At 1:56 PM -0400 7/7/05, Mark Nottingham wrote:
On 07/07/2005, at 11:36 AM, Paul Hoffman wrote:

At 10:23 AM -0400 7/7/05, Mark Nottingham wrote:

Are we specifying exclusive c14n with or without comments? My preference would be without.

Without. That is explicitly the default for <http://www.w3.org/TR/2002/REC-xml-exc-c14n-20020718/>.

Where does it state that explicitly?

"Just as with [XML-C14N] one may use the "#WithComments" parameter to include the serialization of XML comments." Meaning: if you don't include #WithComment, you don't get comments.

There are two identifiers in section four; it would be best to reference the spec and the applicable identifier by name.

Works for me: http://www.w3.org/2001/10/xml-exc-c14n#

Imagine that you sign an entry that relies on an feed-level xml:base of "http://www.example.com/";.

There are zillions of external things that might affect the *interpretation* of what is signed. We saw that in the discussion of signing entries with external references.

We are signing the bits only, not some interpretation of the bits. That is true for the xml:base, the xml:lang, the xml:something-else, and so on.

I have no problem with the implementer's guide (or the signing-and-encrypting guide, if it happens) to talk about the dangers of interpreting things not covered by the signature, but if we start a list in the base spec, readers will assume that the list is exhaustive. We can easily tell now that it won't be.

--Paul Hoffman, Director
--Internet Mail Consortium

Reply via email to