ebxml-poc message

Subject: Re: How is this supposed to work?

Message text written by Christopher Ferris
Your statement below makes absolutely no sense
at all. A TPA is an agreement between two parties.
What you cite as a possible DoS attack point
is in fact not possible because the two parties
agreed to the orchestration of the message exchange,
including the response URI for a given message.

>>>>>>>>>> Chris - notice that the Registry publishes its
                        CPP to the world - so anyone can interact
                        with it,  so its very different from the 
                        closed CPA model.

I would agree that RR needs to examine carefully
which features of TR&P are suitable for its use, and 
most certainly agree that if there are deficiencies
in the features available, that we will need to 
address these in a subsequent version of the MS spec.

>>>>>>>>>>> Farrukh replied that he has this all done
                           already in the spec's he put out so far.
                          If so - its hidden well!  So the need is 
                          probably to break out those aspects
                          separately so this is all very clear.
                          We've certainly been struggling with the
                          implementation details this week.


