OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

ubl-security message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [ubl-security] Draft 10 of the UBL Digital Signature Profile for review


At 2011-03-19 21:49 -0400, Jon Bosak wrote:
>Please review this new draft carefully, keeping in mind that the editor
>(me) has very little knowledge of digital signature technology and can
>easily introduce technical errors in the process of working with the
>language.

I found something I didn't see before:  Both the Terms and 
Definitions (1.1.1) and section 2.2 make reference to an enveloping 
signature, yet we don't provide a profile for such.  Should we 
explicitly acknowledge (perhaps in section 2.4) that we are not 
providing a profile for such (so the reader realizes nothing is 
inadvertently missing), or change the existing text to say something 
along the lines of "Two of the ways an XML Signature may be described 
are as detached and enveloped."?  It might be enough that in 2.4 we 
alread say "specifies two profiles..." so the reader knows nothing is missing.

>This document is intended to form part of UBL 2.1 and will be included
>in UBL 2.1 PRD2.  In order to keep to our projected schedule for PRD2, I
>am setting a one-week review cycle for the draft attached.  If any
>member of the Security SC sees something that needs to be corrected or
>added to this draft, please register the change to this mail list before
>COB Sunday 27 March 2011.

Please forgive me that my leave of absence prevented me from 
submitting my comments in a timely fashion.

The document looks good to me, Jon ... thank you for your efforts.

I hope this helps.

. . . . . . . . . . Ken

--
Contact us for world-wide XML consulting & instructor-led training
Crane Softwrights Ltd.          http://www.CraneSoftwrights.com/o/
G. Ken Holman                 mailto:gkholman@CraneSoftwrights.com
Legal business disclaimers:  http://www.CraneSoftwrights.com/legal



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]