XML Signature (1.1, W3C Recommendation 11 April 2013) signs a whole document or selected elements after canonicalization, which removes the differences that parsing does not preserve (Infoset and Tree Model): attribute order, namespace declarations, whitespace inside tags. SAML assertions, SOAP's WS-Security and e-invoicing formats rely on it. xmlsec1 (github.com/lsh123/xmlsec (https://github.com/lsh123/xmlsec 164 ), MIT) signs a template whose Signature element names the algorithms, here an enveloped RSA-SHA256 signature over the feed:
<catalog-feed id="feed">
<book id="b3"><title>Salt and Saffron</title><price currency="USD">24.00</price></book>
<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<Reference URI="">
<Transforms>
<Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</Transforms>
<DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<DigestValue/>
</Reference>
</SignedInfo>
<SignatureValue/>
</Signature>
</catalog-feed>openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out feed.key 2> /dev/null
openssl pkey -in feed.key -pubout -out feed.pub
xmlsec1 --sign --lax-key-search --privkey-pem feed.key --output signed.xml sign-template.xml
grep -c '<SignatureValue>.' signed.xml
verify="xmlsec1 --verify --lax-key-search --pubkey-pem feed.pub"
$verify signed.xml 2>&1 | grep -E 'status|reason'
sed 's/>24.00</>2.40</' signed.xml > tampered.xml
$verify tampered.xml 2>&1 | grep -E 'status|reason'Signature status: OK 1 Verification status: OK Verification status: FAILED Failure reason: REFERENCE
The changed price no longer matched the digest in Reference. XML Encryption (1.1, also 11 April 2013) replaces an element with EncryptedData, and xmlsec1 handles it with --encrypt and --decrypt templates. When you consume signed XML, check what was signed: use only the elements the verified Reference covers, because signature-wrapping attacks move signed content beside unsigned content in the same document.
XKMS
XML Key Management Specification (XKMS) uses public key infrastructure (PKI) to secure communication among applications. Web services can receive updated key information from an XKMS-compliant server for encryption and authentication.XKMS is made up of:
- X-KISS (XML Key Information Service Specification) outlines the syntax that delegates the tasks required to process the key information element of an XML signature to a trust service.
- X-KRSS (XML Key Registration Service Specification) outlines the registration of public key information.
<?xml version="1.0"?>
<PaymentInfo xmlns="http://example.org/paymentv2">
<Name>John Smith</Name>
<CreditCard Limit="5,000" Currency="USD">
<Number>
<EncryptedData
xmlns="http://www.w3.org/2001/04/xmlenc#"
Type="http://www.w3.org/2001/04/xmlenc#Content">
<CipherData>
<CipherValue>A23B45C56</CipherValue>
</CipherData>
</EncryptedData>
</Number>
<Issuer>Example Bank</Issuer>
<Expiration>04/02</Expiration>
</CreditCard>
</PaymentInfo>
(Courtesy of http://www.w3.org/TR/2013/REC-xmlenc-core1-20130411/ 189 )
The following shows a signature.<Signature Id="MyFirstSignature"
xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod
Algorithm="http://www.w3.org/2006/12/xml-c14n11"/>
<SignatureMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<Reference
URI="http://www.w3.org/TR/2000/REC-xhtml1-20000126/">
<Transforms>
<Transform Algorithm="http://www.w3.org/2006/12/xml-c14n11"/>
</Transforms>
<DigestMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<DigestValue>
dGhpcyBpcyBub3QgYSBzaWduYXR1cmUK...
</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>...</SignatureValue>
<KeyInfo>
<KeyValue>
<DSAKeyValue>
<P>...</P><Q>...</Q><G>...</G><Y>...</Y>
</DSAKeyValue>
</KeyValue>
</KeyInfo>
</Signature>
(Courtesy of http://www.w3.org/TR/2013/REC-xmldsig-core1-20130411/ 189 )