On Jun 19, 2007, at 12:56 PM, Bjoern Hoehrmann wrote:


* Paul Hoffman wrote:
Because servers are allowed (and in some cases required) to modify
the contents of an Entry Document before publishing it, a client that
signs a Entry Document should only do so with the intention of the
server possibly validating the submission; the client cannot assume
that the signature will be valid when viewed by a third party, or
that the server will even publish the client's signature.

Could you point out where the draft requires making changes?

The atom:id has to be globally unique, and the server has to manage app:edited.

I so far
assumed you can make a conforming implementation that does little but
passing through the content I want to publish as-is, your text seems
to rule that out.

Such an implementation would be possible, but would be an exotic corner case. Client implementers SHOULD NOT expect digsigs to survive the operation of a typical Atom server implementation, and Sam Hartman is correct that we need to be clear about this. -Tim

Reply via email to