mace-opensaml-users - Re: [opensaml] Default Canonicalization Algorithm
Subject: OpenSAML user discussion
List archive
- From: Chad La Joie <>
- To: mace-opensaml-users <>
- Subject: Re: [opensaml] Default Canonicalization Algorithm
- Date: Thu, 31 Jan 2008 13:55:44 +0100
- Organization: SWITCH
Oh, also just a bit of background on this.
OpenSAML 1.0 was just an SAML library, so all the code was really trying to implement exactly what the SAML specifications said. The new OpenSAML 2.0 library is actually a library stack. Signature and Encryption support is actually located in the XMLTooling library. This library is meant to be generic and allow things, like OpenSAML, to be built on top of it. So, naturally, that lower level library can't make the same number of assumptions as the OpenSAML 1 library could.
That said, I'm all for trying to encode reasonable, best-practice, behavior into the library as long as it doesn't prohibit people from changing it for some reason.
Dimuthu Leelarathne wrote:
Hi All,
I think the new opensaml implementation is really good. It has good
javadocs and very intuitive.
I'd like to put forward my idea as a user. If you guys can set a default
CanonicalizationAlgorithm to the Signature object, it will be good.
I am saying that because when using opensaml-1.0 I was unaware of the
the canonicalization method, and when using the new library, in order to
fix a signature verification problem I had to read about the four C14N
canonicalization methods.
Thank you,
Dimuthu
--
SWITCH
Serving Swiss Universities
--------------------------
Chad La Joie, Software Engineer, Security
Werdstrasse 2, P.O. Box, 8021 Zürich, Switzerland
phone +41 44 268 15 75, fax +41 44 268 15 68
,
http://www.switch.ch
- [opensaml] Default Canonicalization Algorithm, Dimuthu Leelarathne, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Chad La Joie, 01/31/2008
- RE: [opensaml] Default Canonicalization Algorithm, Scott Cantor, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Chad La Joie, 01/31/2008
- Message not available
- Re: [opensaml] Default Canonicalization Algorithm, Brent Putman, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Chad La Joie, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Brent Putman, 01/31/2008
- RE: [opensaml] Default Canonicalization Algorithm, Scott Cantor, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Chad La Joie, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Dimuthu Leelarathne, 01/31/2008
- Re: [opensaml] Default Canonicalization Algorithm, Chad La Joie, 01/31/2008
Archive powered by MHonArc 2.6.16.