[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: DSig & DOM & Databases

  • From: Paul Spencer <paul.spencer@b...>
  • To: Tony Coates <Tony.Coates@r...>, xml-dev@l...
  • Date: Wed, 04 Apr 2001 10:54:08 +0100

dom databases
You need to differentiate between the meaning of the document and the
lexical representation. The signature works at the lexical level, so
everything is significant. This includes, for example, whether you use
single or double quotes round attribute values. The simple answer is
therefore that you cannot do *any* manipulation of the data. Even reading a
document into a DOM where part of the document is signed, manipulating the
unsigned part, then writing it back could invalidate the signature as the
DOM processing will not preserve the lexical aspects of the document.

That is the bad news. The good news is canonicalization (c14n). By putting
the document into a standard canonicalized form before signing it, you can
manipulate the document later and put it back into the same canonicalized
form. Depending on what you have been doing to the document in the meantime,
this should preserve the validity of the signature. The W3C has a c14n REC
http://www.w3.org/TR/xml-c14n.

Paul Spencer
CTO, alphaXML Ltd
alphaXML is recruiting XML Consultants
+44 (0)1491 630053
http://www.alphaxml.com


-----Original Message-----
From: Tony Coates [mailto:Tony.Coates@r...]
Sent: 03 April 2001 15:59
To: xml-dev@l...
Subject: DSig & DOM & Databases




Does anyone have any experience with dealing with digitally signed XML
documents
that are loaded into the DOM or stored in tables in a database?  I'm
interested
in(i) the question of what limited manipulations you can do without
invalidating
the signature, and (ii) the question of whether you need to keep textual
copies
of all attributes values and element content to be able to regenerate the
original document without invalidating the signature.  All comments
gratefully
received,

     Cheers,
          Tony.
========
Anthony B. Coates
Leader of XML Architecture & Design
Chief Technology Office
Reuters Plc, London.
tony.coates@r...
========


-----------------------------------------------------------------
        Visit our Internet site at http://www.reuters.com

Any views expressed in this message are those of  the  individual
sender,  except  where  the sender specifically states them to be
the views of Reuters Ltd.

------------------------------------------------------------------
The xml-dev list is sponsored by XML.org, an initiative of OASIS
<http://www.oasis-open.org>

The list archives are at http://lists.xml.org/archives/xml-dev/

To unsubscribe from this elist send a message with the single word
"unsubscribe" in the body to: xml-dev-request@l...


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.