Makoto
Thank you for sharing this revised Relax NG schema for XML Signature,
Second Edition.
XML Signature 1.1 [1] adds some additional elements in the new 1.1
namespace, which could require some additional RNG schema.
Specifically, it adds structures for Elliptic Curve algorithms, an
OCSP response in KeyInfo, and a DEREncodedKeyValue type. (I've
attached the XSD schema file for the additions).
Perhaps you could take a look and see what would be needed to create
an XML Signature 1.1 RNG Schema? If so perhaps I should share with the
W3C Device APIs WG, since BONDI 1.01 has defined RNG schemas for XML
Signature [2] and might also consider to use your latest version.
regards, Frederick
Frederick Hirsch
Nokia
[1] http://www.w3.org/2008/xmlsec/Drafts/xmldsig-core-11/Overview.htm
[2] http://bondi.omtp.org/1.01/security/xmldsig-core-schema.rnc
On Oct 17, 2009, at 9:53 AM, ext MURATA Makoto (FAMILY Given) wrote:
> Dear colleagues,
>
> Attached please find a revised version of the RELAX NG schemas for
> XML Signature Syntax and Processing (Second Edition).
>
> Unlike the XSD version, it is possible to easily customize the
> attached
> xmldsig-core-schema.rnc for a particular application of XML Signature.
> Depending on the value of @Algorithm, different content models are
> specified.
>
> I plan to combine this schema and the Open Packaging Convention (ISO/
> IEC
> 29500-2) schema so as to impose tighter constraints. This experiment
> is likely to require some changes to these schemas, but I do not think
> that the changes will be drastic.
>
> Cheers,
> Makoto
> <any-containing-xmldsig.rnc><xmldsig-core-schema.rnc>