OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ubl-security message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [ubl-security] Draft 10 of the UBL Digital Signature Profilefor review


Andrea Caccia wrote:
> Page 5: XAdES contains several modules that permit various levels of 
> security, such as non-repudiation with timestamps and long-term 
> signature verification
> --> XAdES contains several modules that permit various levels of 
> security, such as content commitment and non-repudiation enforcement 
> with timestamps and long-term signature verification

Done.

> Page 11: Non-repudiation (or content commitment): the document signer 
> cannot deny ...
> --> Non-repudiation / content commitment: the document signer cannot deny…

I think we're trying to say that both terms refer to the same thing, so
I would suggest:

     <para>Non-repudiation (content commitment): the document
       signer cannot deny its involvement in creating and/or
       approving the document (depending on the context and signer
       role).</para>

> Page 13: XAdES-T, where a timestamp is added to enforce non-repudiation 
> and as a proof of anteriority. This envelope allows ascertaining the 
> validity of a signature in case the signer certificate is later revoked;
> --> XAdES-T, where a timestamp is added to enforce content commitment 
> and as a proof of anteriority. This envelope allows ascertaining the 
> validity of a signature in case the signer certificate is later revoked;

Here I would suggest:

     <para><emphasis role="bold">XAdES-T</emphasis>, where a
        timestamp is added to enforce content commitment
        (non-repudiation) and as a proof of anteriority. This
        envelope allows ascertaining the validity of a signature in
        case the signer certificate is later revoked;</para>

> Page 13: Business requirements. A digital signature can reduce the risks 
> associated with a business transaction (e.g., non-repudiation of a 
> commercial order, proof-of-origin and integrity of an invoice)...
> --> Business requirements. A digital signature can reduce the risks 
> associated with a business transaction (e.g., content commitment of a 
> commercial order, proof-of-origin and integrity of an invoice)…

Done.

Results are attached.

> I please ask Jon to apply these changes (after checking EnglishÂ…)
> while thanking him for his patience.

It is my pleasure to play some role in your work, Andrea. Please let me
know when the ASiC URL becomes available.

Best regards,

Jon


20110426-cd11.zip



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]