[xmlsec] Encryption and namespace

xs04.jmdesp at free.fr xs04.jmdesp at free.fr
Fri May 7 09:17:04 PDT 2004


Quoting Aleksey Sanin <aleksey at aleksey.com>:
> >   is the decryptor required to perform "parsing" ? 
> Not in the spec. One can dump the document and decrypted piece into
> a string and then parse the whole document back. Not very fast
> and not very efficient :(
> 
> > That's an implementation issue. Parsing a substring within a node
> > context
> > could be a useful addition to libxml2 API, I'm not saying it's impossible
> > but I try to understand the real scope of the problem, in order to get
> > the right solution. There is more than just in-scope namespaces which are
> > inherited from a document, like entities ...
> Yes, you are right. It's much more. The general idea behind the spec is
> that you get a piece of XML document and encrypt it, then someone
> decrypts this piece and gets original XML document "as-is".

I'm coming back about this. 
I think it would be a good thing to open a bug in both xmlsec and libxml2 to
keep track of this issue and of whether any progress is made toward a solution
and give the number of the bugs on the xmlsec mailing-list.



More information about the xmlsec mailing list