> Is [1] sufficient for your concerns about base64?
> [1]

The relevant point is:

     4. what is the canonical form for base64Binary values?

     Respose: Option A: 76 characters from the base64 alphabet, then a
     sequence; repeat as needed; last line of more than 0, less than 76
     characters, also terminated by newline sequence.

But I am not sure about the consequences of introducing a canonical form for
base64Binary values: Is a schema validating parser enforced to report only
canonical form of the value to the application?

  * If yes, then my concerns are addressed, if the signature application is
    ENFORCED to produce the canonical form of the digest value's base64
    lexical representation.

  * In the current draft of XMLDSIG, this enforcement is not established.
    Without such an enforement, the signature will break if the creator
    of a signature does not produce the canonical representation, and if
    the validator of the signature uses a validating parser.

  * If no, my concerns are not addressed.

