OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xri message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xri] Agenda: XRI TC Telecon 2-3PM PT Thursday 2009-06-04


Drummond Reed wrote on 2009-06-03:
> 1) ADOPTION OF CONSTRAINED XML DSIG AS XRD SIGNING METHOD
> 
> We will continue the discussion from last week's call and the email list -
> see the thread working backwards from:
> 
> 	http://lists.oasis-open.org/archives/xri/200905/msg00076.html
> 
> All TC members who care about XRD signing methods are urged to attend this
> call to discuss this.

My apologies, I have a one-time conflict and can't make this call
unfortunately.

I think I've said my peace, and my technical background and priorities are
sufficiently different from the other players here that I don't think I
could add too much more in any case.

My concerns about the proposal in the wiki are such that I would urge
*either* that XML Signature be used directly (in the constrained form I
suggested) or not at all. Using it only half-way and then plugging in c14n
methods and restrictions that wouldn't be compatible with existing
implementations of the standard is definitely suboptimal.

If XML Signature isn't going to fly, then personally I would say serialize,
base64, sign it with one or more standard algorithms, and then create an XML
structure with the blob, the signature value, and the algorithm URI, and
leave it at that. I don't relish implementing yet another mechanism like
that, but it's the second best choice.

Sorry again for having to skip out...

-- Scott




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]