Re: Another tentative version of the RELAX NG schemas for XML Signature Syntax and Processing (Second Edition)

Makoto

Thank you for sharing this revised Relax NG schema for XML Signature,  
Second Edition.

XML Signature 1.1 [1] adds some additional elements in the new 1.1  
namespace, which could require some additional RNG schema.  
Specifically, it adds structures for Elliptic Curve algorithms, an  
OCSP response in KeyInfo, and a DEREncodedKeyValue type. (I've  
attached the XSD schema file for the additions).

Perhaps you could take a look and see what would be needed to create  
an XML Signature 1.1 RNG Schema? If so perhaps I should share with the  
W3C Device APIs WG, since BONDI 1.01 has defined RNG schemas for XML  
Signature [2] and might also  consider to use your latest version.

regards, Frederick

Frederick Hirsch
Nokia

[1] http://www.w3.org/2008/xmlsec/Drafts/xmldsig-core-11/Overview.htm

[2] http://bondi.omtp.org/1.01/security/xmldsig-core-schema.rnc

On Oct 17, 2009, at 9:53 AM, ext MURATA Makoto (FAMILY Given) wrote:

> Dear colleagues,
>
> Attached please find a revised version of the RELAX NG schemas for
> XML Signature Syntax and Processing (Second Edition).
>
> Unlike the XSD version, it is possible to easily customize the  
> attached
> xmldsig-core-schema.rnc for a particular application of XML Signature.
> Depending on the value of @Algorithm, different content models are
> specified.
>
> I plan to combine this schema and the Open Packaging Convention (ISO/ 
> IEC
> 29500-2) schema so as to impose tighter constraints.  This experiment
> is likely to require some changes to these schemas, but I do not think
> that the changes will be drastic.
>
> Cheers,
> Makoto
> <any-containing-xmldsig.rnc><xmldsig-core-schema.rnc>

Received on Friday, 30 October 2009 15:24:53 UTC