<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>http://groups.google.com/group/basicb2b</id>
  <title type="text">Basic B2B Profile Google Group</title>
  <subtitle type="text">
  The purpose of this group is to discuss the development of the Basic B2B Profile. Feedback which is received on the Basic B2B Profile will be posted here. Issues will be discussed and the resolutions will be posted here.
  </subtitle>
  <link href="/group/basicb2b/feed/atom_v1_0_msgs.xml" rel="self" title="Basic B2B Profile feed"/>
  <updated>2006-04-11T15:03:31Z</updated>
  <generator uri="http://groups.google.com" version="1.99">Google Groups</generator>
  <entry>
  <author>
  <email>b...@dcx.com</email>
  </author>
  <updated>2006-04-11T15:03:31Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/81a898534c2ef69a/38526da13243a1f3?show_docid=38526da13243a1f3</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/81a898534c2ef69a/38526da13243a1f3?show_docid=38526da13243a1f3"/>
  <title type="text">Small Updates</title>
  <summary type="html" xml:space="preserve">
  Hello, &lt;br&gt; In order to make the profile easier to understand, in sections 4 and &lt;br&gt; 5 it would be good to have incorrect and correct examples with the &lt;br&gt; incorrect and correct elements highlighted. &lt;br&gt; Is there going to be a new revision of the profile? &lt;br&gt; Thanks, &lt;br&gt; Brian
  </summary>
  </entry>
  <entry>
  <author>
  <name>Christopher B Ferris</name>
  <email>chris...@us.ibm.com</email>
  </author>
  <updated>2005-06-28T16:55:42Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/23c887513dc8f261?show_docid=23c887513dc8f261</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/23c887513dc8f261?show_docid=23c887513dc8f261"/>
  <title type="text">Re: Adding WS-SecureConversation to the Basic B2B Profile</title>
  <summary type="html" xml:space="preserve">
  Barbara, &lt;br&gt; &lt;p&gt;I didn&#39;t notice any follow-ups to this, so here goes. Yes, you can use &lt;br&gt; WS-Secure Conversation without WS-Trust. &lt;br&gt; See section 4 of the WS-SC spec. &lt;br&gt; &lt;p&gt;As to the question of where (or whether) this fits into the uses of the &lt;br&gt; profile, basically it is to improve performance &lt;br&gt; of security operations by virtue of the use of symmetric keys.
  </summary>
  </entry>
  <entry>
  <author>
  <name>Christopher B Ferris</name>
  <email>chris...@us.ibm.com</email>
  </author>
  <updated>2005-06-27T20:58:22Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/c3feba5bfa394fd8/d02b58632c99e5b1?show_docid=d02b58632c99e5b1</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/c3feba5bfa394fd8/d02b58632c99e5b1?show_docid=d02b58632c99e5b1"/>
  <title type="text">Retransmission and MessageId/Timestamp</title>
  <summary type="html" xml:space="preserve">
  Please see my blog entry on the matter regarding WS-Addressing LC90: &lt;br&gt; &lt;p&gt;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www-128.ibm.com/developerworks/blogs/dw_blog_comments.jspa?blog=440&amp;entry=84783&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;Cheers, &lt;br&gt; &lt;p&gt;Christopher Ferris &lt;br&gt; STSM, Emerging e-business Industry Architecture &lt;br&gt; email: chris...@us.ibm.com &lt;br&gt; blog: &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://webpages.charter.net/chrisfer/blog.html&quot;&gt;[link]&lt;/a&gt;
  </summary>
  </entry>
  <entry>
  <author>
  <name>Rimas Rekasius</name>
  <email>ri...@us.ibm.com</email>
  </author>
  <updated>2005-05-30T21:45:09Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/49b09281c6736a40/7fca4d1b0dd5a54b?show_docid=7fca4d1b0dd5a54b</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/49b09281c6736a40/7fca4d1b0dd5a54b?show_docid=7fca4d1b0dd5a54b"/>
  <title type="text">Rimas Rekasius is out of the office.</title>
  <summary type="html" xml:space="preserve">
  I will be out of the office starting 05/26/2005 and will not return until &lt;br&gt; 06/02/2005. &lt;br&gt; &lt;p&gt;I will respond to your message when I return.
  </summary>
  </entry>
  <entry>
  <author>
  <name>Anthony Nadalin</name>
  <email>drsec...@us.ibm.com</email>
  </author>
  <updated>2005-05-30T21:05:48Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/a3c8213b9b0ca261?show_docid=a3c8213b9b0ca261</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/a3c8213b9b0ca261?show_docid=a3c8213b9b0ca261"/>
  <title type="text">Re: Strength of R5001 (Use of RSA1.5)</title>
  <summary type="html" xml:space="preserve">
  Correct &lt;br&gt; &lt;p&gt;Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122 &lt;br&gt; &lt;p&gt; Rimas &lt;br&gt; Rekasius/Chicago/
  </summary>
  </entry>
  <entry>
  <author>
  <name>Rimas Rekasius</name>
  <email>ri...@us.ibm.com</email>
  </author>
  <updated>2005-05-25T22:19:54Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/0374265e438e2e24?show_docid=0374265e438e2e24</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/0374265e438e2e24?show_docid=0374265e438e2e24"/>
  <title type="text">Re: Strength of R5001 (Use of RSA1.5)</title>
  <summary type="html" xml:space="preserve">
  OK, so just to be painfully clear, the proposal is to change &lt;br&gt; &lt;p&gt;R5001 When used for Key Transport, any xenc:EncryptionMethod/@Algorit hm &lt;br&gt; attribute in an ENCRYPTED_KEY MUST have a value of &lt;br&gt; &amp;quot;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.w3.org/2001/04/xmlenc#rsa-1_5&quot;&gt;[link]&lt;/a&gt;&amp;quot;. &lt;br&gt; &lt;p&gt;to &lt;br&gt; &lt;p&gt;R5001 When used for Key Transport, any xenc:EncryptionMethod/@Algorit hm
  </summary>
  </entry>
  <entry>
  <author>
  <email>tfow...@ford.com</email>
  </author>
  <updated>2005-05-25T17:35:32Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/d513f68072fec833?show_docid=d513f68072fec833</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/d513f68072fec833?show_docid=d513f68072fec833"/>
  <title type="text">Re: Adding WS-SecureConversation to the Basic B2B Profile</title>
  <summary type="html" xml:space="preserve">
  I agree that WS-SecureConversation should be part of the profile. Each &lt;br&gt; message would typically be signed / encrypted with the sending &lt;br&gt; endpoint&#39;s credential. A WS-SecureConversation endpoint caches the &lt;br&gt; credentials related to all of its partner endpoints and reuses those &lt;br&gt; for verification of incoming messages. Each message is verified with
  </summary>
  </entry>
  <entry>
  <author>
  <name>Barbara McKee</name>
  <email>bmc...@us.ibm.com</email>
  </author>
  <updated>2005-05-16T13:52:05Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/e10c19e8ca83907f?show_docid=e10c19e8ca83907f</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/e10c19e8ca83907f?show_docid=e10c19e8ca83907f"/>
  <title type="text">Re: Adding WS-SecureConversation to the Basic B2B Profile</title>
  <summary type="html" xml:space="preserve">
  Always questions :-) And this one is probably a naive one, but can you use &lt;br&gt; WS-SecureConversation without WS-Trust? The Abstract for the spec states &lt;br&gt; that WS-SecureConversation builds on WS-Security and WS-Trust. And it &lt;br&gt; looks to me like all of the techniques for establishing a Security Context
  </summary>
  </entry>
  <entry>
  <author>
  <name>Anthony Nadalin</name>
  <email>drsec...@us.ibm.com</email>
  </author>
  <updated>2005-05-15T23:44:33Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/2b7bd9a25fb9983a/48d2a04be6c56e72?show_docid=48d2a04be6c56e72</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/2b7bd9a25fb9983a/48d2a04be6c56e72?show_docid=48d2a04be6c56e72"/>
  <title type="text">Re: Constraining the choice of BSP token profile</title>
  <summary type="html" xml:space="preserve">
  Since the BSP has allowed conformance to the base, one can use any token &lt;br&gt; and still claim conformance, this will sure cause interoperability issues. &lt;br&gt; I believe is you constrain to the token profiles that the BSP profiles you &lt;br&gt; should be OK as they have looked at these for interop issues. So
  </summary>
  </entry>
  <entry>
  <author>
  <name>Christopher B Ferris</name>
  <email>chris...@us.ibm.com</email>
  </author>
  <updated>2005-05-13T17:01:09Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/a1820d8cce94ee02?show_docid=a1820d8cce94ee02</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/a1820d8cce94ee02?show_docid=a1820d8cce94ee02"/>
  <title type="text">Re: Strength of R5001 (Use of RSA1.5)</title>
  <summary type="html" xml:space="preserve">
  +1 &lt;br&gt; &lt;p&gt;Christopher Ferris &lt;br&gt; STSM, Emerging e-business Industry Architecture &lt;br&gt; email: chris...@us.ibm.com &lt;br&gt; blog: &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://webpages.charter.net/chrisfer/blog.html&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; phone: +1 508 377 9295 &lt;br&gt; &lt;p&gt;Anthony Nadalin/Austin/IBM@IBMUS wrote on 05/13/2005 12:19:42 PM: &lt;br&gt; &lt;p&gt;(OEAP or RSA1.5) no problem &lt;br&gt; to &amp;quot;SHOULD&amp;quot; and &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www&quot;&gt;[link]&lt;/a&gt;.
  </summary>
  </entry>
  <entry>
  <author>
  <name>Anthony Nadalin</name>
  <email>drsec...@us.ibm.com</email>
  </author>
  <updated>2005-05-13T16:19:42Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/598c2731a1f29d11?show_docid=598c2731a1f29d11</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/598c2731a1f29d11?show_docid=598c2731a1f29d11"/>
  <title type="text">Re: Strength of R5001 (Use of RSA1.5)</title>
  <summary type="html" xml:space="preserve">
  There are 2 allowed values, if each site chooses the same algorithm (OEAP &lt;br&gt; or RSA1.5) no problem (only way to do this today is out of band), so this &lt;br&gt; should be softened to &amp;quot;SHOULD&amp;quot; and &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.w3.org/2001/04/xmlenc#rsa-1_5&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; should be made the default value &lt;br&gt; &lt;p&gt;Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122
  </summary>
  </entry>
  <entry>
  <author>
  <name>Anthony Nadalin</name>
  <email>drsec...@us.ibm.com</email>
  </author>
  <updated>2005-05-13T13:02:09Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/47914b541b7c4470?show_docid=47914b541b7c4470</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/67c037808c392cfd/47914b541b7c4470?show_docid=47914b541b7c4470"/>
  <title type="text">Adding WS-SecureConversation to the Basic B2B Profile</title>
  <summary type="html" xml:space="preserve">
  I think that it makes piratical sense to add WS-SecureConversation to the &lt;br&gt; Basic B2B Profile. as without it, you really can&#39;t have secure, reliable &lt;br&gt; messaging. Besides helping to tremendously increase the performance of &lt;br&gt; secure Web services, WS-SC also gives you context based (i.e. instance)
  </summary>
  </entry>
  <entry>
  <author>
  <name>Rimas Rekasius</name>
  <email>ri...@us.ibm.com</email>
  </author>
  <updated>2005-05-12T20:25:11Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/6333fe38c94bcc21?show_docid=6333fe38c94bcc21</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/e103dff095ff4734/6333fe38c94bcc21?show_docid=6333fe38c94bcc21"/>
  <title type="text">Strength of R5001 (Use of RSA1.5)</title>
  <summary type="html" xml:space="preserve">
  The current version of the Basic B2B Profile has the following &lt;br&gt; requirement in it constraining the choice of encryption algorithm: &lt;br&gt; R5001 When used for Key Transport, any xenc:EncryptionMethod/@Algorit hm &lt;br&gt; attribute in an ENCRYPTED_KEY MUST have a value of &lt;br&gt; &amp;quot;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://www.w3.org/2001/04/xmlenc#rsa-1_5&quot;&gt;[link]&lt;/a&gt;&amp;quot;. &lt;br&gt; Question: should this be softened to a SHOULD, or is MUST the right
  </summary>
  </entry>
  <entry>
  <author>
  <email>ri...@us.ibm.com</email>
  </author>
  <updated>2005-05-12T18:41:44Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/2b7bd9a25fb9983a/068b003faca1dcdf?show_docid=068b003faca1dcdf</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/2b7bd9a25fb9983a/068b003faca1dcdf?show_docid=068b003faca1dcdf"/>
  <title type="text">Constraining the choice of BSP token profile</title>
  <summary type="html" xml:space="preserve">
  In the early days of developing the Basic B2B Profile, we considered &lt;br&gt; whether or not to constrain the choice of BSP token profiles which can &lt;br&gt; be used while conforming to the Basic B2B Profile. If I recall &lt;br&gt; correctly, I think the thought was that since not all platforms will &lt;br&gt; support all the same token profiles, it might help interoperability if
  </summary>
  </entry>
  <entry>
  <author>
  <name>Christopher B Ferris</name>
  <email>chris...@us.ibm.com</email>
  </author>
  <updated>2005-05-12T15:25:29Z</updated>
  <id>http://groups.google.com/group/basicb2b/browse_thread/thread/2aca15b4516044fc/1a501139166dca13?show_docid=1a501139166dca13</id>
  <link href="http://groups.google.com/group/basicb2b/browse_thread/thread/2aca15b4516044fc/1a501139166dca13?show_docid=1a501139166dca13"/>
  <title type="text">Re: Question on R0005 - cardinality of wsa:To header</title>
  <summary type="html" xml:space="preserve">
  +1 &lt;br&gt; &lt;p&gt;Christopher Ferris &lt;br&gt; STSM, Emerging e-business Industry Architecture &lt;br&gt; email: chris...@us.ibm.com &lt;br&gt; blog: &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://webpages.charter.net/chrisfer/blog.html&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; phone: +1 508 377 9295 &lt;br&gt; &lt;p&gt;Doug Davis/Raleigh/IBM@IBMUS wrote on 04/30/2005 07:11:10 PM: &lt;br&gt; &lt;p&gt;simply &amp;quot;mandatory&amp;quot;. Its &lt;br&gt; that it doesn&#39;t say that
  </summary>
  </entry>
</feed>
