|
Comment: |
Updated text to read:
WS-SecurityPolicy token assertions specify the type of tokens required during communication. Unfortunately, the WS-SecurityPolicy specification does
not provide a way to bind an actual token within a token assertion. This functionality is desirable as a means of using endpoint references for key
distribution. For example, consider an EPR containing policy describing a security mechanism (e.g., message-level encryption) that requires the
INITIATOR to use a token (e.g., an X.509 certificate) identifying the RECIPIENT. In this case, it is convenient to furnish the actual RECIPIENT token
along with the security policy within the EPR.
|