Re: [Java] XML Signature on external files

2004-02-29 Thread Berin Lautenbach
Johan, I had a long think about this one. I can't think of a better way to achieve what you are trying to do, other than potentially using a manifest embedded in the body of your document. However a manifest is hashed and checked during signature verification, so if the file name changed,

Re: Decrypt using KeyInfo

2004-02-29 Thread Berin Lautenbach
Hyejung, Oops. I missed this - apologies! Did you get this working? My first thought would be that you are trying to create a key using SecretKeySpec ks = new SecretKeySpec(encryptionKeyCipherValue.getValue().getBytes(), ek.getEncryptionMethod().getAlgorithm()); Which

DO NOT REPLY [Bug 25509] - Signature veryfication fails when used with SAML

2004-02-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://nagoya.apache.org/bugzilla/show_bug.cgi?id=25509. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND INSERTED IN THE BUG DATABASE.

Re: [Patch] build-ant1.5.xml

2004-02-29 Thread Berin Lautenbach
Vishal, I just went to apply this, and it looks like it might have already been done by Axl, a few days before this e-mail?? Could you just confirm for me? Cheers, Berin Vishal Mahajan wrote: Hi All, Please find attached a patch for build-ant1.5.xml file in the xml-security

RE: Using XML security slows down the Axis Call

2004-02-29 Thread Davanum Srinivas
Scott, Berin, Was reviewing the codeQuestion - If we write a class that extends SignatureAlgorithm (see SignatureBaseRSA$SignatureRSASHA1 for example, we should be able to use the NativeJCE jar without having to sign it first). Right? Has anyone looked in the Claymore stuff?

RE: Using XML security slows down the Axis Call

2004-02-29 Thread Scott Cantor
Was reviewing the codeQuestion - If we write a class that extends SignatureAlgorithm (see SignatureBaseRSA$SignatureRSASHA1 for example, we should be able to use the NativeJCE jar without having to sign it first). Right? Yes, signature providers can be unsigned, it's encryption providers

[GUMP@lsd]: xml-security/xml-security failed

2004-02-29 Thread Sam Ruby
To whom it may engage... This is an automated request, but not an unsolicited one. For help understanding the request please visit http://gump.apache.org/nagged.html, and/or contact [EMAIL PROTECTED] Project xml-security has an issue affecting it's community integration. This issue

[GUMP@lsd]: xml-security/xml-security failed

2004-02-29 Thread Sam Ruby
To whom it may engage... This is an automated request, but not an unsolicited one. For help understanding the request please visit http://gump.apache.org/nagged.html, and/or contact [EMAIL PROTECTED] Project xml-security has an issue affecting it's community integration. This issue