Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Notes about deviation from profile are not being stated in the DSGj profile #13

Open
ritikarawlani opened this issue May 8, 2024 · 0 comments
Labels
open-issue Open Issue mentioned in the Implementation Guide

Comments

@ritikarawlani
Copy link
Contributor

It is presumed that the deviations from the profile will yield implementations non-conformant to the DSGj profile and that doesn't need to be explicitly stated.

Repeated below is the content that was proposed but not included inthe chapter.

"Note that Content Creators and Content Consumers should be capable of being configured to other conformance policies to support local policy. For example, some environments may choose a different JAdES profile, hashing algorithm, policy identifier, or signature purpose vocabulary. Content Creators would thus create Digital Signature blocks that are not conformant to this profile. Content Consumers can validate these Digital Signature blocks, and be capable of configured behavior according to the local policy. Deviations from these guidelines would need to be expressed in site policy and would be enumerated in the JWS-Signature block. For example, some environments may choose a different hashing algorithm, policy identifier, or signature purpose vocabulary. Some regions also require conformance to ISO 17090, which includes additional Certificate issuing, content, and validation rules."

@JohnMoehrke JohnMoehrke added the open-issue Open Issue mentioned in the Implementation Guide label May 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
open-issue Open Issue mentioned in the Implementation Guide
Projects
None yet
Development

No branches or pull requests

2 participants