<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""><div><br class=""><blockquote type="cite" class=""><div class="">On 2020-10-09, at 00:55, Weiwu Zhang <<a href="mailto:weiwu.zhang@alphawallet.com" class="">weiwu.zhang@alphawallet.com</a>> wrote:</div><div class=""><div class=""><br class="">Through your explanation now I understood that<br class="">typically xmlsectool is used in a context where the verifier has the<br class="">right certificate (instead of a trusted authority list).</div></div></blockquote><div><br class=""></div><div>Yes. The principal real world use case for xmlsectool is for the secure exchange of the large aggregate documents holding national or international federation metadata. The trust model is very tightly controlled (much more so than the typical public web PKI use of signatures) and does essentially boil down to "must be that specific key".</div><div><br class=""></div><div>As Scott says, XML DSIG in general can be a *lot* more complicated than that, and xmlsectool doesn't aim to handle more than a small number of specific use cases.</div><div><br class=""></div><div><br class=""></div><blockquote type="cite" class=""><div class=""><div class="">That is, unless, if xmlsectool already support certificate chain where<br class="">I can actually supply a chain certificate in --verifySignature<br class="">--certificate and it will check against the public key used to sign<br class="">the certificate in XMLDSIG instead of the public key used to sign the<br class="">XML. I haven't experiemented that kind of use.<br class=""></div></div></blockquote><div><br class=""></div><div>No, it doesn't support that, and there are no plans for that to change.</div><div><br class=""></div><div>Cheers,</div><div><br class=""></div></div><div class=""><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div class=""> -- Ian<br class=""></div><div class=""><span class="Apple-style-span" style="font-size: medium;"><br class=""></span></div></span></div></span><br class="Apple-interchange-newline"><br class="Apple-interchange-newline">
</div>
<br class=""></body></html>