4 ms·
The main issue that I have with XmlDSig is that the signatures are stored inside of the document being signed. Because of that, you can’t properly implement the
by jf 2y ago
The main issue that I have with XmlDSig is that the signatures are stored inside of the document being signed. Because of that, you can’t properly implement the standard without writing enough of an XML parser to do the canonicalization needed to properly compute and verify the hashes used for signatures. In practice, this means you need approximately an entire XML stack just to hash some data, something that is a simple operation otherwise.