{"id":119,"date":"2005-06-09T20:32:17","date_gmt":"2005-06-09T20:32:17","guid":{"rendered":"\/?p=119"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-30T04:00:00","slug":"phil-windley-on-ws-policy-and-rest","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=119","title":{"rendered":"Phil Windley on WS-Policy and REST"},"content":{"rendered":"<p dir=ltr>Phil Windley has started a <a href=\"http:\/\/www.windley.com\/archives\/2005\/06\/some_thoughts_a.shtml\">very fascinating thread<\/a> in response to <a href=\"https:\/\/www.identityblog.com\/2005\/06\/07.html#a256\" class=\"broken_link\">my piece<\/a> on WS-Policy.  Since a number of people have found it helpful I&#39;ve decided to go through the other microstandards necessary for InfoCards and do a similar &#8220;identity person&#39;s summary&#8221;.  Clearly I will forgive those who don&#39;t find protocols as interesting as I do &#8211; just skip on by.<\/p>\n<p dir=ltr>Anyway, back to the point&#8230;  Phil&#39;s posting:<\/p>\n<blockquote dir=ltr style=\"MARGIN-RIGHT: 0px\">\n<p>Kim Cameron has a <a href=\"https:\/\/www.identityblog.com\/2005\/06\/07.html#a256\" class=\"broken_link\"><font color=#001e4c>very cogent piece on WS-Policy<\/font><\/a>. In fact, read it and forget the standard. Everything you need to know is in Kim&#146;s description. This was timely because I&#146;ve been considering my article at Between the Lines on a <a href=\"http:\/\/blogs.zdnet.com\/BTL\/?p=1478\" class=\"broken_link\"><font color=#001e4c>RESTful alternative (or augmentation perhaps) to the InfoCard<\/font><\/a> proposal, something that was sparked by <a href=\"http:\/\/garage.docsearls.com\/node\/605\"><font color=#001e4c>some questions from Doc<\/font><\/a>. As I read Kim&#146;s description, I realized that there really no need to redo WS-Policy for REST&#151;it can be used as is. <\/p>\n<p>One way to think about the RESTian argument is to separate out those parts of the WS stack that are about transport and those that are not. SOAP, WSDL, UDDI, WS-MEX, WS-ReliableMessaging, and so on are about defining transport for XML documents. This is especially apparent when you consider the Doc Literal style of using SOAP. The goal is to define an <a href=\"http:\/\/www.windley.com\/archives\/2005\/05\/don_box_on_wsme.shtml\"><font color=#001e4c>HTTP-independent way of transporting XML documents around<\/font><\/a> in order to define services. The other standards are ways of <em>declaring<\/em> meta information about the service. <\/p>\n<p>The REST folks argue &#147;why replace HTTP?&#148; Just forget SOAP and use HTTP instead. There&#146;s some real meat to this argument. In particular, RESTful services seem to be easier to use. My point, however, is not to convince you to use REST or SOAP, but to convince you that these are just two different ways of transporting XML documents around. <\/p>\n<p>What the RESTians have not done, however, is to define solutions to the very problems that most of the WS-* stack addresses. I believe we need to come up with <a href=\"http:\/\/www.windley.com\/archives\/2005\/03\/toward_more_sop.shtml\"><font color=#001e4c>equivalent alternatives<\/font><\/a> in the REST world for things like WS-MEX or WSDL&#151;all the transport related stuff. We don&#146;t, however, need to replace the XML documents and the security and policy declarations that accompany them. <\/p>\n<p>Things like WS-Policy and WS-Security could just as easily be used with RESTful services as they could with SOAP-based services. Sure, we&#146;d need some conventions to pass the reference for the declaration in the message header so that it accompanies the XML document and maybe a few other things, but I think it&#146;s workable. If you read through Kim&#146;s description of WS-Policy, you&#146;ll see that the issues it solves and the ways it does so would work very well in a RESTful service.<\/p>\n<\/blockquote>\n<p dir=ltr>I&#39;m going to send this link to <a href=\"http:\/\/pluralsight.com\/blogs\/dbox\/\" class=\"broken_link\">Don Box<\/a> and see what he has to say about it.  He has thought about these more general issues a lot more than I have.  I&#39;m really just an identity person looking for a way to build a metasystem that will encompass many security and privacy technolgies, allowing us to build a unified fabric rather than a patchwork solution.<\/p>\n<p dir=ltr>\n","protected":false},"excerpt":{"rendered":"<p>Phil Windley has started a very fascinating thread in response to my piece on WS-Policy. Since a number of people have found it helpful I&#39;ve decided to go through the other microstandards necessary for InfoCards and do a similar &#8220;identity person&#39;s summary&#8221;. Clearly I will forgive those who don&#39;t find protocols as interesting as I &hellip; <a href=\"https:\/\/www.identityblog.com\/?p=119\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Phil Windley on WS-Policy and REST<\/span><\/a><\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/119"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=119"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/119\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}