Proposed text for Action Item 122: draft best practice around xpath filter 2

Best Practice X: Prefer the XPath Filter 2 Transform to the XPath Filter 
Transform

Applications should prefer the <a 
href="http://www.w3.org/TR/xmldsig-filter2/">XPath Filter 2 
Transform</a> to the <a 
href="http://www.w3.org/TR/xmldsig-core/#sec-XPath">XPath Filter 
Transform</a> when generating XML Signatures. The XPath Filter 2 
Transform was designed to improve the performance issues associated with 
the XPath Filter Transform and allow signing operations to be expressed 
more clearly and efficiently, as well as helping to mitigate the denial 
of service attacks discussed in section 2.1.2. See 
http://www.w3.org/TR/xmldsig-filter2/#sec-Intro for more information.

--Sean

Received on Monday, 26 January 2009 19:22:17 UTC