mace-opensaml-users - RE: verifying signature on saml assertions
Subject: OpenSAML user discussion
List archive
- From: Scott Cantor <>
- To: ,
- Subject: RE: verifying signature on saml assertions
- Date: Wed, 16 Apr 2003 10:37:27 -0400
- Importance: Normal
- Organization: The Ohio State University
> toStream() canonizes before output. shouldn't this
> happen within the sign() code specified as a
> transform, so that the verify routine can properly
> apply the reverse transforms to obtain the pre-singed
> version of the element?
No, the point of the simple flag hack is to tell it that the SAML is alone in
the document. DSig always runs inclusive c14n as the
final step when the input is a node set. If excl c14n is needed to deal with
namespace bleed in, that has to be a transform.
I use c14n so that the XML can move across a network and still verify, which
is a separate issue.
None of this will work reliably until SAML 1.1, so I actually suggest people
don't waste a lot of their time on this.
As soon as the schema changes for 1.1 are approved by the SSTC, I'm probably
going to drop a new schema in for it and start using
it. This is too painful to keep screwing around with.
If anybody is trying to interop with a commercial SAML 1.0 product, I might
reconsider, but I can't see that being too likely yet.
-- Scott
---------------------------------------------------mace-opensaml-users-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at
http://archives.internet2.edu/
---------------------------------------------------mace-opensaml-users--
- verifying signature on saml assertions, Rakesh Aggarwal, 04/11/2003
- Re: verifying signature on saml assertions, mochamaster, 04/11/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/12/2003
- <Possible follow-up(s)>
- RE: verifying signature on saml assertions, Rakesh Aggarwal, 04/14/2003
- RE: verifying signature on saml assertions, mochamaster, 04/14/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/14/2003
- RE: verifying signature on saml assertions, mochamaster, 04/15/2003
- RE: verifying signature on saml assertions, mochamaster, 04/15/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/16/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/16/2003
- RE: verifying signature on saml assertions, mochamaster, 04/16/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/16/2003
- RE: verifying signature on saml assertions, mochamaster, 04/16/2003
- RE: verifying signature on saml assertions, mochamaster, 04/15/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/14/2003
- RE: verifying signature on saml assertions, mochamaster, 04/14/2003
- RE: verifying signature on saml assertions, Rakesh Aggarwal, 04/14/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/14/2003
- RE: verifying signature on saml assertions, Rakesh Aggarwal, 04/14/2003
- RE: verifying signature on saml assertions, Scott Cantor, 04/14/2003
- RE: verifying signature on saml assertions, Rakesh Aggarwal, 04/16/2003
Archive powered by MHonArc 2.6.16.