<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>3708</bug_id>
          
          <creation_ts>2006-09-12 19:39:44 +0000</creation_ts>
          <short_desc>Updated Security Considerations section in framework document: Add mention of use of XML Signature to sign policy</short_desc>
          <delta_ts>2006-09-14 17:40:28 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WS-Policy</product>
          <component>Framework</component>
          <version>FPWD</version>
          <rep_platform>Macintosh</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Frederick Hirsch">w3c</reporter>
          <assigned_to name="Frederick Hirsch">w3c</assigned_to>
          
          
          <qa_contact name="Web Services Policy WG QA List">public-ws-policy-qa</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>11627</commentid>
    <comment_count>0</comment_count>
    <who name="Frederick Hirsch">w3c</who>
    <bug_when>2006-09-12 19:39:44 +0000</bug_when>
    <thetext>Policy may need integrity protection, yet not in the context of a SOAP message. For this reason XML Signature may be used.

Mention of use of XML Signature for this purpose can be added to the Framework Security Considerations section of the Framework document.

Proposed changes to framework document:

1) Add sentence at end of current section 5 (Security Considerations):

Policies may be signed using XML Signature to provide integrity protection and origin authentication, especially in contexts where message security is not appropriate.

2) Incorporate  security considerations listed in contributed primer into Framework document
See Appendix A in PDF referenced in http://lists.w3.org/Archives/Public/public-ws-policy/2006Jul/0001</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>11653</commentid>
    <comment_count>1</comment_count>
    <who name="Frederick Hirsch">w3c</who>
    <bug_when>2006-09-13 15:01:16 +0000</bug_when>
    <thetext>In template format:

Description - Update security considerations section of Framework to include discussion of XML Signature use as well as additional security considerations from Primer

Justification - Core document should include informative Securiity Considerations section. Integrity protection and source authentication provided by XML Signature in non-messaging context should be included as consideration.

Target - WS-Policy Framework [1]

Proposal:

1) Add sentence at end of current section 5 (Security Considerations):

Policies may be signed using XML Signature to provide integrity protection and origin authentication, especially in contexts where message security is not appropriate.

2) Incorporate  security considerations listed in contributed primer into Framework document. See Appendix A in PDF referenced in
http://lists.w3.org/Archives/Public/public-ws-policy/2006Jul/0001

Test: review of section

[1] http://dev.w3.org/cvsweb/~checkout~/2006/ws/policy/ws-policy-framework.html?content-type=text/html;%20charset=utf-8</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>11725</commentid>
    <comment_count>2</comment_count>
    <who name="Frederick Hirsch">w3c</who>
    <bug_when>2006-09-14 17:40:28 +0000</bug_when>
    <thetext>Entire proposal adopted as well as decision to remove considerations from primer, adding pointer from primer to Framework security considerations section.

Minutes
 http://www.w3.org/2006/09/14-ws-policy-irc#T17-38-49</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>