RE: [uddi-spec] The need to adopt a policy framework - concerns over the current approach taken on modeling security/auth

From
"Muc Dlement"
Date
2005-05-23T20:55:17+00:00
ID
Thread
RE: [uddi-spec] The need to adopt a policy framework - concerns over the current approach taken on modeling security/auth
Andrew: please consider the attached –
a document I put together hurriedly so please excuse the flaws. I disagree that
your mapping is consistent with PolicyAttachment – albeit it is close. Let’s
review your approach and compare it with the attached. I think we will find
divergence in the approach.

 

Can we discuss this tomorrow during the
call?

 

Luc

 

From: Rogers, Tony
[mailto:] 

Sent: Monday, May 23, 2005 15:58

To: Andrew Hately; Luc Clement

Cc: 

Subject: RE: [uddi-spec] The need
to adopt a policy framework - concerns over the current approach taken on
modeling security/auth

 

We definitely need a liaison with the WS Policy WG. Is anyone in the TC
also in WS Policy?

 

Tony

-----Original
Message----- 

From: Andrew Hately
[mailto:] 

Sent: Tue 24-May-05 2:30 

To: Luc Clement 

Cc: 

Subject: Re: [uddi-spec] The need
to adopt a policy framework - concerns over the current approach taken on
modeling security/auth

>> 

I’m
very concerned about making any recommendations that should (MUST) be expressed
using policy by any other means.
I think we should take a step back; finally take that bold move and adopt
WS-Policy; and recast these two TNs using WS-Policy/PolicyAttachment.

<<

Regardless
of the framework, one of the challenges is that these Technical Notes are
proposing composable/reusable policy pieces.  I believe they are
compatible with WS-Policy as they exist today and we would just need to
reference WS-Policy files and we should probably do so.  If you are
proposing something deeper in terms of policy framework integration such as
changing the concept of UDDI searching to be based on something deeper than
tModel concept searches, we should discuss this tommorow. 

In
my opinion the challenge is not picking the framework or language, it is
getting these reviewed by people who can articulate if we've got the write
reusable policy pieces that would be composable. 

Should
we form a liasion with the W3C policy working group to move this forward?

Regards,

Andrew Hately

IBM Software Group, Emerging Technologies 

 

  
  
"Luc Clement"
  <> 

  
05/22/2005 10:18 PM 

  
  
  
   

    
    
To

    
    
    
Andrew Hately/Austin/IBM@IBMUS 

    
   

   

    
    
cc

    
    
    
<>
    

    
   

   

    
    
Subject

    
    
    
[uddi-spec] The need to adopt a policy
    framework - concerns over the current approach taken on modeling
    security/auth

    
   

  
  
 

  
   

    
    
 

    
    
    
 

    
   

  
  

  
 

Andrew, 

 

Something
hadn’t been sitting well with me with the approaches you’ve taken
on these two TNs 

 

 
Modeling Web services Security in UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/12217/uddi-spec-tc-tn-wssecurity-20040328.doc
     

 
Modeling HTTP Access Auth in UDDI: http://www.oasis-open.org/apps/org/workgroup/uddi-spec/download.php/11960/uddi-spec-tc-tn-httpauth-20050321.doc 

  

The
problem stems from the fact that we’ve yet to adopt a policy framework
for registry and the approach you’ve taken though not strictly incorrect
is only delaying what in my opinion is the inevitable – the adoption of a
policy framework for UDDI. 

 

Had
we one, we wouldn’t take the approach you’ve taken which as far as
I’m concerned is the only reasonable one for you at this point within the
current framework – or lack-thereof. That said, it isn’t reasonable
for us to delay adopting a policy framework – dare I say
WS-PolicyAttachment and WS-Policy. 

 

I’m
very concerned about making any recommendations that should (MUST) be expressed
using policy by any other means.
I think we should take a step back; finally take that bold move and adopt
WS-Policy; and recast these two TNs using WS-Policy/PolicyAttachment.

 

Luc 

 

Luc Cl幦ent | Senior Program Manager | Systinet Corporation | 

One van
  de Graaff Drive Burlington,
 MA 01803

Phone +1 781.362.1330 | Mobile
+1 978.793.2162 | Fax +1 781.362.1400 | 

 

Proposed framework for policy in UDDI.doc