> <KeySelector>
> <ds:KeyInfo>
> <ds:X509Data>...</ds:X509Data>
> </ds:KeyInfo>
> </KeySelector>
I also prefer this. Verbosity doesn't both me -- we're talking about
XML, and not only that, but mounds of base64-encoded strings. Also,
this lets future versions extend KeySelector, such as by letting the
client include an ordered list of possible keys to use. Or perhaps by
including a SAML assertion that gives proof of right to use the key.
/r$
--
Rich Salz, Chief Security Architect
DataPower Technology http://www.datapower.com
XS40 XML Security Gateway http://www.datapower.com/products/xs40.html
XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html