Signing and Encrypting XML

XML Signature (1.1, W3C Recommendation 11 April 2013) signs a whole document or selected elements after canonicalization, which removes the differences that parsing does not preserve (Infoset and Tree Model): attribute order, namespace declarations, whitespace inside tags. SAML assertions, SOAP's WS-Security and e-invoicing formats rely on it. xmlsec1 (github.com/lsh123/xmlsec (https://github.com/lsh123/xmlsec 164 ), MIT) signs a template whose Signature element names the algorithms, here an enveloped RSA-SHA256 signature over the feed:

sign-template.xml: a feed with an empty enveloped signatureXML
<catalog-feed id="feed">
  <book id="b3"><title>Salt and Saffron</title><price currency="USD">24.00</price></book>
  <Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
    <SignedInfo>
      <CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
      <SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
      <Reference URI="">
        <Transforms>
          <Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
          <Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </Transforms>
        <DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
        <DigestValue/>
      </Reference>
    </SignedInfo>
    <SignatureValue/>
  </Signature>
</catalog-feed>
Signing, verifying, then verifying a changed priceShell
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out feed.key 2> /dev/null
openssl pkey -in feed.key -pubout -out feed.pub
xmlsec1 --sign --lax-key-search --privkey-pem feed.key --output signed.xml sign-template.xml
grep -c '<SignatureValue>.' signed.xml
verify="xmlsec1 --verify --lax-key-search --pubkey-pem feed.pub"
$verify signed.xml 2>&1 | grep -E 'status|reason'
sed 's/>24.00</>2.40</' signed.xml > tampered.xml
$verify tampered.xml 2>&1 | grep -E 'status|reason'
Output
Signature status: OK
1
Verification status: OK
Verification status: FAILED
Failure reason: REFERENCE

The changed price no longer matched the digest in Reference. XML Encryption (1.1, also 11 April 2013) replaces an element with EncryptedData, and xmlsec1 handles it with --encrypt and --decrypt templates. When you consume signed XML, check what was signed: use only the elements the verified Reference covers, because signature-wrapping attacks move signed content beside unsigned content in the same document.


XKMS

XML Key Management Specification (XKMS) uses public key infrastructure (PKI) to secure communication among applications. Web services can receive updated key information from an XKMS-compliant server for encryption and authentication.

XKMS is made up of:

The following demonstrates encryption.
ch12-xkms-encryption-example.xmlXML
<?xml version="1.0"?>
<PaymentInfo xmlns="http://example.org/paymentv2">
  <Name>John Smith</Name>
  <CreditCard Limit="5,000" Currency="USD">
    <Number>
      <EncryptedData
          xmlns="http://www.w3.org/2001/04/xmlenc#"
          Type="http://www.w3.org/2001/04/xmlenc#Content">
        <CipherData>
          <CipherValue>A23B45C56</CipherValue>
        </CipherData>
      </EncryptedData>
    </Number>
    <Issuer>Example Bank</Issuer>
    <Expiration>04/02</Expiration>
  </CreditCard>
</PaymentInfo>

(Courtesy of http://www.w3.org/TR/2013/REC-xmlenc-core1-20130411/ 189 )

The following shows a signature.
ch12-xkms-signature-example.xmlXML
<Signature Id="MyFirstSignature"
           xmlns="http://www.w3.org/2000/09/xmldsig#">
   <SignedInfo>
      <CanonicalizationMethod
          Algorithm="http://www.w3.org/2006/12/xml-c14n11"/>
      <SignatureMethod
          Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
      <Reference
          URI="http://www.w3.org/TR/2000/REC-xhtml1-20000126/">
         <Transforms>
            <Transform Algorithm="http://www.w3.org/2006/12/xml-c14n11"/>
         </Transforms>
         <DigestMethod
             Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
         <DigestValue>
            dGhpcyBpcyBub3QgYSBzaWduYXR1cmUK...
         </DigestValue>
      </Reference>
   </SignedInfo>
   <SignatureValue>...</SignatureValue>
   <KeyInfo>
      <KeyValue>
         <DSAKeyValue>
            <P>...</P><Q>...</Q><G>...</G><Y>...</Y>
         </DSAKeyValue>
      </KeyValue>
   </KeyInfo>
</Signature>

(Courtesy of http://www.w3.org/TR/2013/REC-xmldsig-core1-20130411/ 189 )