massimiliano.masi at gmail.com massimiliano.masi at gmail.com
Thu Aug 9 06:30:17 EDT 2012


Scott,

Thank you for your response. Whitespaces shouldn't be a problem. With the
apache xml-security libraries, I've test cases with different namespaces
locations,
and they all pass.

Are you internally using apache libraries, or you implement signature
verification
and validation in xmltooling? I'm asking in order to try to identify where
the problem
can be.

On Wed, Aug 8, 2012 at 7:42 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 8/8/12 10:50 AM, "massimiliano.masi at gmail.com"
> <massimiliano.masi at gmail.com> wrote:
> >
> >
> >
> >How to avoid this situation?
>
> You're the one responsible for serialization of any XML, so whatever
> you're doing isn't working. If that's a piece of code somebody else wrote,
> then it's at fault.
>
> >AFAIK, the two xmls are semantically equivalent, thus the signature shall
> >behave the same, or am I wrong?
>
> Email is not a way to gauge that, but the examples you posted have
> different whitespace, and that's all it takes.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>



-- 
Massimiliano Masi

http://www.mascanc.net/~max
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120809/f4dc46a5/attachment.html 


More information about the dev mailing list