Re: question

2008-05-28 Thread Jean-Charles Laurent
Groupe Jean Coutu (PJC) Inc. tél: 450-463-1890 (3363) fax: 450-646-0567 [EMAIL PROTECTED] Brent Putman <[EMAIL PROTECTED]> 27/05/2008 06:10 PM A Jean-Charles Laurent <[EMAIL PROTECTED]>, security-dev@xml.apache.org cc Objet Re: question (Please hit reply-to-all when you r

Re: question

2008-05-27 Thread Brent Putman
(Please hit reply-to-all when you reply so that your email goes to the list and not just to me). Jean-Charles Laurent wrote: Hi Brent, Yes I did write to a file and I validate it with a Java tool (found on the web) or with a Java program that I got in the sample directory of xml security

Re: question

2008-05-27 Thread Brent Putman
Jean-Charles Laurent wrote: Thanks Brent, I agree, the removel of line break is not the perfect solution. My guest would be be some kind of serialization or deserialization problem. That's probably the most common problem with signatures that fail to validate after being sent to a remote

question

2008-05-22 Thread Jean-Charles Laurent
I have been trying to sign an XML file using the apache security package. I seem to be able to verify the signature on my side but it cannot be verified on the client side. What I can explain is why the CanonicalizationMethod Algorithim is "http://www.w3.org/TR/2001/REC-xml-c14n-2001031

Re: Interop question

2007-06-22 Thread Ulrich Ackermann
response! Ulrich -Ursprüngliche Nachricht- Von: security-dev@xml.apache.org Gesendet: 22.06.07 14:51:02 An: security-dev@xml.apache.org Betreff: Re: Interop question Hi Ulrich, It's probably a c14n issue. What you should do is enable logging on each side, and then compare the canonica

Re: Interop question

2007-06-22 Thread Sean Mullan
on in JDK 6 or XMLSec 1.4.1, which is more up to date. --Sean Ulrich Ackermann wrote: > Hi all, > > I have got a question concerning the interoperability between the > Apache XML Security framework (we are currently using the version > 1.3.0) and the Sun implementation of XML DS

Interop question

2007-06-21 Thread Ulrich Ackermann
Hi all, I have got a question concerning the interoperability between the Apache XML Security framework (we are currently using the version 1.3.0) and the Sun implementation of XML DSIG (Java XML Digital Signature API, 1.0 EA2). Currently we are running into problems because the opposite

Re: Basic hash value question

2006-12-08 Thread Dominik Schadow
ation. Thanks again for all the help. Regards Dominik > -Ursprüngliche Nachricht- > Von: security-dev@xml.apache.org > Gesendet: 08.12.06 14:57:41 > An: security-dev@xml.apache.org > Betreff: Re: Basic hash value question > Hello Raul, > > I'm not quite

Re: Basic hash value question

2006-12-08 Thread Ulrich Ackermann
Hello Raul, I'm not quite sure if I understood your question right. There was no signing and transforming involved outside the code I posted. I just took the Base64 encoded String and converted it into a hex String to show, that it matched the result Dominik got from the CrypTool. Maybe

Re: Basic hash value question

2006-12-07 Thread Raul Benito
ou expected: hexFromBase64 = a19308142f1b7720db1787b8d90176ba0afedf43 Cheers, Ulrich -Ursprüngliche Nachricht- Von: security-dev@xml.apache.org Gesendet: 06.12.06 21:45:05 An: security-dev@xml.apache.org Betreff: RE: Basic hash value question Hello again, Thanks for the answer before. I discovered an online

RE: Basic hash value question

2006-12-06 Thread Ulrich Ackermann
y-dev@xml.apache.org Betreff: RE: Basic hash value question Hello again, Thanks for the answer before. I discovered an online tool doing exactly what I wanted: http://www.softwaremaker.net/DotNetApps/B64BytDecHex/index.aspx After playing around a little bit I discovered a difference in the hash v

RE: Basic hash value question

2006-12-06 Thread Dominik Schadow
correctly? What do I have to do to make both hash values comparable? Thanks again! Dominik > -Ursprüngliche Nachricht- > Von: security-dev@xml.apache.org > Gesendet: 06.12.06 00:02:42 > An: > Betreff: RE: Basic hash value question > > As far as I understand, the Dige

RE: Basic hash value question

2006-12-05 Thread Scott Cantor
> As far as I understand, the DigestValue is the base64 > representation of the calculated binary hash value. How can I > compare this calculated SHA1 hash value with the one > calculated with a different tool where the hash value looks > something like 8011 FAB5 3D6D 20D0 E8B5 3F72 00F1 7D81 E

Basic hash value question

2006-12-05 Thread Dominik Schadow
Hello, I've a basic question about the calculated hash values with Apache XML Security 1.3 (Java). Say I get the following result for a signature calculation (I took it out of one of the samples): ds:Reference URI=""> http://www.w3.org/2000/09/xmldsig#sha1";> F+toCRW

Xmlsec question: when is base64 done

2006-09-03 Thread Jean-Luc Cooke
Team, I had a question about how xmlsec (the standard) processes elements that are base64 encoded. Will these two structures be hashed to the same value? Will the encoding attribute be added to the hash? Will both "6dnN..." payloads be base64 decoded before being processed? Thanks

Re: Debian packaging, quick naming question

2006-05-25 Thread Russ Allbery
Berin Lautenbach <[EMAIL PROTECTED]> writes: > BTW - Am really glad someone has picked up the debian thing. I had an > ITP filed for a long time, but I never got around to actually doing the > packaging. Did the ITP get closed, or is there still one floating around that I need to make sure I cat

Re: Debian packaging, quick naming question

2006-05-25 Thread Berin Lautenbach
Scott Cantor wrote: >>Second, and this is one of those things that doesn't really matter but I >>promised to at least ask, there were a few Debian developers who responded >>to my Intent to Package notification who were wondering why the package >>was called XML-Security-C when it was written in C+

RE: Debian packaging, quick naming question

2006-05-24 Thread Scott Cantor
> Second, and this is one of those things that doesn't really matter but I > promised to at least ask, there were a few Debian developers who responded > to my Intent to Package notification who were wondering why the package > was called XML-Security-C when it was written in C++. Just a guess on

Debian packaging, quick naming question

2006-05-23 Thread Russ Allbery
Hello folks, First, I wanted to introduce myself and mention that I and Quanah Gibson-Mount are currently working on packaging Shibboleth for Debian and therefore are also packaging XML-Security-C as a prerequisite. Quanah has finished a first pass at the packaging and I'm currently working on a

Re: Question about WS-Security

2006-03-14 Thread William Bathurst
IL GON KIM wrote: I am studying on WS-Security and have a question about it. As far as I understand it, WS-Security defines security elements in header part of the SOAP messages, by combining WS-Signature and WS-Encryption standards. I think it is possible to define security elements in

Re: Question about WS-Security

2006-03-14 Thread Tech Rams
functionality even if you have achieved elegance and generalization. -rams > *question 1) * Is there other reasons why > WS-Security defines > especially security elments in header part of SOAP > message. > > As I mentioned in an original e-mail, I believe that > security element

Re: Question about WS-Security

2006-03-14 Thread IL GON KIM
messages, in WS-Security. *question 1) * Is there other reasons why WS-Security defines especially security elments in header part of SOAP message. As I mentioned in an original e-mail, I believe that security element defined with XML-Signature and XML-Encryption could be located in either

Re: Question about WS-Security

2006-03-14 Thread Davanum Srinivas
/response. -- dims On 3/14/06, IL GON KIM <[EMAIL PROTECTED]> wrote: > I am studying on WS-Security and have a question about it. > As far as I understand it, WS-Security defines security elements in > header part of the SOAP messages, by combining WS-Signature and > WS-Encryptio

Question about WS-Security

2006-03-14 Thread IL GON KIM
I am studying on WS-Security and have a question about it. As far as I understand it, WS-Security defines security elements in header part of the SOAP messages, by combining WS-Signature and WS-Encryption standards. I think it is possible to define security elements in body part of the SOAP

Re: TRANSFORM_XPATH2FILTER question

2006-01-30 Thread Raul Benito
Hi Stefeno, I think you have hit a bug in the changes I do for xpath between 1.2 and 1.3, do you mind to open a bug report in bugzilla? Please, attach a test case that shos the bug(This increase the speed of fix a lot...). Regards, On 1/27/06, Berin Lautenbach <[EMAIL PROTECTED]> wrote: > > Stef

Re: TRANSFORM_XPATH2FILTER question

2006-01-27 Thread Berin Lautenbach
Stefano Del Sal wrote: I'm trying to sign a document using the transform TRANSFORM_XPATH2FILTER, but I get a bad signature if I try to use ONLY the filter XPath2FilterContainer.SUBTRACT 1) Ex: String filters[][] = { {XPath2FilterContainer.SUBTRACT, "//NotToBeSigned"} }; transforms.ad

TRANSFORM_XPATH2FILTER question

2006-01-27 Thread Stefano Del Sal
I'm trying to sign a document using the transform TRANSFORM_XPATH2FILTER, but I get a bad signature if I try to use ONLY the filter XPath2FilterContainer.SUBTRACT 1) Ex: String filters[][] = { {XPath2FilterContainer.SUBTRACT, "//NotToBeSigned"} }; transforms.addTransform( Transforms.T

Re: DSig Question

2005-12-15 Thread Tech Rams
there are quite a few oddities with the xml you posted. 1. security element does not belong to the wsse namespace 2. username token appears in the body But, anyway, that does not cause a problem with your signature verification. Looking at the keyinfo, it looks like the code will take a path whe

DSig Question

2005-12-15 Thread Nicholas G Harlow
- Forwarded by Nicholas G Harlow/Santa Cruz/IBM on 12/15/2005 12:38 PM - Nicholas G Harlow 12/15/2005 12:33 PM                 To:        [EMAIL PROTECTED]         cc:                 From:        Nicholas G Harlow/Santa Cruz/[EMAIL PROTECTED]         Subject:         DSig Question

Some Question about Xml-Security

2005-08-29 Thread Tian WenQiang
Dear, Our organization is planning a big project which is a Linux-Embedded system and will be sold as products in the market. It is necessary for us to choose a Xml security product. From internet, we found your Xml security product -- Xml-security, and we are very interested in it, so we

RE: question on data directory

2005-08-13 Thread Anthony Sangha
I'm answering my question myself because I found the solution. There is an OfflineResolver class that can be modified to specify different data paths. Anthony Sangha -Original Message- From: Anthony Sangha [mailto:[EMAIL PROTECTED] Sent: Saturday, August 13, 2005 1:42 PM To: sec

RE: question on data directory

2005-08-13 Thread Anthony Sangha
TED] Sent: Saturday, August 13, 2005 12:59 PM To: security-dev@xml.apache.org Subject: Re: question on data directory Anthony, this list discusses two libraries implementing standards concerning signature and encryption of XML documents. One java and one C++ library. AFAIK there is no obvious

Re: question on data directory

2005-08-13 Thread Heiner Westphal
Anthony, this list discusses two libraries implementing standards concerning signature and encryption of XML documents. One java and one C++ library. AFAIK there is no obvious executable. Neither any preset data directroy is to be found. Perhaps you confused the mailing lists? Or are you workin

question on data directory

2005-08-13 Thread Anthony Sangha
I would like to have a different data directory. Currently the data directory, as I understand, has to be in the path of the executable.   Is there a way to do this?   Anthony Sangha [EMAIL PROTECTED]    

Re: XML Signature transform question

2005-08-01 Thread Sean Mullan
Paul Buhler wrote: I have what I hope is a simple question. I am trying to sign the EncryptedData element in an XML document. This element has an id attribute of "ed1". If I use a same-document reference URI of "#ed1" I get the desired result; i.e., the digest is onl

XML Signature transform question

2005-07-30 Thread Paul Buhler
I have what I hope is a simple question. I am trying to sign the EncryptedData element in an XML document. This element has an id attribute of "ed1". If I use a same-document reference URI of "#ed1" I get the desired result; i.e., the digest is only calculated for the Encry

Re: Newbie question

2005-06-09 Thread Mike Haller
Hi Berin, you're absolutely right, and I understand it. If it was a requirement to use CDATA tags for text nodes, we wouldn't have such problems. All other contents could be considered subject to change. However, i'm using Castor and it seems that the deserialisation process (marshalling) rem

Re: Newbie question

2005-06-09 Thread Berin Lautenbach
Mike Haller wrote: i don't know why Canonicalization doesn't address this problem at all. It sounds like being incomplete to me. One the one hand, there is taken effort to "normalize" the XML document so it can be signed to avoidproblems with formattings - on the other hand something simple li

Re: Newbie question

2005-06-09 Thread Mike Haller
Yes Berin, thanks, i don't know why Canonicalization doesn't address this problem at all. It sounds like being incomplete to me. One the one hand, there is taken effort to "normalize" the XML document so it can be signed to avoidproblems with formattings - on the other hand something simple li

Re: Newbie question

2005-06-09 Thread Berin Lautenbach
Mike Haller wrote: But after some marshalling/unmarshalling with Castor, the resulting Document has no newlines any more, hence the SignatureValue of the SignedInfo element is invalid. How do I tell XMLSignature to add newlines into the SignedInfo before validation? Or should I remove the ne

Newbie question

2005-06-06 Thread Mike Haller
Hi, in hope this is the correct mailing list, here my question: Signing works, verification works. But after some marshalling/unmarshalling with Castor, the resulting Document has no newlines any more, hence the SignatureValue of the SignedInfo element is invalid. How do I tell

RE: Base64 question + Preparing for a 1.2 C++ release

2005-02-27 Thread Scott Cantor
> Scott - you are the person with the most experience in schema validation > and signatures. Is it worthwhile adding some form of switch to tell the > library to output base64 data in normalised form? (I.e. no line feeds > etc.) That way normalisation won't touch the data and schema validatio

Base64 question + Preparing for a 1.2 C++ release

2005-02-26 Thread Berin Lautenbach
Peoples, I've been doing some work to clean up for a 1.2 release. In particular, I have just : 1. Started going through and cleaning up the various bugs that haven't yet been fixed 2. Stripped out all requirements for RTTI 3. Stripped out requirement for MFC in debug build 4. Now builds aga

Re: xmlsec-c question about XSECEnv

2005-01-11 Thread Berin Lautenbach
rting to incoporate a few pieces of the XML Encryption classes into some of my project, and I had a question about the XSECEnv class, specifically about the DOMDocument parameter in the c'tor, and how to use this class. Is this object supposed to be created per XML instance being manipulated?

xmlsec-c question about XSECEnv

2005-01-10 Thread Scott Cantor
I'm starting to incoporate a few pieces of the XML Encryption classes into some of my project, and I had a question about the XSECEnv class, specifically about the DOMDocument parameter in the c'tor, and how to use this class. Is this object supposed to be created per XML inst

Newbie question on HMAC signature

2004-10-12 Thread Monica Lau
Hi,   I'm  signing an xml document using hmac-sha1.  I was just wondering what do people normally fill in for the element?  I assume that you don't incorporate this  element into the document because you can't/shouldn't store the secret in it.  Or is there some way to incorporate this information

Re: AW: AW: Question on c14n exclusive

2004-05-28 Thread Berin Lautenbach
[EMAIL PROTECTED] wrote: Well, In the current c14n implementation changing the behaviour is only a how the symb table is create(i.e. When I create the symbol table the xmlns="" binding is marked as rendered, so it is not emitted), I can parametrized this behaviour. But what happend in the excl c1

Re: AW: AW: Question on c14n exclusive

2004-05-28 Thread Berin Lautenbach
Dittmann Werner wrote: This behaviour is absolutely necessary in order that exclusive canonicalization can function correctly in the case of changes to apex definitions of the default namespace. The canonicalization specifications should both have been defined to always emit apex xmlns=""; this la

Re: AW: AW: Question on c14n exclusive

2004-05-28 Thread raul-info
> Berin, > > well I don't know if it is the same reason as for > encryption. During the discussion I also asked > one of the WSS gurus about the topic. Here is his > answer to my question: > > > This behaviour is absolutely necessary in order that exclusive

AW: AW: Question on c14n exclusive

2004-05-28 Thread Dittmann Werner
Berin, well I don't know if it is the same reason as for encryption. During the discussion I also asked one of the WSS gurus about the topic. Here is his answer to my question: This behaviour is absolutely necessary in order that exclusive canonicalization can function correctly in the ca

Re: AW: Question on c14n exclusive

2004-05-28 Thread Berin Lautenbach
Dittmann Werner wrote: * Finally, employ the canonicalization method specified as a parameter to the transform to serialize N to produce the octet stream output of this transform; but, in place of any dereferenced element Ri and its descendants, process the dereferenced node set Ri' instead. Dur

Re: AW: AW: Question on c14n exclusive

2004-05-27 Thread Vishal Mahajan
m can be sloved. Regards, Werner -Ursprüngliche Nachricht- Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Gesendet: Donnerstag, 27. Mai 2004 17:22 An: [EMAIL PROTECTED] Betreff: Re: AW: Question on c14n exclusive Raul, thanks. However, the element that I

Re: AW: AW: Question on c14n exclusive

2004-05-27 Thread raul-info
On 27/05/2004, at 17:34, Dittmann Werner wrote: Raul, already tried that hack, the problem with that is that c14n outputs either a byte buffer that is the XML docu as String or as a node set - this has to be serialized then deadlock. Well, I try to ask the WSS guys how they think this problem c

AW: AW: Question on c14n exclusive

2004-05-27 Thread Dittmann Werner
> -Ursprüngliche Nachricht- > Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > Gesendet: Donnerstag, 27. Mai 2004 17:22 > An: [EMAIL PROTECTED] > Betreff: Re: AW: Question on c14n exclusive > > > > Raul, > > thanks. > > > > However, the element that I c

Re: AW: Question on c14n exclusive

2004-05-27 Thread raul-info
> Raul, > thanks. > > However, the element that I create is a top level > elemen, i.e. an apex node (as far as I understand the > c14n specs). According to the WSS specs > > > * Finally, employ the canonicalization method specified as a parameter to > the transform to > serialize N to produce the

AW: Question on c14n exclusive

2004-05-27 Thread Dittmann Werner
nicalizeXPathNodeSet(nodeset, incNamespace) would this work? A very confusing topic :-) (And hard to read specs too). Regards, Werner > -Ursprüngliche Nachricht- > Von: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] > Gesendet: Donnerstag, 27. Mai 2004 15:29 > An: [EMAIL PROTE

Re: Question on c14n exclusive

2004-05-27 Thread raul-info
> All, > > a question to the c14 gurus on the list. > > I set up an Element node and set the default namespace > to "" using the following code: > >elem.setAttributeNS(WSConstants.XMLNS_NS, "xmlns", ""); > > This seems

Question on c14n exclusive

2004-05-27 Thread Dittmann Werner
All, a question to the c14 gurus on the list. I set up an Element node and set the default namespace to "" using the following code: elem.setAttributeNS(WSConstants.XMLNS_NS, "xmlns", ""); This seems to work. The element is c14n'ed using the following c

Re: question on insecure Id/ID/id search method

2004-04-28 Thread Sean Mullan
steel scorpion wrote: From: Erwin van der Koogh <[EMAIL PROTECTED]> Somewhere in your code you have a reference to a particular ID, but it's not always possible to see what attributes are of type ID. To Not sure I understand this completely. Does this mean that, from a parser/resolver point of

Re: question on insecure Id/ID/id search method

2004-04-27 Thread steel scorpion
From: Erwin van der Koogh <[EMAIL PROTECTED]> Somewhere in your code you have a reference to a particular ID, but it's not always possible to see what attributes are of type ID. To Not sure I understand this completely. Does this mean that, from a parser/resolver point of view, it is impossible t

Re: c14n Inclusive question.

2004-04-27 Thread Berin Lautenbach
[EMAIL PROTECTED] wrote: Other question when a xmlns attribute is selected with the xpath but the parent isn´t(i.e you just output xmlns:X="") & a child needs to render the same xmlns. It is taken at renderedi.e. the output is: xmlns:d="ddd" or: xmlns:d

Re: question on insecure Id/ID/id search method

2004-04-27 Thread Erwin van der Koogh
When I sign or open a signed XML document, I see the following warning messages: Apr 27, 2004 3:40:53 PM org.apache.xml.security.utils.IdResolver getElementById WARNING: Found an Element using an insecure Id/ID/id search method: claim:MemberID ... What does that mean exactly? Somewhere in your

question on insecure Id/ID/id search method

2004-04-27 Thread steel scorpion
When I sign or open a signed XML document, I see the following warning messages: Apr 27, 2004 3:40:53 PM org.apache.xml.security.utils.IdResolver getElementById WARNING: Found an Element using an insecure Id/ID/id search method: claim:MemberID Apr 27, 2004 3:40:53 PM org.apache.xml.security.

Re: c14n Inclusive question.

2004-04-26 Thread raul-info
count(Can anyone comfirm this?). And as i unifiying the handling of attributes in a (sub)tree c14n & xpath I found this problem. Other question when a xmlns attribute is selected with the xpath but the parent isn´t(i.e you just output xmlns:X="") & a child needs to render the s

Re: c14n Inclusive question.

2004-04-26 Thread Karel Wouters
Hi Raul, here's an attempt to help you further: from the spec: Namespace Nodes- A namespace node N is ignored if the nearest ancestor element of the node's parent element that is in the node-set has a namespace node in the node-set with the same local name and value as N. Otherwise, process the n

c14n Inclusive question.

2004-04-25 Thread [EMAIL PROTECTED]
I'm rewriting the inclusive canonicalization and i see same weirds thing in the test vector: /data/interop/c14n/Y4/c14n-1.txt: http://example.org/bar"; xml:lang="en-ie"> http://example.org/foo";> http://example.org/bar";> http://example.org/foo";> http://example.

Re: Question about iop test of c14n

2004-04-17 Thread Berin Lautenbach
One of the really cool things about c14n is it doesn't necessarily result in valid XML . C14n takes as an input a node-set, which may not be a complete XML document. That means you can use it to canonicalise only the data in the document that you are interested in signing. As an example - if

Question about iop test of c14n

2004-04-17 Thread [EMAIL PROTECTED]
Hi, I'm refacotoring the c14n and i see that i can get some minor speed-ups, but I have found something strange. It is this vector correct? xml-security/data/interop/c14n/Y4/c14n-24.txt It isn't a valid xml file, I'm missing something? Perhaps i need to read better the recomendation. But any

RE: Signature Element (a user question, not dev)

2004-03-28 Thread Scott Cantor
> In this signature, the Reference element in the SignedInfo has the > attribute URI="". I understand that this references the current > document, which is correct. In this case, I think I need to ensure the > Transform directives exclude the Signature element itself via nested > XPath elements. Fo

Signature Element (a user question, not dev)

2004-03-28 Thread Jem Mawson
Hello First let me apologise for emailing the dev group with my user questions, but it's the only group I could find for xml-security. I'm new to this and have been looking at the examples that are shipped with the Java library. I have been able to generate an enveloped Signature element within a

Re: Is anybody out there? No one is interested in my question?

2004-03-24 Thread Erwin van der Koogh
Been trying to get an answer to my question very patiently. I thought I would try it a third time and see if anyone is interested in my question. One thing to try is check out latest CVS and give that a shot. Let me know if you need help. 1.05D2, even though it's the latest version is

Is anybody out there? No one is interested in my question?

2004-03-24 Thread Chugh, Sanjay
Title: Message Been trying to get an answer to my question very patiently. I thought I would try it a third time and see if anyone is interested in my question. I am using Apache Java library for XMLDsig. Version is 1.05D2. I want to add a xslt transform to the . It all works fine as long

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Berin Lautenbach
> Sean, > Update the junit test result - > http://nagoya.apache.org/~dims/xmlsec-junit/. Here's my config.xml > http://nagoya.apache.org/~dims/xmlsec-junit/config.xml. Results are > just slightly better. > > Can you please update config.xml and send us something that passes all > the tests? OK -

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Davanum Srinivas
> >>>>using the wrong cipher spec for the unwrap cipher. > >>>> > >>>>Unfortunately, the Sun JCE doesn't take AESWrap or DESEDEWrap, only AES > >>>>or DESEDE, so I *think* what is happening is the JCE is doing a straight > >>>&g

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Sean Mullan
re failing? --Sean Berin Lautenbach wrote: Peoples, I have just checked in a new version of config.xml that works for most encryption algorithms under SunJCE (have not yet checked sig). One question - I am having issues with symmetric key wraps. The Baltimore interop tests all fail where a s

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Sean Mullan
xml that works for most encryption algorithms under SunJCE (have not yet checked sig). One question - I am having issues with symmetric key wraps. The Baltimore interop tests all fail where a symmetric key wrap is used. The BC JCE takes an algorithm of "AESWrap" or "DESEDEWrap"

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Davanum Srinivas
>>Cheers, > >>Berin > >> > >>Sean Mullan wrote: > >> > >>>Can you tell me which test vectors are failing? > >>> > >>>--Sean > >>> > >>>Berin Lautenbach wrote: > >>> > >>> > >&g

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Berin Lautenbach
checked sig). One question - I am having issues with symmetric key wraps. The Baltimore interop tests all fail where a symmetric key wrap is used. The BC JCE takes an algorithm of "AESWrap" or "DESEDEWrap" for the unwrap algorithms. The SunJCE , I think, uses "AES" a

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Berin Lautenbach
arching, but all ideas welcome :>. Cheers, Berin Sean Mullan wrote: Can you tell me which test vectors are failing? --Sean Berin Lautenbach wrote: Peoples, I have just checked in a new version of config.xml that works for most encryption algorithms under SunJCE (have not yet checked

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Davanum Srinivas
> Cheers, > Berin > > Sean Mullan wrote: > > Can you tell me which test vectors are failing? > > > > --Sean > > > > Berin Lautenbach wrote: > > > >> Peoples, > >> > >> I have just checked in a new version of config.xml

Re: Fragment Signing question

2004-03-04 Thread Berin Lautenbach
e document following the schema precisely ( the organization sending the document is loose in the way it interprets the schema.) My Question is "IS there any way of using the sig.addDocument("Xpointer(Xpath))"); type syntax at all ? Or is there any planned?" Does anyone know i

Re: Question on JCE 1.5 key wraps

2004-03-04 Thread Berin Lautenbach
g). One question - I am having issues with symmetric key wraps. The Baltimore interop tests all fail where a symmetric key wrap is used. The BC JCE takes an algorithm of "AESWrap" or "DESEDEWrap" for the unwrap algorithms. The SunJCE , I think, uses "AES" and &qu

Fragment Signing question

2004-03-03 Thread John Francis
rganization sending the document is loose in the way it interprets the schema.) My Question is "IS there any way of using the sig.addDocument("Xpointer(Xpath))"); type syntax at all ? Or is there any planned?" I would be quite willing to write a resolver or whatever to do th

Re: Question on JCE 1.5 key wraps

2004-03-03 Thread Sean Mullan
Can you tell me which test vectors are failing? --Sean Berin Lautenbach wrote: Peoples, I have just checked in a new version of config.xml that works for most encryption algorithms under SunJCE (have not yet checked sig). One question - I am having issues with symmetric key wraps. The

Question on JCE 1.5 key wraps

2004-03-03 Thread Berin Lautenbach
Peoples, I have just checked in a new version of config.xml that works for most encryption algorithms under SunJCE (have not yet checked sig). One question - I am having issues with symmetric key wraps. The Baltimore interop tests all fail where a symmetric key wrap is used. The BC JCE takes

RE: [Java] Newb question concerning XML-Sec JCE requirements

2004-01-23 Thread Anderson Jonathan
MAIL PROTECTED] Subject: Re: [Java] Newb question concerning XML-Sec JCE requirements Anderson Jonathan wrote: > Many, many thanks Sean. You just settled quite a few discussions in my > shop. You're welcome. > > A follow up question: > > Slides presented at JavaOne referred t

Re: [Java] Newb question concerning XML-Sec JCE requirements

2004-01-23 Thread Sean Mullan
Anderson Jonathan wrote: Many, many thanks Sean. You just settled quite a few discussions in my shop. You're welcome. A follow up question: Slides presented at JavaOne referred to JSR 105 and 106 being included in J2SE 1.5. What does this imply, exactly? 105/106 were originally targete

RE: [Java] Newb question concerning XML-Sec JCE requirements

2004-01-23 Thread Anderson Jonathan
Many, many thanks Sean. You just settled quite a few discussions in my shop. A follow up question: Slides presented at JavaOne referred to JSR 105 and 106 being included in J2SE 1.5. What does this imply, exactly? Are JSR 105 and 106 built around an SPI model like JCA/JCE are? Will there be

Re: [Java] Newb question concerning XML-Sec JCE requirements

2004-01-23 Thread Sean Mullan
Anderson Jonathan wrote: Hi everyone, Apologies in advance for what is probably a rather naive question. Current distributions of Apache XML-Security contain no third party JCE, but all of the documentation points to using the latest versions of the Bouncy Castle JCE as the provider for

[Java] Newb question concerning XML-Sec JCE requirements

2004-01-23 Thread Anderson Jonathan
Hi everyone, Apologies in advance for what is probably a rather naive question. Current distributions of Apache XML-Security contain no third party JCE, but all of the documentation points to using the latest versions of the Bouncy Castle JCE as the provider for XML-Security. I am

[java]Init.class question

2003-12-10 Thread Seungwook Jung
Hi, Init.Class reads from config.xml and register KeyInfoHandler to _contentHandlerHash. However, as I known, no class calls getKeyInfoContentHandler so I think that this registeration process is not necessary. If I were right, a developer should actually do for extends and customize library

Question/Problem using XMLCipher

2003-12-08 Thread Dittmann Werner
Hi all, while doing some tests with Encryption and Signing a SOAP message (in that order: encrypt, then sign) I use a pre-release version of xmlsec XMLCipher class. The XMLCipher produces the following output when encrypting the SOAP Body child element: http://schemas.xmlsoap.org/ws/2002/07/uti