Description: |
[Extracted from Blair Dillaway's mail to the list.]
Section 7 has seemingly contradictory requirements. I can quess at what you meant, but it would be better if
you clarified it. First, you say not to use username tokens “ C0701 – Username Token credentials SHOULD NOT be used
for message level authentication because they are not cryptographically verifiable. Then 7.2 says to use them for
message sender authN “This subsection describes the secure messaging requirements for message SENDERs authenticating to
RECIEVERs using Username Token credentials…… R0702 – Message SENDERs MUST place the UsernameToken credential in the
message header in accordance with the WSS UTP and Section 11 of the WS-I BSP.” |