RE: [BONDI Architecture Security] [widgets] new digsig draft, further comments

2009-03-27 Thread Marcin Hanclik
Hi Marcos, These are my further comments to the DigSig spec: 1. There is no section about typographic conventions, as e.g. section 1.3 in PC spec. Therefore it is not possible to know e.g. which part of the spec is defining an example. 2. Section 4. My below comment 5. Section 4, item 3: is

Re: [BONDI Architecture Security] [widgets] new digsig draft, further comments

2009-03-27 Thread Frederick Hirsch
Marcin [removed cross-posting, since my posting would fail anyway] comments inline regards, Frederick Frederick Hirsch Nokia On Mar 27, 2009, at 5:27 AM, ext Marcin Hanclik wrote: Hi Marcos, These are my further comments to the DigSig spec: 1. There is no section about typographic

RE: [BONDI Architecture Security] [widgets] new digsig draft, further comments

2009-03-27 Thread Marcin Hanclik
Hi Frederick, Thanks for your review of my comments. Ordering of widget signature files by the numeric portion of the file name can be used to allow consistent processing and possible optimization. I think we should keep a sentence since Mark Priestly had earlier asked that we add it. Agreed.

Re: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Frederick Hirsch
Marcin Thanks, for the careful review. some comment inline [removed cross post, fails anyway] regards, Frederick Frederick Hirsch Nokia On Mar 26, 2009, at 2:04 PM, ext Marcin Hanclik wrote: Hi Marcos, All, Please find below my - mostly editorial - comments to the latest digsig

Re: [BONDI Architecture Security] [widgets] new digsig draft, further comments

2009-03-27 Thread Frederick Hirsch
Marcin re author, would the term creator in the sentence from Thomas help, e.g. The author signature asserts that the signing party is a creator of the widget, and binds the creator's identity to the widget package. this probably doesn't help, since by definition author means creator...

RE: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Marcin Hanclik
Hi Frederick, Thanks for your review again. Thanks for all the corrections. These are my further comments for dispute. b) Clarify file name in PC (the definition in DigSig says about deriving from file name field and it seems strange to me). why? it is the string file name? PC defines (or

Re: [widgets] Author

2009-03-27 Thread Frederick Hirsch
No I agree, we are trying to stay away from legal statements , that requires much more. regards, Frederick Frederick Hirsch Nokia On Mar 27, 2009, at 10:40 AM, ext Marcin Hanclik wrote: Hi Frederick, re author, would the term creator in the sentence from Thomas help, this probably

[admin] Seeking clarification of otsi-arch-sec mail list

2009-03-27 Thread Arthur Barstow
Hi, Where can we find: a) a short description of the otsi-arch-sec mail list (e.g. its function); b) who is subscribed to this list and c) its Public archive? Also, is this mail list writable by anyone that has not agreed to the Turin Rules [1]? -Regards, Art Barstow [1]

[admin] Seeking clarification of otsi-arch-sec mail list

2009-03-27 Thread Arthur Barstow
Hi, Where can we find: a) a short description of the otsi-arch-sec mail list (e.g. its function); b) who is subscribed to this list and c) its Public archive? Also, is this mail list writable by anyone that has not agreed to the Turin Rules [1]? -Regards, Art Barstow [1]

RE: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Hillebrand, Rainer
Dear Marcos, I hope to have less critical comments than in my last feedback email. 1. Section 7.1: change The ds:SignatureMethod algorithm used in the ds:SignatureValue element MUST one of the signature algorithms. to The ds:SignatureMethod algorithm used in the ds:SignatureValue element MUST

Re: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Marcos Caceres
Hi Frederick, I support the changes below. They are all editorial in nature. Kind regards, Marcos On Fri, Mar 27, 2009 at 6:26 PM, Hillebrand, Rainer rainer.hillebr...@t-mobile.net wrote: Dear Marcos, I hope to have less critical comments than in my last feedback email. 1. Section 7.1:

Re: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Frederick Hirsch
comments inline, thanks for reviewing this regards, Frederick Frederick Hirsch Nokia On Mar 27, 2009, at 1:26 PM, ext Hillebrand, Rainer wrote: Dear Marcos, I hope to have less critical comments than in my last feedback email. 1. Section 7.1: change The ds:SignatureMethod algorithm used

Re: [BONDI Architecture Security] [widgets] new digsig draft

2009-03-27 Thread Frederick Hirsch
I think we should remove it. Also, I revised the e.g. as follows ... undesireable and security relevant effects, such as overwriting of startup or system files. regards, Frederick Frederick Hirsch Nokia On Mar 27, 2009, at 2:00 PM, ext Hillebrand, Rainer wrote: Dear Frederick, I

[widget-digsig] Updated Editors Draft of Widget Signature

2009-03-27 Thread Frederick Hirsch
I have completed a major round of editorial updates to the Widget Signature editors draft. http://dev.w3.org/2006/waf/widgets-digsig/ This is intended to be our public working draft for Monday, so please review the changes. Thanks to all who commented. This does not include changes for