matthew...@esacinc.com: Apr 02 12:45PM -0700
Hello. I worked on the PDTI project (link to the github project above),
which understood the hpdServiceAdress to be the place where a Direct
address would go. In fact, any electronic service address would go in
there, whether it is a Direct address, a CONNECT endpoint, or anything
else. That is why it is a URI. The mail attribute for individual
provider/HPDProvider is an artifact of the LDAP underpinnings of the data
model (it comes from the LDAP InetOrgPerson and how the HPDProvider was
built up from existing LDAP objects) and was not intended to hold the
Direct address. Both Organizations (aka HPDOrganization) and Individuals
(HPDProvider) can own Direct addresses (as noted above) and the
HPDElectronicService object holds that information, and this is why both of
those provider objects point to any number of HPDElectronicService objects.
The Certificate Discovery IG was also mentioned. The Direct Cert Discovery
process is completely separate from getting certificates and endpoint
information in HPD. In Cert Discovery, one must already know the direct
address to which they wish to send information. Direct Cert Discovery was
designed to be a process by which one could find a public key certificate
by knowing ONLY the Direct address, and not other demographic information
HTH, Matt
You received this digest because you're subscribed to updates for this group. You can change your settings on the group membership page.
To unsubscribe from this group and stop receiving emails from it send an email to ihe-hpd-implemen...@googlegroups.com.
Peter,
I can confirm that all you said is true.. The history of Direct is very ugly. I did what I could at the time to get them to use standards, however the deciding factor was always “first to code”. No matter how much I pointed at ‘already working systems’ they were not “code” checked into the Direct reference repository. So, the decisions that look silly now, were made by one coder when they decided to implement something and checked working code in. Unfortunately today the momentum still rules the day. There is no ‘fixing’ Direct, there is only waiting until it dies because a better solution fills the need.
Many of the issues you point out are indeed documented as known issues in the Direct wiki. Many of them on the Security Risks page…
You leave us all on the edge of our seats waiting for that ‘aha moment’... I know what my understanding is, however if we all have different aha moments then we don’t have agreement. What is your conclusion?
John
--
You received this message because you are subscribed to the Google Groups "ihe-hpd-implementors" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ihe-hpd-implemen...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.