<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>9570</bug_id>
          
          <creation_ts>2010-04-21 12:28:53 +0000</creation_ts>
          <short_desc>MEX: &quot;Security Considerations&quot; sections vague and misleading</short_desc>
          <delta_ts>2010-07-28 09:12:10 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WS-Resource Access</product>
          <component>MetadataExchange</component>
          <version>LC</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>REMIND</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Robert Freund">bob</reporter>
          <assigned_to name="Gilbert Pilz">gilbert.pilz</assigned_to>
          <cc>dug</cc>
          
          <qa_contact name="notifications mailing list for WS Resource Access">public-ws-resource-access-notifications</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>35182</commentid>
    <comment_count>0</comment_count>
    <who name="Robert Freund">bob</who>
    <bug_when>2010-04-21 12:28:53 +0000</bug_when>
    <thetext>WS-Eventing, WS-Transfer, WS-MetadataExchange, and WS-Enumeration each contain
a &quot;Security Considerations&quot; section. These sections contain various bits of
&quot;pious advice&quot; that have no normative value and little to do with the protocols
to which they apply. If you understand the basics of web services security,
these sections won&apos;t teach you anything new and don&apos;t provide any insight into
the particular problems of securing their corresponding protocols. For example,
the Security Considerations section of WS-Eventing says nothing about making
sure that the sender of a Renew, GetStatus, or Unsubscribe request is the same
entity as the sender of the Subscribe request that created the subscription
that is being acted upon.

Proposal 1: remove the &quot;Security Considerations&quot; sections from WS-Eventing,
WS-Transfer, WS-MetadataExchange, and WS-Enumeration.

Proposal 2: rewrite the &quot;Security Considerations&quot; sections from WS-Eventing,
WS-Transfer, WS-MetadataExchange, and WS-Enumeration along the following
guidelines:

1. Identify the specific resources that need to be protected (e.g.
subscriptions, enumeration contexts, etc.)

2. Describe common methods for protecting these resources including, but not
limited to, the use of WS-Security and related technologies. Relate these
methods to the protocol in question.

3. Identify any special challenges posed to (2) due to the nature of the
protocols, etc.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35551</commentid>
    <comment_count>1</comment_count>
    <who name="Robert Freund">bob</who>
    <bug_when>2010-05-11 11:01:10 +0000</bug_when>
    <thetext>proposal at http://lists.w3.org/Archives/Public/public-ws-resource-access/2010May/0017.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>35558</commentid>
    <comment_count>2</comment_count>
    <who name="Robert Freund">bob</who>
    <bug_when>2010-05-11 16:22:55 +0000</bug_when>
    <thetext>resolved as proposed in message linked in comment #1</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>