OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ubl-security message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Revision of Draft 11 of the UBL Digital Signature Profile for review


[Re-sending this message under a corrected subject header]

Andrea Caccia wrote:
> Page 5: XAdES contains several modules that permit various levels of 
> security, such as non-repudiation with timestamps and long-term 
> signature verification
> --> XAdES contains several modules that permit various levels of 
> security, such as content commitment and non-repudiation enforcement 
> with timestamps and long-term signature verification

Done.

> Page 11: Non-repudiation (or content commitment): the document signer 
> cannot deny ...
> --> Non-repudiation / content commitment: the document signer cannot deny…

I think we're trying to say that both terms refer to the same thing, so
I would suggest:

      <para>Non-repudiation (content commitment): the document
        signer cannot deny its involvement in creating and/or
        approving the document (depending on the context and signer
        role).</para>

> Page 13: XAdES-T, where a timestamp is added to enforce non-repudiation 
> and as a proof of anteriority. This envelope allows ascertaining the 
> validity of a signature in case the signer certificate is later revoked;
> --> XAdES-T, where a timestamp is added to enforce content commitment 
> and as a proof of anteriority. This envelope allows ascertaining the 
> validity of a signature in case the signer certificate is later revoked;

Here I would suggest:

      <para><emphasis role="bold">XAdES-T</emphasis>, where a
         timestamp is added to enforce content commitment
         (non-repudiation) and as a proof of anteriority. This
         envelope allows ascertaining the validity of a signature in
         case the signer certificate is later revoked;</para>

> Page 13: Business requirements. A digital signature can reduce the risks 
> associated with a business transaction (e.g., non-repudiation of a 
> commercial order, proof-of-origin and integrity of an invoice)...
> --> Business requirements. A digital signature can reduce the risks 
> associated with a business transaction (e.g., content commitment of a 
> commercial order, proof-of-origin and integrity of an invoice)…

Done.

Results are attached.

> I please ask Jon to apply these changes (after checking EnglishÂ…)
> while thanking him for his patience.

It is my pleasure to play some role in your work, Andrea. Please let me
know when the ASiC URL becomes available.

Best regards,

Jon



20110426-cd11.zip

---------------------------------------------------------------------
To unsubscribe from this mail list, you must leave the OASIS TC that
generates this mail.  Follow this link to all your TCs in OASIS at:
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php 


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]