OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

xri message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [xri] SimpleSign for estabilishing the authenticity of XRD.


So in the TC call, there was a mention that you are quite close to being in agreement.
Are you settling down to thie algorithm #4 (2.4 in the wiki)?

I have still got a feeling that 2.2 way of doing it might not be that hard, and trying to figure them out in various languages, but yes, 2.4 is bullet proof, though the size of the document gets more than dobuled. (Perhaps we can gzip the string to make it slightly better.)

=nat

________________________________________
差出人: Brian Eaton [beaton@google.com]
送信日時: 2008年12月12日 2:52
宛先: John Bradley
CC: Sakimura Nat; Markus Sabadello; XRI TC; Drummond Reed
件名: Re: [xri] SimpleSign for estabilishing the authenticity of XRD.

On Thu, Dec 11, 2008 at 8:23 AM, Brian Eaton <beaton@google.com> wrote:
> A third possibility would be to accept that you really want to be able
> to move XML elements from document to document, munge them as
> necessary, and still be able to verify the signatures.  XML DSIG is
> really the right tool for that.

I forgot the fourth option that Nat already proposed, including both
an XML version and a base64 version of the content in the document.

Those who need security would check the signature on the base64
encoded version and use that for their resolution.

Those who don't need security would just use the XML version.


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]