Re: [PATCH] xml-security-c: Potential bug in canonicalization from an XPathNodeList

2009-06-11 Thread John Keeping
Scott Cantor wrote: > Can you please file all of that in the bugzilla? Filed as bug 47353 (as you've probably seen!) > I'm very reluctant to make changes to that code because I don't understand > it, and don't have any easy way to run any regressions using test vectors, > but I'll take a look at

RE: [PATCH] xml-security-c: Potential bug in canonicalization from an XPathNodeList

2009-06-11 Thread Scott Cantor
Can you please file all of that in the bugzilla? I'm very reluctant to make changes to that code because I don't understand it, and don't have any easy way to run any regressions using test vectors, but I'll take a look at it. One question, is this just Enveloped by itself, or is any actual use o

[PATCH] xml-security-c: Potential bug in canonicalization from an XPathNodeList

2009-06-11 Thread John Keeping
Hi, We've recently started using xml-security-c and while trying to validate signatures in some test files we noticed some digest failures. Using the "2 out of 3" rule, the digests validate in xmlsec (http://www.aleksey.com/xmlsec/) and using a validator based on the Java 6 libraries but not xml-