Updated XML Signature 1.1 and XML Encryption 1.1 change explanation documents

I've brought the explanation documents for XML Signature 1.1 and XML Encryption 1.1 up to date to reflect changes we've made since mid-February 2011, review welcome:

XML Signature 1.1 explain:

New mention and reference  to best practices in introduction
Changes to prefer KeyInfoReference over RetrievalMethod
Scope clarifications for KeyInfo section.

Reference updates:

fix bad link for OpenPGP (referred to obsolete RFC 2440 instead of 4880)
update XML Signature Best Practices reference
Update XMLSEC-RELAXNG reference
update ABA digital signature guidelines reference
update RFC 4949 to refer to text version for consistency
update RELAXNG-SCHEMA reference to document reference

--------
XML Encryption 1.1 explain:

add type='anyURI' to Algorithm for AlgorithmIdentifierType, ACTION-824
Added information on patent advisory group and additional patent disclosures to status section
changed "[XMLENC-CORE1]" to "(XMLENC-CORE1, this document)" in media type section to avoid generating normative self reference, to resolve LC-2541
revise base64 note in algorithms section
clarify  Encoding attribute in 3.1. Clarifications to resolve LC-2542
add new security considerations section on timing attacks
add Note re ConcatKDF nonce in section 5.4.1
Updates for RSA-OAEP

Reference updates:
Updated reference, in particular link, for RIPEMD-160.
rfc2633 obsoleted by 3851 (S/MIME v3 to v3.1)
rfc 2048 obsoleted by 4289 (MIME Part 4 registration procedures)
update  XMLSEC-RELAXNG references to reflect April 2011 publication
update RELAXNG-SCHEMA reference to document reference

---

This should complete ACTION-838  and ACTION-839

regards, Frederick

Frederick Hirsch
Nokia

Received on Thursday, 13 October 2011 14:50:02 UTC