OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

dss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [dss] Individual reports for verification response


At 12:33 PM 6/25/2003 +0200, Juan Carlos Cruellas wrote:

>Hi,
>
>I agree that adding individual reports even if the
>verification succeeds could be convenient...
>Concerning the issue that Trevor points out, whether to
>let them as human-readable or machine-readable, well,
>certainly the last one would imply more work, but there are
>over there pieces of work already done dealing with similar
>issues, and we can use them, and besides that, as the
>answers will XML documents, easy XSLT transformations could
>be defined to translate them to a human-readable form....
>So I think that we could initially try to define a  machine-processable
>format....


I agree this would be a neat doodad, like watching your car go through the 
carwash or something.  Is it worth the effort though, if the only point is 
to reassure the user that the signature was verified really good?

Assuming you do want this, we could add a bullet to 3.6.2 "Whether a list 
of signature verification steps should be returned", and:

3.7.6 Signature Verification Steps
   The verification service may return a list of the steps undertaken by 
the server in verifying the signature (such as hashing the document, 
checking the signature, validating the path, checking CRLs, etc.).

Or feel free to suggest better text.

Trevor 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]