Next in thread → Next in month →

RE: [ubl-tsc] [Fwd: [ubl-psc] Proposal for a signature refenrence]

From
Tambi Kamarudin
Date
2005-11-18T08:51:00+00:00
ID
Thread
RE: [ubl-tsc] [Fwd: [ubl-psc] Proposal for a signature refenrence]
MHonArc v2.5.0b2 -->

ubl-tsc message

[Date Prev]
 | [Thread Prev]
 | [Thread Next]
 | [Date Next]

--

[Date Index]
 | [Thread Index]
 | [List Home]

Subject: RE: [ubl-tsc] [Fwd: [ubl-psc] Proposal for a signature refenrence]

From: "Kama, Kamarudin Bin Tambi" <>

To: "Peter Larsen Borresen" <>, <>,       <>

Date: Fri, 18 Nov 2005 16:52:32 +0800

Hi Peter,

Sorry for the belated reply. Well, as the
saying goes, better late than never. The past 1-month, we’ve been focusing
on finalizing the TSC data models.

 

In regards to your question, current COML
uses the W3C XML DigSig. That in itself is an ASBIE. We like to explore further
your proposed SignatureReference ABIE, perhaps with more detailed explanation. The
sample file UBL-Order-1.0-Office-Example_with signatureReference.xml contains
the SignatureReference but did not contain the actual signature. From an
implementation perspective, this is not sufficient. It simply contains the SignatureReference,
but the actual signature which is being referenced to is not there. The actual
signature is needed as well.

 

If you could provide the detailed
explanation, in terms of the meaning of each element, and the sample file with
the sample signature, that’ll allow us to understand better and see if it
can actually suit our requirement.

 

Rgds

kama

 

-----Original
Message-----

From: Peter Larsen Borresen
[mailto:]

Sent: Tuesday, October 11, 2005 7:49 PM

To: Kama, Kamarudin Bin Tambi;
; 

Cc: Grace Ng, Swee Lee (T&L);
Jern Kuan, Leong; Fu Wang, Thio

Subject: SV: [ubl-tsc] [Fwd:
[ubl-psc] Proposal for a signature refenrence]

 

Hi Kama

 

Do I understand you
correctly that what you need is a ASBIE that

 

1) contains (embed) or
refer to the actual signature.

2) contains (embed) or
refer to the document that has been signed.

 

It is significant to know
whether there is a need for actual containing the signature or whether a
reference is enough.

 

King ragards

 

Peter

-----Oprindelig meddelelse-----

Fra: Kama, Kamarudin Bin Tambi
[mailto:]

Sendt: 11. oktober 2005 04:38

Til: Peter Larsen Borresen;
; 

Cc: Grace Ng, Swee Lee (T&L);
Jern Kuan, Leong; Fu Wang, Thio

Emne: RE: [ubl-tsc] [Fwd:
[ubl-psc] Proposal for a signature refenrence]

Hi Peter,

Pls see my response
below.

 

Rgds

kama

 

-----Original
Message-----

From: Peter Larsen Borresen
[mailto:]

Sent: Thursday, September 29, 2005 10:40 PM

To: Kama, Kamarudin Bin Tambi;
; 

Cc: Grace Ng, Swee Lee (T&L);
Jern Kuan, Leong; Fu Wang, Thio

Subject: SV: [ubl-tsc] [Fwd:
[ubl-psc] Proposal for a signature refenrence]

 

Hi Kama

 

Do I
understand you correctly when that ebXML supports a solution where the
xml-document and the signature are in the same envelope, but in different
payloads?

           
Kama>> Think you've misunderstood. COML is not a messaging protocol but a
business document. What we mentioned is that in our solution, the COML approach
is independent of the messaging layer. The digsig is embedded inside the COML
document and is used by the application for multi-signer approval workflows. In
ebXML case, the digsig done in the soap header is only used for the transport
layer.

 

What I
suggest is that the xml-document becomes able to refer to the signature, not
only as a URL but also as a Mime reference. 

           
Kama>> OK, noted.

 

The
problem with embeddign the siganture in the xml-document is 

1) it
becomes invalid if it is transformed to an other document. 

           
Kama>> How does this differ from your proposed approach? Whenever any XML
document is being transformed, the digsig is no longer valid.

 

2) A
digital signature on a xml document is not valid in legal terms. Only a
transformation of a xml-document can be brought into a court room.

           
Kama>> Think lets not get into the legal aspect of it. Each country will
have its own Electronic Transaction Act. Interpretation might differ from
country to country.

 

3) A
digital signature with the purpose of ensuring that no one has tampered with
the document has nothing to do in a procurement document. This is a matter for
the transportation layer.

           
Kama>> This depends on whether the entire procurement process requires
the document to be signed or not. 

 

What is
needed at the business level is infomation about whether someone actual has
aproved the document. On the other hand, to reference the signature gives you
problem with consistency and persistency. This can be solved by adding two more
fields in document reference: GaranteeStoragePeriode and Hashcode (perhaps
hashmethod as well).

Kama>>
So, there's a problem with detached signature?

 

I would
like to here more about your requirements.

 

Kind
regards

 

Peter L.
Borresen

-----Oprindelig meddelelse-----

Fra: Kama, Kamarudin Bin Tambi
[mailto:]

Sendt: 29. september 2005 09:02

Til: ;
; Peter Larsen Borresen

Cc: Grace Ng, Swee Lee (T&L);
Jern Kuan, Leong; Fu Wang, Thio

Emne: RE: [ubl-tsc] [Fwd:
[ubl-psc] Proposal for a signature refenrence]

Hi
Peter, Tim,

Sorry
for the late response. We have reviewed the proposal for signature reference.
Below is our comment:-

 

1.     
The signature reference calls for the usage of
detached signature. This would be useful in scenario where binary data is
involved and where the referenced signature is always available and accessible
via the specified URL 

2.     
Both ebXML messaging service and COML however
uses the enveloped approach, wherein the digital signature (digsig) is embedded
inside the message itself. In the case of COML, XPath is being used to
reference the appropriate section of the payload that needs the digsig. This is
a preferred approach where we need to perform online verification of digsig.
Hence, there will not be a need to make reference to an external resource,
which may not be available at the time when the digsig verification is being
performed. This reduces the possibility of digsig failure. 

 

We would
urge that you study the COML approach in handling digsig for XML payload.

 

Regards

Kama

UBL TSC
Chair

 

 

-----Original
Message-----

From: Tim McGrath
[mailto:]

Sent: Tuesday, September 13, 2005
9:06 PM

To: 

Subject: [ubl-tsc] [Fwd: [ubl-psc]
Proposal for a signature refenrence]

 

forwarded from Peter
Borresen. 

this is a sample isnatcen of his propsoed digital signature approach.  can
we get some technical feedback on the suitability of this for our needs.
Next in thread → Next in month →