OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

office message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Commented: (OFFICE-2315) Public Comment: ODF1.2 part 1 cd03 - 3.16 digital sig, certificate chain (CLONE)



    [ http://tools.oasis-open.org/issues/browse/OFFICE-2315?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18751#action_18751 ] 

Dennis Hamilton commented on OFFICE-2315:
-----------------------------------------

Malte, I am unclear what you are recommending.

It is my understanding that we are using JTC1 normative language (not the RFC version), so SHALL is the only way to express a mandatory provision.  SHOULD is not a restriction, it is a recommendation.  There is not even a presumption that it is the best choice and that alternatives must be justified.  (We don't even make them implementation-defined in any cases I've noticed.)

I have no opinion how much of Bart's recommendation should be accepted.  I just want to be clear on what the implications of his proposal are.  I am a little concerned about requiring that all files in the package be signed in the META-INF/documentsignatures.xml file.  Is this something that has to be verified as part of verifying the document signature, do you think?  Also, if the signature file is signed, I think it makes it difficult to add further signatures to the same file.  



> Public Comment: ODF 1.2 part 1 cd03 - 3.16 digital sig, certificate chain (CLONE)
> ---------------------------------------------------------------------------------
>
>                 Key: OFFICE-2315
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-2315
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: ODF 1.2 Part 1 CD 4 
>         Environment: This issue applies to OpenDocument-v1.2-part1-cd04 and Public Review of that document.
>            Reporter: Robert Weir 
>            Priority: Blocker
>
> Copied from office-comment list
> Original author: Hanssens Bart <Bart.Hanssens@fedict.be> 
> Original date: 24 Dec 2009 13:37:19 -0000
> Original URL: http://lists.oasis-open.org/archives/office-comment/200912/msg00023.html

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]