OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

office message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Updated: (OFFICE-3466) ODF 1.2 CD05-1 10.4.4<draw:image> xlink:href case Repudiatable



     [ http://tools.oasis-open.org/issues/browse/OFFICE-3466?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Dennis Hamilton updated OFFICE-3466:
------------------------------------

    Component/s: Security

> ODF 1.2 CD05-1 10.4.4 <draw:image> xlink:href case Repudiatable
> ---------------------------------------------------------------
>
>                 Key: OFFICE-3466
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-3466
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: Graphics, Part 1 (Schema), Security
>    Affects Versions: ODF 1.2 CD 05
>            Reporter: Dennis Hamilton
>             Fix For: ODF 1.2 CD 06
>
>
> When the xlink:href form of <draw:image> is used, the image is not captured in the document markup.
> That means that any digital signature of the markup does not include the image that may have been presented to the user, it only includes the xlink:href that is not to content that is part of the signed material.
> In this case, an user that requests the document be signed may believe that the image that is presented is included in that signature.  Alternatively, an user can repudiate that the document with a particular image presented is the one that was signed, because the image itself is not covered by the document signature.
> One way for a producer to safeguard that is to include a cache of the image that was rendered (if it was rendered) in the <draw:image> element in some way.  There is no provision for such a means of assuring, by it being included in the signature, that the user signed the document as seen when that particular image was presented.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]