[Prev]

9.5.4 Web Service Client (WSC) Questions

A FE or WSP may act in secondary role of Web Service Client (WSC). If you call other web services you should answer these questions.

  1. Is your software TAS3 or ID-WSF 2.0 compliant?

    Is it certified? When, by whom: ____

  2. Are you able to use Credentials and Privacy Negotiation agent?

  3. Are you able to handle Interaction Redirect if requested by WSP?

  4. What security mechanisms are you willing and able to support

    1. (__) Bearer Token

    2. (__) Holder of Key Token

    3. (__) X509 signature without token

    4. (__) None

  5. Which Policy Enforcement Points do you implement?

    1. (__) Request Out PEP

    2. (__) Response In PEP

    3. (__) Other, please describe: _______________

  6. Which Policy Decision Point do you use?

    1. (__) Internal or built in

    2. (__) External XACML PDP

    3. (__) Other: _______________

  7. Which obligations or policy languages do you use or support? (tick all that apply)

    1. (__) SOL1

    2. (__) Permis

    3. (__) XACML2

    4. (__) Other, please specify: _____________

  8. What obligations do you pledge to honour with respect to user data returned to you?

    Either describe in prose or provide specific policies using Simple Obligations Language 1 (SOL1) or other obligations language you plan to use.

  9. What obligations do you require other party to honour with respect to user data you send?

    Either describe in prose or provide specific policies using Simple Obligations Language 1 (SOL1) or other obligations language you plan to use.

  10. Do you have automatic mechanims for satisfying the obligations you pledged? Please describe: ______________________

  11. What mechanisms do you provide to user and trust network operator to verify that you have complied with your pledges?

  12. What mechanisms do you have or require from others to verify that they have complied with their pledges?


[Prev | Next]