[ https://issues.apache.org/jira/browse/WSS-399?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Colm O hEigeartaigh closed WSS-399. ----------------------------------- > WSS4J: cannot set DigestMethod for KEYTRANSPORT_RSAOEP though requested by W3C > ------------------------------------------------------------------------------ > > Key: WSS-399 > URL: https://issues.apache.org/jira/browse/WSS-399 > Project: WSS4J > Issue Type: Bug > Components: WSS4J Core > Affects Versions: 1.6.7 > Environment: any > Reporter: Stefan > Assignee: Colm O hEigeartaigh > Fix For: 1.6.8 > > > As stated on http://www.w3.org/TR/xmlenc-core/#sec-RSA-OAEP (and > http://java.net/projects/metro/lists/users/archive/2008-05/message/12) there > should be the possibility to set the message digest that is listed as > MANDATORY (and shall be set in the generated output). > QUOTE: > 5.4.2 RSA-OAEP > Identifier: > http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p (REQUIRED) > The RSAES-OAEP-ENCRYPT algorithm, as specified in RFC 2437 [PKCS1], takes > three parameters. The two user specified parameters are a MANDATORY message > digest function and an OPTIONAL encoding octet string OAEPparams. The message > digest function is indicated by the Algorithm attribute of a child > ds:DigestMethod element and the mask generation function, the third > parameter, is always MGF1 with SHA1 (mgf1SHA1Identifier). Both the message > digest and mask generation functions are used in the EME-OAEP-ENCODE > operation as part of RSAES-OAEP-ENCRYPT. The encoding octet string is the > base64 decoding of the content of an optional OAEPparams child element . If > no OAEPparams child is provided, a null string is used. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@ws.apache.org For additional commands, e-mail: dev-h...@ws.apache.org