OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]
Trying to understand XML signatures

Hi, I'm trying to get a full understanding of XML signatures (for
verification, not creation), and to this end I want to actually
perform each of the individual verification steps myself rather than
using something like the xmlsec library.

Given an xml signature containing the following:


what is the correct method for calculating the actual signature
digest. Doing an sha1 digest over all of the above produces a value as


however this is not the value that is expected - the actual value
expected according to the signature is


(The source data is all in one line - no line breaks, no extra
whitespace etc, and passing it through c14n does not alter the data in
any way. I'm using xmlC14NDocDumpMemory from libxml2 to get that for

What I'm trying to figure out is where am I going wrong. I though I
had figured out how this stuff works, but obvisouly not...
Am I trying to digest too much info, not enough info, or just the wrong info???

I know this is all very much a case of reinventing the wheel, but I
like to understand exactly what is going on and be able to reproduce
it myself just to prove that I really do get it. Just calling a few
'black box' functions in a library does not really give me what I feel
to be a full understanding of things.

In case it helps, a more readable version of the data is as follows
(this has been modified, so will not verify)

<Signature xmlns="http://www.w3.org/2000/09/xmldsig#";>
<SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1";>
<Reference URI="#m2048786">
<DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1";>

All the X509 certificates decode and verify ok, and I am able to
decrypt the data in signature value ok using the relevant public key.

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]

News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 1993-2007 XML.org. This site is hosted by OASIS