Hi,

I had a question regarding the Project Status page at 
http://cxf.apache.org/project-status.html.  It says "Client side done" for 
WS-Trust.  I was wondering what there is to implement on the server side unless 
CXF were to implement it own STS server.  From my limited knowledge, the server 
side of WS-Trust is pretty much the WS-Security stuff for encrypting and 
signing the messages to the client after the client initially obtains the token 
from the STS.  It seems like that part is already complete for CXF.  

Could you let me know what WS-Trust work still needs to be done for the server 
side and if my previous assumption regarding the function of participating 
services in WS-Trust is correct?

Thanks,

Brandon Richins

Reply via email to