W3C home > Mailing lists > Public > public-webapps@w3.org > October to December 2009

Re: Widget DigSign: Example of a distributor signature document is buggy

From: Frederick Hirsch <frederick.hirsch@nokia.com>
Date: Wed, 7 Oct 2009 13:47:49 -0400
Cc: Frederick Hirsch <frederick.hirsch@nokia.com>, "public-Webapps@w3.org" <public-Webapps@w3.org>, Marcos Caceres <marcosc@opera.com>, "Priestley, Mark, VF-Group" <Mark.Priestley@vodafone.com>
Message-Id: <38CC0A4F-4792-429D-AAEF-CD1F3759325F@nokia.com>
To: "ext Breitschwerdt, Christian, VF-Group" <christian.breitschwerdt@vodafone.com>
Christian

You are correct, thank you for catching this error.

I have updated the editors draft accordingly.

http://dev.w3.org/2006/waf/widgets-digsig/#example

regards, Frederick

Frederick Hirsch
Nokia



On Oct 6, 2009, at 9:44 AM, ext Breitschwerdt, Christian, VF-Group  
wrote:

> Hi Marcos,
>
> The position of the <object> element in the example provided in
> http://www.w3.org/TR/widgets-digsig/ section 1.4 is not correct in  
> that
> the <object> occurs before the <SignatureValue>.
>
> The DTD provided fo the XMLDIG11
> http://www.w3.org/TR/2009/WD-xmldsig-core1-20090226/xmldsig-core-schema 
> .
> dtd and also the example
> http://www.w3.org/TR/2009/WD-xmldsig-core1-20090226/signature-example.xm
> l instruct us that it should occur AFTER the <SignatureValue>.
>
> The major problem with the example is that even it is non-normative it
> may be used by implementors as a template, and some existing XML
> security tools  chains (i.e. Apache XML security library) will fail to
> process a template that has the <object> in the wrong order.
>
> Kind regards,
> Christian
>
Received on Wednesday, 7 October 2009 17:48:54 GMT

This archive was generated by hypermail 2.3.1 : Tuesday, 26 March 2013 18:49:34 GMT