At 1:56 PM -0400 7/7/05, Mark Nottingham wrote:
On 07/07/2005, at 11:36 AM, Paul Hoffman wrote:
At 10:23 AM -0400 7/7/05, Mark Nottingham wrote:
Are we specifying exclusive c14n with or without comments? My
preference would be without.
Without. That is explicitly the default for
<http://www.w3.org/TR/2002/REC-xml-exc-c14n-20020718/>.
Where does it state that explicitly?
"Just as with [XML-C14N] one may use the "#WithComments" parameter to
include the serialization of XML comments." Meaning: if you don't
include #WithComment, you don't get comments.
There are two identifiers in section four; it would be best to
reference the spec and the applicable identifier by name.
Works for me: http://www.w3.org/2001/10/xml-exc-c14n#
Imagine that you sign an entry that relies on an feed-level xml:base
of "http://www.example.com/".
There are zillions of external things that might affect the
*interpretation* of what is signed. We saw that in the discussion of
signing entries with external references.
We are signing the bits only, not some interpretation of the bits.
That is true for the xml:base, the xml:lang, the xml:something-else,
and so on.
I have no problem with the implementer's guide (or the
signing-and-encrypting guide, if it happens) to talk about the
dangers of interpreting things not covered by the signature, but if
we start a list in the base spec, readers will assume that the list
is exhaustive. We can easily tell now that it won't be.
--Paul Hoffman, Director
--Internet Mail Consortium