Anne Thomas Manes
WSDL with attachments
Fri, 29 Jul 2005 13:04:21 GMT
I agree with you that the XML gateway appliance vendors will benefit
from widespread adoption of WS-Security. <grin>

I'm not an expert in security, although I do know enough to know that
it's a remarkably complex topic. The security gods have reached the
conclusion that the best way to ensure end-to-end security and to
reduce security vulnerabilities when dealing with attachments is to
make them part of the SOAP message infoset. The documents I cited can
tell you why -- but you need a pretty deep understanding of security
threats and countermeasures to truly understand them. (I'm definitely
on shaky ground when reading them.)

XML Signature requires XML Canonicalization because you absolutely
need to make sure that not one bit in the message changes to replicate
and validate a signature. That's just the way it is. The message may
get compressed or chunked or whatever in transit, so you have to be
able to reconstruct it exactly. Only canonicalization can ensure
perfect reconstruction.


