W3C Technology and Society Domain

XML Security Working Group

On this page:
Mission | News | Current Drafts | Code & Toolkits | The Chairs | Meetings & Calls | Background Reading
Nearby:
Charter | Roadmap | Publication Status | Interop | Participants | Patent Policy Status | Security Activity Statement | WG Members Page
Historic Working Group Pages:
XML Signature
XML Encryption
XML Security Maintenance WG
Chair(s):
Frederick Hirsch <frederick.hirsch@nokia.com>
Mailing Lists
General, Technical and Public Discussions: public-xmlsec@w3.org
Administrative issue Discussions: member-xmlsec@w3.org
Public Comment List: public-xmlsec-comments@w3.org; Archives
Public General Discussion List: public-xmlsec-discuss@w3.org; Archives
W3C IETF XML Signature Discussion List: w3c-ietf-xmlsig@w3.org; Archives
Join the Working Group: Apply here!
Public Archive: http://lists.w3.org/Archives/Public/public-xmlsec/
Member Archive: http://lists.w3.org/Archives/Member/member-xmlsec/
Historical XML Sec Maintenance WG Archive: http://lists.w3.org/Archives/Public/public-xmlsec-maintwg/

Mission

The Group is part of the Security Activity. It takes up prior W3C Work on XML Signature and XML Encryption, as well as work from the XML Security Specifications Maintenance Working Group, that produced XML Signature, Second Edition.

News

2009-04-30: The Web Applications Working Group has published the Last Call Working Draft of Widgets 1.0: Digital Signatures. This document defines a profile of the XML Signature Syntax and Processing 1.1 specification to allow a widget package to be digitally signed. Widget authors and distributors can digitally sign widgets as a mechanism to ensure continuity of authorship and distributorship. A user agent can use the digital signature to verify the integrity of the widget package and to confirm the signing key(s). Comments are welcome through 01 June. The Working Group also published an updated Working Draft of Widgets 1.0: Requirements. Learn more about the Rich Web Client Activity. (Permalink to W3 news announcement.)

2009-04-30: The XML Security Working Group has published a Working Draft of XML Signature Properties. This document outlines proposed standard XML Signature Properties syntax and processing rules and an associated namespace for these properties. The intent is these can be composed with any version of XML Signature using the XML SignatureProperties element. Learn more about the Security Activity. (Permalink to W3C news announcement)

2009-02-26: The XML Security Working Group has published a set of eight Working Drafts. The XML Signature 1.1 and XML Encryption 1.1 First Public Working Drafts make changes to the default sets of cryptographic algorithms in both specifications. XML Security Use Cases and Requirements and XML Signature Transform Simplification: Requirements and Design are documents that we expect to help guide the group's work on a future version of the XML Security specifications that might make more radical changes than the 1.1 series of these specifications. The Working Group would like to receive early feedback on these four drafts.

Additionally, the XML Security Derived Keys specification introduces mark-up for key derivation, for use with both XML Signature and XML Encryption. XML Signature Properties defines commonly used signature properties. XML Security Algorithms is a cross-reference for the algorithms and their identifiers used with the XML security specifications, bringing in one place information located in a number of documents. XML Signature Best Practices is a revised Working Draft for Best Practices in using the XML Signature specification. (Permalink)

These Working Drafts are currently open for public comment - to send external comments to the Working Group, please use the mailing list public-xmlsec-comments @ w3.org.

2009-11-18 First Public Working Draft of Best Practices for XML Signature published.

Current Drafts

Please send comments related to these documents to public-xmlsec-comments@w3.org. There is a public archive of comments received.

A set of 1.1 specifications introduce new mandatory algorithms and other updates to the current XML Security specifications, as well as introducing new material related to derived keys, signature properties and a summary of algorithms. The Working Group is seeking feedback on these changes.

XML Signature v1.1

http://www.w3.org/TR/2009/WD-xmldsig-core1-20090226/
First Public Working Draft, 26 February 2009

XML Encryption v1.1

http://www.w3.org/TR/2009/WD-xmlenc-core1-20090226/
First Public Working Draft, 26 February 2009

XML Security Derived Keys

http://www.w3.org/TR/2009/WD-xmlsec-derivedkeys-20090226/
First Public Working Draft, 26 February 2009

XML Signature Properties

http://www.w3.org/TR/2009/WD-xmldsig-properties-20090430/
Working Draft, 30 April 2009

XML Security Algorithms Note

http://www.w3.org/TR/2009/WD-xmlsec-algorithms-20090226/
First Public Working Draft, 26 February 2009

The XML Security working group is also considering a more extensive revision to XML Signature and is seeking feedback on the use cases and requirements as well as some potential design changes.

XML Security Use Cases and Requirements

http://www.w3.org/TR/2009/WD-xmlsec-reqs-20090226/
First Public Working Draft, 26 February 2009

XML Signature Transform Simplification: Requirements and Design

http://www.w3.org/TR/2009/WD-xmldsig-simplify-20090226/
First Public Working Draft, 26 February 2009

The XML Security WG has also revised its XML Signature Best Practices document:

XML Signature Best Practices

http://www.w3.org/TR/2009/WD-xmldsig-bestpractices-20090226/
Working Draft, Updated, 26 February 2009

Test Suites, Public Code and Toolkits

If you would like to appear in this list, send an announcement to the XML Security public mailing list.

Meetings and Teleconferences

Face-to-Face Announcements and Minutes

Telecon Agenda and Minutes

Optional teleconferences happen as required. See the archive for the latest teleconference announcement. Minutes are posted to the list; WG members are obligated to review, correct, or counter any proposals or consensus achieved on the call on the list.

Background Reading


Chair: Frederick Hirsch
Team Contact and Security Activity Lead: Thomas Roessler
$Id: Overview.html,v 1.63 2009/06/23 18:14:54 fhirsch3 Exp $