Web Services Security UsernameToken Profile 1 - OASIS

1

2 Web Services Security 3 UsernameToken Profile 1.0

4 OASIS Standard 200401, March 2004

5 Document identifier:

6

{WSS: SOAP Message Security }-{UsernameToken Profile }-{1.0} (Word) (PDF)

7 Document Location:

8



9 Errata Location:

10



11 Editors:

Anthony

Nadalin

Phil

Griffin

Chris

Kaler

Phillip

Hallam-Baker

Ronald

Monzillo

13 Contributors:

IBM Individual

12

Microsoft

VeriSign

Sun

Gene

Thurston

AmberPoint

Frank

Siebenlist

Argonne National Lab

Merlin

Hughes

Baltimore Technologies

Irving

Reid

Baltimore Technologies

Peter

Dapkus

BEA

Hal

Lockhart

BEA

Symon

Chang

CommerceOne

Srinivas

Davanum

Computer Associates

Thomas

DeMartini

ContentGuard

Guillermo

Lao

ContentGuard

TJ

Pannu

ContentGuard

Shawn

Sharp

Cyclone Commerce

Ganesh

Vaideeswaran

Documentum

Sam John Tim Toshihiro Tom Yutaka Jason Paula Bob Joel Satoshi Maryann Michael Hiroshi David Anthony Nataraj Wayne Kelvin Don Bob Bob Keith Allen Paul Giovanni Vijay Johannes Scott Chris

Wei Hughes Moses Nishimura Rutt Kudo Rouault Austel Blakley Farrell Hada Hondo McIntosh Maruyama Melgar Nadalin Nagaratnam Vicknair Lawrence Flinn Morgan Atkinson Ballinger Brown Cotton Della-Libera Gajjala Klein Konersmann Kurt

Documentum Entegrity Entrust Fujitsu Fujitsu Hitachi HP IBM IBM IBM IBM IBM IBM IBM IBM IBM IBM IBM IBM (co-Chair) Individual Individual Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft

WSS: UsernameToken Profile Copyright ? OASIS Open 2002-2004. All Rights Reserved.

15 March 2004 Page 2

Brian Paul John John Dan Hervey Chris Prateek Frederick Senthil Lloyd Ed Charles Steve Vipin Jerry Eric Stuart Andrew Rob Peter Martijn Blake Pete Jonathan Yassir Jeff Ronald Jan Michael

LaMacchia Leach Manferdelli Shewchuk Simon Wilson Kaler Mishra Hirsch Sengodan Burch Reed Knouse Anderson Samar Schwarz Gravengaard King Nash Philpott Rostin de Boer Dournaee Wenzel Tourzan Elley Hodges Monzillo Alexander Nguyen

Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft Microsoft (co-Chair) Netegrity Nokia Nokia Novell Novell Oblix OpenNetwork (Sec) Oracle Oracle Reactivity Reed Elsevier RSA Security RSA Security RSA Security SAP Sarvega SeeBeyond Sony Sun Microsystems Sun Microsystems Sun Microsystems Systinet The IDA of Singapore

WSS: UsernameToken Profile Copyright ? OASIS Open 2002-2004. All Rights Reserved.

15 March 2004 Page 3

Don John Phillip Mark Hemma

Adams Weiland Hallam-Baker Hays Prafullchandra

TIBCO US Navy VeriSign Verisign VeriSign

14

15 Abstract:

16

This document describes how to use the UsernameToken with the Web Services

17

Security (WSS) specification.

18 Status:

19

This is a technical committee document submitted for consideration by the OASIS Web

20

Services Security (WSS) technical committee. Please send comments to the editors.

21

If you are on the wss@lists.oasis- list for committee members, send comments

22

there. If you are not on that list, subscribe to the wss-comment@lists.oasis- list

23

and send comments there. To subscribe, send an email message to wss-comment-

24

request@lists.oasis- with the word "subscribe" as the body of the message.

25

For patent disclosure information that may be essential to the implementation of this

26

specification, and any offers of licensing terms, refer to the Intellectual Property Rights

27

section of the OASIS Web Services Security Technical Committee (WSS TC) web page

28

at . General OASIS IPR information

29

can be found at .

WSS: UsernameToken Profile Copyright ? OASIS Open 2002-2004. All Rights Reserved.

15 March 2004 Page 4

30 Table of Contents

31 1 Introduction ................................................................................................................................ 3

32 2 Notations and Terminology ........................................................................................................ 3

33

2.1 Notational Conventions....................................................................................................... 3

34

2.2 Namespaces....................................................................................................................... 3

35

2.3 Acronyms and Abbreviations .............................................................................................. 3

36 3 UsernameToken Extensions ...................................................................................................... 3

37

3.1 Usernames and Passwords ................................................................................................ 3

38

3.2 Token Reference ................................................................................................................ 3

39

3.3 Error Codes ........................................................................................................................ 3

40 4 Security Considerations ............................................................................................................. 3

41 5 References................................................................................................................................. 3

42 Appendix A. Revision History........................................................................................................ 3

43 Appendix B. Notices...................................................................................................................... 3

44

WSS: UsernameToken Profile Copyright ? OASIS Open 2002-2004. All Rights Reserved.

15 March 2004 Page 5

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download