http://netmesh.info/jernst/Technical/really-simple-xml-signatures.html
"RSig" for "Really simple Signature".The trouble for OpenID and XRD and so forth is that it is not our core competency -- and shouldn't be -- to innovate around things that really aren't our business. Signing XML documents isn't our business.
On the other hand, the people whose business it should be somehow seem to be asleep at the wheel, as the problems are well-known and somehow aren't being addressed, and haven't for years.
It seems to me that the best way out of this conundrum is:1. to foresee, architecturally, the use of several different ways of constructing signatures, as the matter clearly isn't settled 2. to make sure that high-end approaches (like XML-DSIG) work well, but low-end approaches (like XML-RSIG) work just as well 3. to maintain a best practices document that says "today, choice X is your best bet, and we say that because based on our market research, X has the highest market share in terms of implementors today."
As we all know, any problem in computer science can be solved by adding a level of indirection. This may well be one of those cases.
Johannes Ernst NetMesh Inc.
<<inline: lid.gif>>
<<inline: openid.gif>>
http://netmesh.info/jernst
_______________________________________________ specs mailing list specs@openid.net http://openid.net/mailman/listinfo/specs