RE: [xml-dev] Is the XML Schema for XML Digital Signatures needed?

From
Costello, Roger L. <>
To
"" <>
Date
2018-07-27T18:36:40Z
ID
<>
Thread
RE: [xml-dev] Is the XML Schema for XML Digital Signatures needed?
Hi Liam,

Suppose that I have this XML instance document:

<Document>
    <foo>abc</foo>
    <ds:Signature xmlns:ds="...">
        ...
    </ds:Signature>
</Document>

My argument says that, an XML Schema for <Document> should simply use an <xs:any namespace="http://www.w3.org/2000/09/xmldsig#" /> element where the digital signature is to occur:

<xs:element name="Document">
    <xs:complexType>
        <xs:sequence>
            <xs:element name="foo" type="xs:string" />
            <!-- Put your XML Digital Signature here, but I ain't gonna schema-validate it! -->
            <xs:any namespace="http://www.w3.org/2000/09/xmldsig#" /> 
        </xs:sequence>
    </xs:complexType>
</xs:element>

My argument says, don't do this:

<xs:import namespace="http://www.w3.org/2000/09/xmldsig#"
    schemaLocation="xmldsig.xsd"/>

<xs:element name="Document">
    <xs:complexType>
        <xs:sequence>
            <xs:element name="foo" type="xs:string" />
            <xs:element ref="ds:Signature" /> <!-- Validate against the XML Schema for xmldigsig -->
        </xs:sequence>
    </xs:complexType>
</xs:element>

My argument is that the digsig tools will ensure that the signature is correct, so don't bother validating against the XML Schema for xmldigsig.

Do you buy that argument?

/Roger