Re: [saag] Fwd: [widgets] New WD of Widgets 1.0: Digital Signatures spec published on March 31

Ben Laurie <benl@google.com> Mon, 06 April 2009 13:07 UTC

Return-Path: <benl@google.com>
X-Original-To: saag@core3.amsl.com
Delivered-To: saag@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9471328C164 for <saag@core3.amsl.com>; Mon, 6 Apr 2009 06:07:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.977
X-Spam-Level:
X-Spam-Status: No, score=-101.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AVAvbPThAPpC for <saag@core3.amsl.com>; Mon, 6 Apr 2009 06:07:52 -0700 (PDT)
Received: from smtp-out.google.com (smtp-out.google.com [216.239.33.17]) by core3.amsl.com (Postfix) with ESMTP id 1758C3A6C20 for <saag@ietf.org>; Mon, 6 Apr 2009 06:07:51 -0700 (PDT)
Received: from wpaz21.hot.corp.google.com (wpaz21.hot.corp.google.com [172.24.198.85]) by smtp-out.google.com with ESMTP id n36D8uHB032691 for <saag@ietf.org>; Mon, 6 Apr 2009 14:08:56 +0100
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=google.com; s=beta; t=1239023336; bh=wnK4DsD6y/na9wHWwm0LDr6EuJY=; h=DomainKey-Signature:MIME-Version:In-Reply-To:References:Date: Message-ID:Subject:From:To:Cc:Content-Type: Content-Transfer-Encoding:X-System-Of-Record; b=ghzncHaD5p5oUM4fB8 zst8OsSRGRWEtiCm5uQu9qeOGnUGchfud+e1iUTZsyfZ4R/F1yr1QhhOsUuQxjNhLo9 A==
DomainKey-Signature: a=rsa-sha1; s=beta; d=google.com; c=nofws; q=dns; h=mime-version:in-reply-to:references:date:message-id:subject:from:to: cc:content-type:content-transfer-encoding:x-system-of-record; b=J/K5EewH1Qy3/h0L/x41AbftY23wOf2N82TOyebVoGEvh0d/xmtpjNoWbcRpxDEuq ar3gbk3l8l/VFFGjwn+rA==
Received: from fg-out-1718.google.com (fge13.prod.google.com [10.86.5.13]) by wpaz21.hot.corp.google.com with ESMTP id n36D8skY010260 for <saag@ietf.org>; Mon, 6 Apr 2009 06:08:54 -0700
Received: by fg-out-1718.google.com with SMTP id 13so678503fge.12 for <saag@ietf.org>; Mon, 06 Apr 2009 06:08:53 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.86.82.16 with SMTP id f16mr3195089fgb.32.1239023333820; Mon, 06 Apr 2009 06:08:53 -0700 (PDT)
In-Reply-To: <E8598CF1-BEA8-4E38-BD1B-B473B24FAA5A@w3.org>
References: <120077F4-0B65-4032-B5A2-FA8FA1330695@nokia.com> <E8598CF1-BEA8-4E38-BD1B-B473B24FAA5A@w3.org>
Date: Mon, 06 Apr 2009 14:08:53 +0100
Message-ID: <1b587cab0904060608x14ccee52g2d16c4e780f8cd5@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: Thomas Roessler <tlr@w3.org>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
Cc: Arthur Barstow <art.barstow@nokia.com>, saag@ietf.org, Frederick Hirsch <Frederick.Hirsch@nokia.com>
Subject: Re: [saag] Fwd: [widgets] New WD of Widgets 1.0: Digital Signatures spec published on March 31
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/saag>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Apr 2009 13:07:59 -0000

2009/4/2 Thomas Roessler <tlr@w3.org>:
> FYI.
> Note that the document is referencing an upcoming version of XML Signature,
> which is currently in Working Draft status.
> There is an expectation that this profile (not the base spec) might undergo
> a W3C last call relatively soon, so this would be a good time to review the
> specification.

I find it pretty annoying that signing widgets is described as a
"trust and quality assurance mechanism".

> --
> Thomas Roessler, W3C  <tlr@w3.org>
>
>
>
>
>
> Begin forwarded message:
>
> From: Arthur Barstow <art.barstow@nokia.com>
> Date: 2 April 2009 18:21:19 GMT+02:00
> To: public-webapps <public-webapps@w3.org>
> Subject: [widgets] New WD of Widgets 1.0: Digital Signatures spec published
> on March 31
> Archived-At:
> <http://www.w3.org/mid/120077F4-0B65-4032-B5A2-FA8FA1330695@nokia.com>
> On March 31 a new WD of the Widgets 1.0 Digital Signature spec was published
> and announced on the W3C's home page:
>
> [[
> 2009-03-31: The Web Applications Working Group has published a Working Draft
> of Widgets 1.0: Digital Signatures. This document defines a profile of the
> XML Signature Syntax and Processing 1.1 specification to allow a widget
> package to be digitally signed. Widget authors and distributors can
> digitally sign widgets as a trust and quality assurance mechanism. Prior to
> instantiation, a user agent can use the digital signature to verify the
> integrity of the widget package and perform source authentication. This
> document specifies conformance requirements on both widget packages and user
> agents.
> ]]
>
> Please review this new WD as soon as possible, preferably within the next
> two weeks:
>
> <http://www.w3.org/TR/2009/WD-widgets-digsig-20090331/>
>
> -Regards, Art Barstow
>
>
>
> _______________________________________________
> saag mailing list
> saag@ietf.org
> https://www.ietf.org/mailman/listinfo/saag
>
>