nishimura Toshihiro: A small errata for the core spec. |
http://lists.oasis-open.org/archives/wss/200406/msg00117.html
|
Closed |
|
305 |
Technical |
Closed |
Kerberos profile - Exchanging raw tickets, that is without Kerberos authenticators, poses several risks. Related to Issue #283 |
http://lists.oasis-open.org/archives/wss/200407/msg00014.html |
Closed |
|
306 |
Technical |
Closed |
SwA Profile comments - |
http://lists.oasis-open.org/archives/wss/200407/msg00024.html |
Closed |
|
307 |
Technical |
Closed |
More SwA comments - |
http://lists.oasis-open.org/archives/wss/200407/msg00025.html
|
Closed |
|
308 |
Technical |
Closed |
Hal Lockhart: License Id in REL token profile |
http://lists.oasis-open.org/archives/wss/200407/msg00041.html
|
Closed |
|
309 |
Editorial |
Closed |
Dana Kaufman: Example 4.4.5 seems to be missing an <xenc:EncryptionMethod> tag |
http://lists.oasis-open.org/archives/wss/200407/msg00103.html
|
Closed |
|
310 |
Technical |
Closed |
Hal Lockhart: Clarification on using Key Identifier when SKI extension is not present. Vijay Gajjala; Are there alternative mechanisms that can be used in this case? Revisit. |
http://lists.oasis-open.org/archives/wss/200408/msg00008.html Status/Action: Frederick - the new text in the latest core WSS draft at line 984 seems to be unclear. Tony to review text. Status/Action: This issue was missing edits.
Still Pending additional text to be added Status: This was already fixed by Tony. No further action required. |
Closed |
|
311 |
Technical |
Closed |
Nishimura Toshihiro: SWA Profile comments |
http://lists.oasis-open.org/archives/wss/200407/msg00097.html
|
Closed |
|
312 |
Technical |
Closed |
Dana Kaufman: Feedback on SWA Profile-1.0-draft-06 |
http://lists.oasis-open.org/archives/wss/200407/msg00101.html
|
Closed |
|
313 |
Technical |
Closed |
Manveen Kaur: Errata WSS:SOAP Message Security v1.0 |
http://lists.oasis-open.org/archives/wss-comment/200408/msg00001.html
|
Closed |
|
314 |
Editorial |
Closed |
Kojiro Nakayama: Comments on final+errata documents |
http://lists.oasis-open.org/archives/wss/200408/msg00022.html
|
Closed |
|
315 |
Technical |
Closed |
Dana Kaufman: Provide PKI examples? |
http://lists.oasis-open.org/archives/wss/200408/msg00024.html
|
Closed |
|
316 |
Editorial |
Closed |
Dana Kaufman: Minor item from SwA profile |
http://lists.oasis-open.org/archives/wss/200408/msg00048.html
|
Closed |
|
317 |
Technical |
Closed |
Vijay Gajjala: Encrypted Header |
http://lists.oasis-open.org/archives/wss/200408/msg00057.html
|
Closed |
|
318 |
Technical |
Closed |
Vijay Gajjala: Encrypted Key |
http://lists.oasis-open.org/archives/wss/200408/msg00058.html
|
Closed |
|
319 |
Technical |
Closed |
Vijay Gajjala: Signature Confirmation |
http://lists.oasis-open.org/archives/wss/200408/msg00059.html
|
Closed |
|
320 |
Technical |
Closed |
If EncryptedData is referenced from an EK within security header, then you don't need a separate reference list as child of security header. |
http://lists.oasis-open.org/archives/wss/200407/msg00101.html
|
Closed |
|
321 |
Technical |
Closed |
Dana Kaufman: Clarify how to interpret/transform the encrypted contents of the attachment |
http://lists.oasis-open.org/archives/wss/200408/msg00071.html
|
Closed |
|
322 |
Technical |
Closed |
Blake Dournaee: Are XML attachments opaque or not |
http://lists.oasis-open.org/archives/wss/200408/msg00072.html
|
Closed |
|
323 |
Technical |
Closed |
Blake Dournaee: Statement in SwA that when <EncyptedKey> element is present, <KeyInfo> element should not be present. This seems wrong. |
http://lists.oasis-open.org/archives/wss/200408/msg00073.html |
Closed |
|
324 |
Technical |
Closed |
Maneesh Sahu: What is the value in canonicalizing the content-length mime header? |
http://lists.oasis-open.org/archives/wss/200409/msg00002.html
|
Closed |
|
325 |
Technical |
Closed |
Which attachment headers to include in signature? Should headers be included in signature? |
http://lists.oasis-open.org/archives/wss/200409/msg00014.html
|
Closed |
|
326 |
Technical |
Closed |
Dana Kaufman: More comments on SwA profile - Draft 8. |
http://lists.oasis-open.org/archives/wss/200409/msg00024.html |
Closed |
|
327 |
Technical |
Closed |
Timestamp ValueType needs to be clarified |
http://lists.oasis-open.org/archives/wss/200409/msg00054.html |
Closed |
|
328 |
Editorial |
Closed |
Errata on STR transform |
http://lists.oasis-open.org/archives/wss/200409/msg00055.html |
Closed |
|
329 |
Technical |
Closed |
Dana Kaufman: SwA profile
comments |
http://lists.oasis-open.org/archives/wss/200409/msg00058.html |
Closed |
|
330 |
Editorial |
Closed |
Comments on oasis-200401-wss-soap-message-security-1
0-errata-003-changes.pdf - |
http://lists.oasis-open.org/archives/wss/200409/msg00086.html
|
Closed |
|
331 |
Editorial |
Closed |
Manveen Kaur: Errata WSS: SOAP Message security v1.0 |
http://lists.oasis-open.org/archives/wss-comment/200408/msg00001.html |
Closed |
|
332 |
Editorial |
Closed |
Manveen Kaur: Comments on Errata |
http://lists.oasis-open.org/archives/wss-comment/200409/msg00002.html
|
Closed |
|
333 |
Technical |
Closed |
Blake : Quoting Issues |
http://lists.oasis-open.org/archives/wss/200410/msg00036.html
|
Closed |
|
334 |
Technical |
Closed |
Vijay: Including SAML AssertionID in the core as a direct ID reference mechanism. |
http://lists.oasis-open.org/archives/wss/200410/msg00037.html
Action: Tony to ensure correct text appears in core
Email from
Status: We will
decide this issue at the Sep 6 meeting. |
Closed |
|
335 |
Editorial |
Duplicate |
WSS comments list: Content-Type and wss-swa-profile-1.0-draft-11 |
http://lists.oasis-open.org/archives/wss-comment/200410/msg00000.html
|
Closed |
|
336 |
Editorial |
Closed |
Dana Kaufman - Small Change: wss-swa-profile-1.0-draft |
http://lists.oasis-open.org/archives/wss/200410/msg00057.html |
Closed |
|
337 |
Editorial |
Closed |
|
http://lists.oasis-open.org/archives/wss/200410/msg00058.html |
Closed |
|
339 |
Editorial |
Closed |
Hal: Errata for X.509 Token Profile - Reference for PKIPath |
http://lists.oasis-open.org/archives/wss/200410/msg00067.html
|
Closed |
|
340 |
Technical |
Closed |
Blake: Short list of SwA interop 1 issues |
http://lists.oasis-open.org/archives/wss/200411/msg00004.html |
Closed |
|
341 |
Technical |
Closed |
Maneesh: Currently lose the content transfer encoding in WSS SwA encryption |
http://lists.oasis-open.org/archives/wss/200411/msg00009.html
|
Closed |
|
342 |
Technical |
Closed |
Ramana Turlapati: Phrasing in SwA profile implies that MimeType is required instead of being optional |
http://lists.oasis-open.org/archives/wss/200411/msg00010.html |
Closed |
|
343 |
Technical |
Closed |
|
http://lists.oasis-open.org/archives/wss/200411/msg00015.html |
Closed |
|
344 |
Technical |
Closed |
Comments on SWA profile interoperability - comments on base64 encoding in relation with encrypted and signed MIME parts. |
http://lists.oasis-open.org/archives/wss/200411/msg00065.html |
Closed |
|
345 |
Technical |
Closed |
Blake: Additional SwA interop issues |
http://lists.oasis-open.org/archives/wss/200411/msg00054.html Resolution: Fixed. Closed. |
Closed |
|
346 |
Technical |
Closed |
|
http://lists.oasis-open.org/archives/wss/200411/msg00087.html Resolution: Fixed. Closed. |
Closed |
|
347 |
Editorial |
Closed |
NISHIMURA: Editorial comments on core 1.0 |
http://lists.oasis-open.org/archives/wss/200412/msg00008.html
|
Closed |
|
348 |
Technical |
Closed |
Items needing clarification in SWA Profile draft 15. (Was SwA Profile draft 15 vote Dec 14) |
http://lists.oasis-open.org/archives/wss/200412/msg00032.html
|
Closed |
|
349 |
Technical |
Close |
Ron: Does the profile effectively prohibit the use of a ReferenceList (in a Security header) to reference an
encrypted attachment? |
http://lists.oasis-open.org/archives/wss/200412/msg00042.html
|
Closed |
|
350 |
Technical |
Closed |
Thomas: thumbprint proposal |
http://lists.oasis-open.org/archives/wss/200412/msg00057.html |
Closed |
|
351 |
Technical |
Closed |
Hal: Proposed text changes relating to EncryptedHeader |
http://lists.oasis-open.org/archives/wss/200412/msg00037.html
|
Closed |
|
352 |
Technical |
Closed |
Hal: Proposed text changes to 1.1 re: EncryptedKey references |
http://lists.oasis-open.org/archives/wss/200412/msg00034.html
|
Closed |
|
353 |
Technical |
Closed |
1.1 schema question |
http://lists.oasis-open.org/archives/wss/200412/msg00058.html
|
Closed |
|
354 |
Editorial |
Closed |
comments on wss-saml-token-profile-1.0-cd-04 |
http://lists.oasis-open.org/archives/wss-comment/200412/msg00003.html
|
Closed |
|
355 |
Editorial |
Closed |
Do examples of signing element(s) in security header need to be updated |
http://lists.oasis-open.org/archives/wss/200502/msg00000.html
|
Closed |
|
356 |
Editorial |
Closed |
Open SwA profile CD issues |
http://lists.oasis-open.org/archives/wss/200502/msg00008.html |
Closed |
|
357 |
Technical |
Closed |
Need a Token Type URI in SAML token profile |
http://lists.oasis-open.org/archives/wss/200502/msg00012.html
Status: Linked to 391. Resolution: Changes incorporated into SAML Token Profile 1.1 |
Closed |
|
358 |
Technical |
Closed |
Comments on wss-swa-profile-1.0-cd-01 |
http://lists.oasis-open.org/archives/wss-comment/200502/msg00004.html
|
Closed |
|
359 |
Editorial |
Closed |
SWA profile: Clarify Goals and non-goals |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
360 |
Editorial |
Closed |
SWA profile: Add additional clarification of relationship to other work, particularly MTOM and S/MIME |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
361 |
Technical |
Closed |
SWA profile: Layering Issue - MIME and SOAP processing are intermixed |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
362 |
Technical |
Closed |
SWA profile: Clarify that Attachment-Content-Only/Attachment-Complete Signature Transform inputs are octet-streams |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
363 |
Technical |
Closed |
SWA profile: Allow ds:Reference transform chain (section 4.4.4) to allow additional transforms including base64, while clarifying typically not needed. |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
364 |
Technical |
Closed |
SWA profile: Can XML attachments be XML canonicalized and used in conjunction with SwA profile? |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html Status: Reopened based on Brian's feedback Status: Resolution: |
Closed |
|
365 |
Technical |
Closed |
SWA profile: Clarify relationship to S/MIME, including how S/MIME attachments are handled and of possible interactions in signature processing |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
367 |
Technical |
Closed |
Can SwA signatures be persisted |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
366 |
Technical |
Closed |
SWA profile: Review MIME headers that are included in signature, make extensible |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html Action Item: |
Closed |
|
368 |
Technical |
Closed |
SWA profile: Signatures over portions of attachments precluded |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
369 |
Technical |
Closed |
SWA profile: Clarify which MIME headers are encrypted with "content and headers" encryption |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html |
Closed |
|
370 |
Technical |
Closed |
SWA profile: Add processing rules/guidance for SOAP and MIME intermediaries |
http://lists.oasis-open.org/archives/wss/200502/msg00054.html Status: Resolution: captured in draft 20 |
Closed |
|
371 |
Technical |
Closed |
X.509v1 Certificate support in 1.0 Errata |
http://lists.oasis-open.org/archives/wss/200502/msg00051.html |
Closed |
|
372 |
Technical |
Closed |
Interop scenario 1:3->Timestamp |
http://lists.oasis-open.org/archives/wss/200503/msg00000.html
|
Closed |
|
373 |
Editorial |
Closed |
WSS spec legibility |
http://lists.oasis-open.org/archives/wss/200503/msg00002.html
|
Closed |
|
374 |
Technical |
Closed |
TokenType URI for EncryptedKey |
EncryptedKey doesn't have a TokenType URI. |
Closed |
|
375 |
Editorial |
Closed |
X.509 Token Profile 1.0 says "Interim draft" |
http://lists.oasis-open.org/archives/wss/200503/msg00024.html
|
Closed |
|
389 |
Technical |
Closed |
ID Clash case |
http://lists.oasis-open.org/archives/wss/200504/msg00023.html
Status: Text is in latest document. |
Closed |
|
393 |
Process |
Closed |
Update contributors list. |
Action: Hans to follow up Status: Closed. Action: Hans
will revise the list based on 1.0 Spec/ List
will be in appendix as all contributors, and current membership in a
different appendix. |
Closed |
|
394 |
Process |
Closed |
Interop document for SAML 2.0 |
Action: Ron to create proposal for scenario.
Status: Abbie completed an interop
document and sent it to the editors of the previous interop
document. Some of those editors are on
vacation and Abbie hopes to send a document to the
TC by early next week. Status: TC members to review by next conf call. Action: Ron and Abbie to post SAML interop plan to TC mailing list. . |
Closed |
|
403 |
Editorial |
Closed |
Adjust Security Considerations Text |
Action: Editors to make the change described in
e-mail
from Thomas No change in status in the last meeting. Status: Text is in latest document. |
Closed |
|
404 |
Technical |
Closed |
RFC 4120 vs RFC 1510 |
Should we make any changes to Kerberos token profile on
account of RFC 4120? Action: Tony/Duane Nickull to review Kerberos token profile
with respect to RFC 4120 (and obsoleted RFC 1510). Reference in profile to be
updated. Status: We will ask
implementers if they support RFC4120. We will try to close this issue at Sept
6 meeting. |
Closed |
|
405 |
Technical |
Closed |
ValueType of EncryptedKey
STR |
Likely error in the value type of the EncryptedKey STR.
|
TC |
|
406 |
Editorial |
Closed |
Editorial comments on WSS 1.1 SAML Token Profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00001.html Status: Ron sent out the document Sept 6th:
http://lists.oasis-open.org/archives/wss/200509/msg00031.html |
Closed |
|
407 |
Editorial |
Closed |
Editorial comments on WSS 1.1 REL Token Profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00002.html Status: Thomas sent out a document on Aug 24th.
http://lists.oasis-open.org/archives/wss/200508/msg00019.html |
Closed |
|
408 |
Editorial |
Closed |
Editorial comments on WSS 1.1 Kerberos Token Profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00003.html
Status: Fixed in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14285/wss-v1.1-spec-draft-KerberosTokenProfile-01.pdf |
Closed |
|
409 |
Editorial |
Closed |
Editorial comments on WSS 1.1 x509 Token Profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00004.html
Status: Fixed in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14287/wss-v1.1-spec-draft-x509TokenProfile-01.pdf |
Closed |
|
410 |
Editorial |
Closed |
Editorial comments on WSS 1.1 Username Profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00005.html
Status: Fixed in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14286/wss-v1.1-spec-draft-UsernameTokenProfile-01.pdf |
Closed |
|
411 |
Editorial |
Closed |
Editorial comments on WSS 1.1 core |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00006.html
Status: Fixed in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14284/wss-v1.1-spec-draft-SOAPMessageSecurity-01.pdf |
Closed |
|
412 |
Editorial |
Closed |
Comment on WSS 1.1 REL Token profile: Are lines 128-129
talking about wsse:STR/@wsse:TokenType? |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00010.html
|
|
|
413 |
Editorial |
Closed |
Clarify ValueType attribute in
STR in Kerberos Token profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00011.html.
Issue #1 Status: Fixed in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14285/wss-v1.1-spec-draft-KerberosTokenProfile-01.pdf |
Closed |
|
414 |
Editorial |
Closed |
Kerberos Token profile: Clarify lines 303-305. Suggest
rewording. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00011.html.
Issue #2 |
Closed |
|
415 |
Editorial |
Closed |
Kerberos Token profile: Some minor clarifications |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00011.html.
Issue #3 & #4 |
Closed |
|
416 |
Editorial |
Closed |
Username Token profile: Clarification on the URI for
Username token. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00012.html
. Issue #1. |
Closed |
|
417 |
Editorial |
Closed |
Username Token profile: Clarification on how to serialize
the salt |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00012.html
. Issue #2 |
Closed |
|
418 |
Technical |
Closed |
Username Token profile: Iteration field is marked as decimal
instead of unsigned integer. Expected unsigned integer |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00012.html
. Issue #3 |
Closed |
|
419 |
Technical |
Closed |
Username Token profile: Consistent usage of password field
for cryptographic purposes |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00012.html.
Issue #4 Status: Fixed: No change required. http://lists.oasis-open.org/archives/wss/200509/msg00014.html |
Closed |
|
420 |
Editorial |
Closed |
X509 Token profile: ThumbprintSHA1 should be added to the
table at line 157 |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00013.html.
Issue #1 |
Closed |
|
421 |
Editorial |
Closed |
X509 Token profile: Clarify minimal certificate
requirement |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00013.html.
Issue #2 |
Closed |
|
422 |
Editorial |
Closed |
X509 Token profile: Clarification on the URI for
X509 subject key identifier. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00013.html.
Issue #3. |
Closed |
|
423 |
Editorial |
Closed |
X509 Token profile: ValueType URI should be changed. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00013.html.
Issue #4. |
Closed |
|
424 |
Editorial |
Closed |
X509 Token profile: Suggest deleting lines 430 - 431 in
light of the thumbprint support. Modify the following example to show use of
thumbprint instead. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00013.html.
Issue #5. |
Closed |
|
425 |
Comment |
Closed |
Comments on SAML token profile. |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00014.html
. All issues |
Closed |
|
426 |
Comment |
Closed |
Request for clarification on WSS 1.1 Kerberos token
profile |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00015.html.
|
Closed |
|
427 |
Technical |
Closed |
STRs outside of <wsse:Security> header |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00017.html
|
Gudge |
|
428 |
Technical |
Closed |
Recursive security token reference |
http://lists.oasis-open.org/archives/wss-comment/200508/msg00018.html |
Closed |
|
429 |
Editorial |
Closed |
Use of STR/Reference/@ValueType deprecated in favour of STR/@wsse11:TokenType |
http://lists.oasis-open.org/archives/wss/200507/msg00041.html Status: Gudge to mail revised wording to TC.
Issue to be closed at Septemer 6th
meeting. Status: Closed 2005-10-18 per Gudge's e-mail; http://lists.oasis-open.org/archives/wss/200510/msg00038.html |
|
| 430 | Editorial | Closed | Comments on WSS 1.1 Core | http://lists.oasis-open.org/archives/wss/200509/msg00013.html | Closed |
| 431 | Editorial | Closed | Comments on WSS 1.1 Core: Re: X.509 TP |
http://lists.oasis-open.org/archives/wss/200509/msg00013.html
Action: Vijay to provide information on how Microsoft product define the term X.509 thumbprint extension. Action: Editors to fix PKIPATH reference. Status: Proposal from Vijay http://lists.oasis-open.org/archives/wss/200510/msg00043.html adopted 2005-10-18. Moved to Pending Status: 2005-11-01: Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15126/oasis-wss-x509-token-profile-1.1.pdf |
Closed |
|
432 Public Comments |
Editorial | Closed | Further comments on WSS 1.1 Core | http://lists.oasis-open.org/archives/wss-comment/200508/msg00021.html | Closed |
|
433 |
Editorial | Closed | Editorial comment on use token type attribute in core | http://lists.oasis-open.org/archives/wss-comment/200509/msg00011.html | Closed |
|
434 Public Comments |
Editorial | Closed |
Schema corrections in SAML token profile 1.1 draft-01
|
http://lists.oasis-open.org/archives/wss-comment/200509/msg00012.html
Status: Update in draft 7. |
Closed |
|
435 |
Editorial | Closed | Public comment on X.509 token profile 1.1 |
http://lists.oasis-open.org/archives/wss-comment/200509/msg00016.html
Status: Resolution related to 431. Status: Closed 2005-10-18 as dupe of 431. |
Closed |
|
436 |
Editorial | Closed | Public comment on SOAP Message security 1.1 | http://lists.oasis-open.org/archives/wss-comment/200509/msg00017.html | Closed |
|
437 |
Editorial | Closed | Public comment on username token profile 1.1 | http://lists.oasis-open.org/archives/wss-comment/200509/msg00018.html | Closed |
|
438 |
Editorial | Closed | Public comment on SAML token profile 1.1 | http://lists.oasis-open.org/archives/wss-comment/200509/msg00019.html | Closed |
|
439 |
Editorial | Closed |
comments on wss-v1.1-spec-pr-SOAPMessageSecurity-01 |
http://lists.oasis-open.org/archives/wss-comment/200509/msg00025.html
Status: Comment on Core 2009 ref'd but not cited Status: Moved to Pending Review 2005-10-18; Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14865/wss-v1.1-spec-draft-SOAPMessageSecurity-01.pdf |
Closed |
| 440 | Technical | Closed | What is GSS wrapped Kerberos V5 AP_REQ? |
http://lists.oasis-open.org/archives/wss/200509/msg00047.html
& http://lists.oasis-open.org/archives/wss/200509/msg00061.html Status: Proposal from Prateek http://lists.oasis-open.org/archives/wss/200509/msg00061.html adopted 2005-10-18. Moved to Pending Status: 2005-11-01: Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15124/oasis-wss-kerberos-token-profile-1.1.pdf |
Closed |
| 441 | Editorial | Closed | Examples in Kerberos token profile need to be updated to use latest URIs |
http://lists.oasis-open.org/archives/wss/200509/msg00053.html
Status: Moved to Pending Review 2005-10-18. |
Closed |
| 442 | Editorial | Closed | wss11.xsd schema file | http://lists.oasis-open.org/archives/wss/200509/msg00056.html | Closed |
| 443 | Editorial | Closed | comment on wsu:Timestamp description in wss-v1.1-spec-pr-SOAPMessageSecurity-01 |
http://lists.oasis-open.org/archives/wss/200509/msg00060.html
Status: Editors to make the changes. Status: 2005-10-04: Changes made. Document not yet posted to TC site. Status: Moved to Pending Review 2005-10-18; Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14865/wss-v1.1-spec-draft-SOAPMessageSecurity-01.pdf |
Closed |
|
445 Public Comments |
Editorial | Closed | Changes from Errata not included 1.1 |
http://lists.oasis-open.org/archives/wss-comment/200509/msg00029.html
Status: 2005-10-04: Editors to make changes and post updated document. Status: Moved to Pending Review 2005-10-18; Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/14865/wss-v1.1-spec-draft-SOAPMessageSecurity-01.pdf |
Closed |
|
446 Public Comments |
Editorial | Closed | Need clarification on STR transform |
http://lists.oasis-open.org/archives/wss-comment/200509/msg00030.html
Status: 2005-10-18. Gudge's answer A1 and A4 in e-mail http://lists.oasis-open.org/archives/wss/200510/msg00044.html to be used as basis for clarification of STR Transform in the core spec. Gudge to work with editors to add this clarification. Status: 2005-11-01: Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15127/oasis-wss-soap-message-security-1.1.pdf |
Closed |
| 447 | Technical | Closed |
Should wsse11:EncryptedHeader/xenc:EncryptedData elements carry
a Type attribute in WSS 1.1 implementations? |
http://lists.oasis-open.org/archives/wss/200509/msg00035.html & http://lists.oasis-open.org/archives/wss/200509/msg00039.html Status: Closed with no change 2005-10-18. |
Closed |
| 448 | Technical | Closed | xml:id core text update |
http://www.oasis-open.org/apps/org/workgroup/wss/email/archives/200510/msg00049.html
This was previously discussion as part of issue 334. Status: 2005-11-01: Tony agreed to implement the missing three changes from the above e-mail |
Closed |
| 449 | Editorial | Closed | Updates document and namespace URIs |
Status: Per 2005-10-18 meeting, URIs to be updated by
editors. Status: 2005-11-01: Changes present in http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15127/oasis-wss-soap-message-security-1.1.pdf, http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15126/oasis-wss-x509-token-profile-1.1.pdf , http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15125/oasis-wss-username-token-profile-1.1.pdf , http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15124/oasis-wss-kerberos-token-profile-1.1.pdf , http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15148/oasis-wss-rel-token-profile-1.1-draft05-clean.pdf , http://www.oasis-open.org/apps/org/workgroup/wss/download.php/15144/wss-v1.1-spec-draft-SAMLTokenProfile-09.pdf ACTION: 2005-11-01: Frederick to change the SwA Namespace to be like the Core Namespace from: http://docs.oasis-open.org/wss/wss1-1-SwAProfile-1.0.xsd to: http://docs.oasis-open.org/wss/oasis-wss-SwAProfile-1.1.xsd ACTION: 2005-11-01-05: Tony to determine correct legal notices text (Mary to provide this text) and then the other Editor's should adopt the same text. |
Closed |
| 450 | Editorial | Closed | Update reference to XMLDSIG |
http://lists.oasis-open.org/archives/wss-comment/200510/msg00002.html Status: 2005-11-01: Editors to change a) The [XMLSIG] reference to remove the URI (http://www.w3.org/TR/xmldsig-core/): b) In the Schema file change the URI from the undated reference to the dated reference for the Feb 2002 document. |
Closed |
| 451 | Editorial | Closed | TokenType in Kerberos Token Profile |
http://www.oasis-open.org/archives/wss/200511/msg00005.html Status: 2005-11-01: The following changes were agreed; a) Lines 227-228 (to match value at 220-221): Change "#Kerberosv5APREQSHA1" to "#Kerberosv5_AP_REQ" b) Line 160 Remove "and wsse11:TokenType". c) Line 161: Replace "for this token" with "for this attribute". d) Lines 202-204 Original text: "When a Kerberos Token is referenced using <wsse:SecurityTokenReference> the @ValueType attribute is not required. If specified, the URI listed above as Kerberos token type MUST be specified." Replacement text: "When a Kerberos Token is referenced using <wsse:SecurityTokenReference> the @TokenType attribute SHOULD be specified, and its value MUST be the URI that identifies the Kerberos token type as defined for a corresponding BinarySecurityToken/@ValueType attribute. The Reference/@ValueType attribute is not required. If specified, its value MUST be equivalent to that of the @TokenType attribute." Gudge: The sentiment is that the @TokenType attribute is optional but when it occurs its value must match the value from the table that defines the values for @ValueType. |
Closed |