| From | Sent On | Attachments |
|---|---|---|
| robe...@entrust.com | Mar 24, 2003 12:58 pm | |
| Gregor Karlinger | Mar 25, 2003 7:34 am | .bin |
| Trevor Perrin | Mar 25, 2003 11:30 am | |
| Nick Pope | Mar 25, 2003 11:35 am | |
| Nick Pope | Mar 25, 2003 12:23 pm | |
| Trevor Perrin | Mar 25, 2003 12:29 pm | |
| Trevor Perrin | Mar 25, 2003 12:33 pm | |
| jmessing | Mar 25, 2003 12:36 pm | |
| Trevor Perrin | Mar 25, 2003 1:18 pm | |
| Nick Pope | Mar 25, 2003 1:21 pm | |
| Nick Pope | Mar 25, 2003 1:21 pm | |
| Nick Pope | Mar 26, 2003 1:21 am | |
| kare...@esat.kuleuven.ac.be | Mar 26, 2003 4:02 am | |
| Nick Pope | Mar 26, 2003 5:22 am | |
| jmessing | Mar 26, 2003 5:26 am | |
| Trevor Perrin | Mar 26, 2003 10:49 am | |
| jmessing | Mar 26, 2003 10:57 am | |
| Trevor Perrin | Mar 26, 2003 11:11 am | |
| Rich Salz | Mar 26, 2003 11:24 am | |
| Trevor Perrin | Mar 26, 2003 1:15 pm | |
| Greg Alvord | Mar 27, 2003 4:37 am | |
| Gregor Karlinger | Mar 27, 2003 9:01 am | .bin |
| Trevor Perrin | Mar 27, 2003 1:17 pm | |
| Nick Pope | Mar 28, 2003 3:54 am | |
| Trevor Perrin | Mar 28, 2003 1:52 pm | |
| Nick Pope | Mar 29, 2003 9:35 am | |
| Rich Salz | Mar 29, 2003 10:10 am | |
| Trevor Perrin | Mar 29, 2003 10:14 am | |
| Rich Salz | Mar 29, 2003 10:36 am | |
| jmessing | Mar 29, 2003 11:19 am | |
| Rich Salz | Mar 29, 2003 11:26 am | |
| Trevor Perrin | Mar 29, 2003 11:46 am | |
| jmessing | Mar 29, 2003 12:31 pm | |
| Rich Salz | Mar 29, 2003 3:35 pm | |
| Trevor Perrin | Mar 30, 2003 1:49 am | |
| Gregor Karlinger | Mar 30, 2003 10:50 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:07 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:18 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:23 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:31 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:47 am | .bin |
| Gregor Karlinger | Mar 30, 2003 11:58 am | .bin |
| Gregor Karlinger | Mar 30, 2003 12:14 pm | .bin |
| Gregor Karlinger | Mar 30, 2003 12:23 pm | .bin |
| Rich Salz | Mar 30, 2003 2:25 pm | |
| Gregor Karlinger | Mar 30, 2003 11:14 pm | .bin |
| Gregor Karlinger | Mar 30, 2003 11:20 pm | .bin |
| Gregor Karlinger | Mar 30, 2003 11:26 pm | .bin |
| Gregor Karlinger | Mar 30, 2003 11:30 pm | .bin |
| Gregor Karlinger | Mar 30, 2003 11:37 pm | .bin |
| Trevor Perrin | Mar 31, 2003 1:41 am | |
| Gregor Karlinger | Mar 31, 2003 1:48 am | .bin |
| Gregor Karlinger | Mar 31, 2003 1:56 am | .bin |
| Nick Pope | Mar 31, 2003 4:02 am | |
| Anthony Nadalin | Mar 31, 2003 5:15 am | |
| Karel Wouters | Mar 31, 2003 6:30 am | |
| Gregor Karlinger | Mar 31, 2003 7:22 am | .bin |
| Trevor Perrin | Mar 31, 2003 8:46 am | |
| Gregor Karlinger | Mar 31, 2003 1:20 pm | .bin |
| Nick Pope | Apr 1, 2003 1:32 am | |
| Karel Wouters | Apr 1, 2003 2:52 am | |
| Nick Pope | Apr 1, 2003 2:52 am | |
| Nick Pope | Apr 1, 2003 3:03 am |
| Subject: | RE: [dss] Groups - dss-requirements-1.0-draft-02.doc uploaded | |
|---|---|---|
| From: | Gregor Karlinger (greg...@cio.gv.at) | |
| Date: | Mar 31, 2003 1:56:51 am | |
| List: | org.oasis-open.lists.dss | |
| Attachments: | ![]() bin00022.bin - 13k | |
Trevor,
-----Original Message----- From: Trevor Perrin [mailto:tre...@trevp.net] Sent: Monday, March 31, 2003 11:49 AM To: Gregor Karlinger Cc: 'ML OASIS DSS' Subject: RE: [dss] Groups - dss-requirements-1.0-draft-02.doc uploaded
At 09:17 PM 3/30/2003 +0200, Gregor Karlinger wrote:
I suggest therefore the following definition:
"For use cases where the relying party would like to check the relationship between the the 'transforms process input data' (which is the data he wants to operate on) and the 'transforms process output data' (which is the data the signing party has actually signed) all the information used by the signing party to compute the transforms process must be signed. Most of this information is included in a XMLDSIG signature anyway. However, there are some exceptions, for instance imported stylesheets referred to in an XSLT transform. Those additional information must be signed as well, for instance as part of a dsig:Manifest."
I see I was misinterpreting things - all you're saying is that imported stylesheets within an XSLT transform should have their contents covered by the signature. Since XML-DSIG doesn't accomplish this, you suggest adding a reference in the XML-DSIG Signature to a dsig:Manifest which then references these imported stylesheets.
Since this solution addresses a problem with XML-DSIG, I don't think it's within our scope to mandate something like that. But we should make sure that something like that is possible within our DSS protocol, and whether it needs any special requirements.
I agree. We should not make this mandatory, but it should be possible for the requester to say "please sign all information used to compute the transform process".
The only requirement I can see this adding, is that if the client is applying transforms to the to-be-signed data himself, then sending the transformed data to the server for a signature, then maybe the client should also send the imported stylesheets, i.e. "additional transform data", so the server can link them in somehow?
This is a side issue. The important requirement is what I have stated above. But you are right, it should also be possible for the requester to make the statement cited above in the case he processes the trasforms himself.
/Gregor






.bin