massimiliano.masi at gmail.com
massimiliano.masi at gmail.com
Thu Aug 9 06:30:17 EDT 2012
Scott,
Thank you for your response. Whitespaces shouldn't be a problem. With the
apache xml-security libraries, I've test cases with different namespaces
locations,
and they all pass.
Are you internally using apache libraries, or you implement signature
verification
and validation in xmltooling? I'm asking in order to try to identify where
the problem
can be.
On Wed, Aug 8, 2012 at 7:42 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 8/8/12 10:50 AM, "massimiliano.masi at gmail.com"
> <massimiliano.masi at gmail.com> wrote:
> >
> >
> >
> >How to avoid this situation?
>
> You're the one responsible for serialization of any XML, so whatever
> you're doing isn't working. If that's a piece of code somebody else wrote,
> then it's at fault.
>
> >AFAIK, the two xmls are semantically equivalent, thus the signature shall
> >behave the same, or am I wrong?
>
> Email is not a way to gauge that, but the examples you posted have
> different whitespace, and that's all it takes.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> dev-unsubscribe at shibboleth.net
>
--
Massimiliano Masi
http://www.mascanc.net/~max
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120809/f4dc46a5/attachment.html
More information about the dev
mailing list