dss-x — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Proposal for SignatureIdentifier-structure
Hallo Juan Carlos,
thanks for your mail. I briefly included some remarks below.
> Thanks for the message and sorry for not reacting before.
> I essentially agree in the principles that lead your
> proposal, ie to define mechanisms that allow for identifying
> signatures in the two group of situations we mentioned in our
> conf call....
>
> Looking at the specific proposal I would like to make some comments:
>
> 1. I agree that the signed properties are worth for
> identifying signatures when the relationships in
> dss:VerificationRequest have been lost. We could discuss
> whether the signing certificate information could be
> mandatory in that case, so that we identify the signature by
> its value and its generator.
Yes, the signing certificate should be included - at least
in all cases in which there is a signing certificate. As this
would not work for all PGP-signatures for example it might be
a problem to make this requirement strictly mandatory.
In the end the signed properties, which are included should
be sufficient to identify the signature unambigiously. Hence
another good candidate might be the SigningTime (again, if it is
included in the signature).
As we can not impose requirements with respect to the existence of
certain properties, the mechanism should allow to include any signed
property and we should only provide recommendations, which signed properties
SHOULD be used if they are existing.
> In addition I miss what the vr:
> prefix stands for?
vr is simply the abbreviation for Verification Report.
>
> 2. Just making a kind of brainstorming, could we optionally
> include also the digest of the document where the signature
> is? in the case of multiple documents and multiple enveloped
> signatures this would avoid to dig in the bytes of the
> documents until finding the pointed signature...just
> computing the digest of the documents we could identify
> it....Just a first idea that has come into my mind when
> reading your proposal.
Good idea.
>
> 2. As for the attributes, I agree that we should provide also
> mechanisms for pointing at a signature within a binary document....
OK.
BR,
Detlef
>
> Regards
>
> Juan Carlos.
> Huehnlein, Detlef escribió:
>
> Hallo all,
> >
>
> as briefly discussed during our last phone call, we need to define
>
> some generalization of the
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]