CARVIEW |
Select Language
HTTP/2 200
date: Sun, 12 Oct 2025 01:36:56 GMT
content-type: text/html
content-encoding: gzip
last-modified: Thu, 13 Jul 2023 17:20:23 GMT
cache-control: max-age=2592000, public
expires: Mon, 10 Nov 2025 04:37:35 GMT
vary: Accept-Encoding
access-control-allow-origin: *
x-request-id: 98cba9c2ab01f43c
strict-transport-security: max-age=15552015; preload
x-frame-options: deny
x-xss-protection: 1; mode=block
cf-cache-status: HIT
set-cookie: __cf_bm=i31Vas8ShDM8nJ_fVMvKPs1tBhVpRut4hVyK5qXIkvQ-1760233016-1.0.1.1-KQo__adnX6xyEBjKdBBr0zpBVa1aL52laeIlB3Ltxl6tafqzcR3OqsqmNcqv6iISwswneNOfPnmyEC45E4J0okuBgDu1vsnsB4L8HNAVcag; path=/; expires=Sun, 12-Oct-25 02:06:56 GMT; domain=.w3.org; HttpOnly; Secure; SameSite=None
server: cloudflare
cf-ray: 98d2de7acc5858e1-BLR
alt-svc: h3=":443"; ma=86400
Detached signature of non-sibling elements (?) from helpcrypto helpcrypto on 2014-07-29 (public-xmlsec-comments@w3.org from July 2014)
Detached signature of non-sibling elements (?)
- From: helpcrypto helpcrypto <helpcrypto@gmail.com>
- Date: Tue, 29 Jul 2014 09:30:01 +0200
- To: public-xmlsec-comments@w3.org
- Message-ID: <CAHMQSgsoLcL4LsaAwVctu5WAuzc7ps_CsBOv8Hgi=V_pZ2tJrw@mail.gmail.com>
Hi. Altough XMLDSig [1] is quite old, stable and well-known, I havent been able to understand (maybe a translation/missunderstanding issue) the detached signatures properly. According to [2]: "*The signature is over content external to the Signature element, and can be identified via a URI or transform. Consequently, the signature is "detached" from the content it signs.*" Ok. Detached elements... "*This definition typically applies to separate data objects, but it also includes the instance where the Signature and data object reside within the same XML document but are sibling elements.*" Ok. Signature and object in the same XML doc and siblings. As stated in [3] (I't seems the standard doesnt distinguish between internal/external) "the signature and data can be in separate files or in the same XML file as sibling elements" Shall I understand the "internally detached" *unique valid signature* is where signature and data are brothers (or sisters) [have the same parent]? *Is the following example a valid detached signature? * *<root>* * <my-data>* * <node Id="n"></node>* * <my-data>* * <my-sign> * * <signature ref="n"></signature> </my-sign>* *</root>* Thanks a lot for your help Regards [1] https://www.w3.org/TR/xmldsig-core/ [2] https://www.w3.org/TR/xmldsig-core/#def-SignatureDetached [3] https://msdn.microsoft.com/en-us/library/ms759193%28v=vs.85%29.aspx
Received on Tuesday, 29 July 2014 07:32:42 UTC