X.509 certificate

    One of the advantage of XMLDSIG over PKCS, I read,
is the textual format instead of binary ASN.1 format.
But when it comes to certificates, it is still X.509
certificate which is in binary format. So for a box
to support XMLDSIG, it needs to have both XML parser
as well as ASN.1 parser isnt' it. 

    I understand using XKMS this validation can be 
ofloaded to a key management system. But if a box 
has to do all the validation itself, then does it
require both XML & ASN.1 parser to validate 
certificates isnt it.

thanks
Joseph

Received on Friday, 17 January 2003 17:23:35 UTC