OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help

ebxml-transport message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]

Subject: RE: CPA and overrides

Mary Ann,
	I agree with you and stated this same position during the TRP
meetings in Vancouver.  During those meetings, we agreed that the MSH
COULD NOT override values in the CPA.  I thought that this issue was
	The issue remaining is must certain content of the CPA be
communicated inside of the ebXML Header?  Will intermediate MSH need the
information to ensure compliance with the CPA?  And if the first two
questions result in 'YES', then what information is needed?  It is not
reasonable to assume that the entire CPA would be sent, for that matter
it is not reasonable to assume that all values related to the MSH would
be sent.  
	I think that I started this when I pointed out that we have
moved all of the attributes of the QualityOfServiceInto element into the
Reliable Messaging portion of the specification.  The specification
states that the values are in the CPA and that the CPA cannot be
over-ridden. I asked, "Do we need to send the QualityOfServiceInfo
element?"  The group seemed to accept the idea that the element was
still needed and that perhaps additional attributes need to identified
for the element.

Ralph Berwanger  

-----Original Message-----
From: Maryann Hondo [mailto:mhondo@us.ibm.com]
Sent: Friday, February 23, 2001 8:17 AM
To: Dick Brooks
Cc: rsalz@CaveoSystems.com; ebxml-transport@lists.ebxml.org;
Subject: RE: CPA and overrides

Am I the only one who is concerned about this from a security view?
if we allow for "overrides" .....what is the model of who overrides
can i override the "to" part or the "from" part (particularly if i want
muck up the works of my
competition a bit) can i "override" the https protocol with http? and
about "intermediaries"?
are they allowed to "override" things?

how does as2 provide for this type of override? is this ok? is it up to
app to determine if the transaction came over a secure channel?  whose
liability is it
if the sender sends data over an insecure link when a secure link was
agreed to and
some information is "stolen"? are these issues addressed in as2?

i could see defining a default which is used instead of a cpp/cpa or if
there is no cpa referenced,
but i would want to know how the security piece was agreed to by both
parties and how it is possible to
verify that the correct mechanism was used.


Dick Brooks <dick@8760.com> on 02/23/2001 08:44:19 AM

To:   rsalz@CaveoSystems.com, ebxml-transport@lists.ebxml.org,
Subject:  RE: CPA and overrides

I agree with Martha and Rich. Forcing a CPA/CPP module onto an MSH
is an unnecessary burden on those
needing simple, "direct" file transfer over a single transport, which is
majority of implementations
in the Energy industry. The EDIINT AS2 specification made provisions for
multiple transport options by adding
a "receipt-delivery-option" header.  This header contains a URI
the transport and delivery point (e.g.
http://b2b.imacompany.com/cgi-bin/ebxmlhandler or
mailto:ebxmlhandler@imacompany.com ) to send an asynchronous receipt

CPA/CPP functionality is a nice feature for some, but it shouldn't be a
requirement for ALL. If alternate delivery channels are needed for
*acknowledgements* then I suggest a solution like that found in AS2.

Dick Brooks

-----Original Message-----
From: rsalz@CaveoSystems.com [mailto:rsalz@CaveoSystems.com]
Sent: Friday, February 23, 2001 7:57 AM
To: ebxml-transport@lists.ebxml.org; maw2@daimlerchrysler.com
Subject: Re: CPA and overrides

List-Archive: <http://lists.ebxml.org/archives/ebxml-transport>
List-Help: <http://lists.ebxml.org/doc/email-manage.html>,

As I recall the discussion of "override" from the telecon's of a couple
of weeks ago, the concern was that an MSH not be able to change the
delivery semantics that were specified in the CPA.  For example, a
UDP-based MSH could not accept a message intended for ReliableMessaging,
but then silently use BestEffort.

*IF* we put all the delivery semantics into the ebXML message header,
then this question mostly goes away, because there is no CPA involved:
it becomes a quality of implementation issue for how the business app
tells its local MSH what semantics are required *by the business

Requiring an MSH to have to refer to a CPA is clearly a layering


To unsubscribe from this elist send a message with the single word
"unsubscribe" in the body to: ebxml-transport-request@lists.ebxml.org

To unsubscribe from this elist send a message with the single word
"unsubscribe" in the body to: ebxml-transport-request@lists.ebxml.org

To unsubscribe from this elist send a message with the single word
"unsubscribe" in the body to: ebxml-transport-request@lists.ebxml.org

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]

Search: Match: Sort by:
Words: | Help

Powered by eList eXpress LLC