index.html 12.8 KB
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"

<html xmlns="">
<head profile="">
  <meta name="generator" content=
  "HTML Tidy for Mac OS X (vers 31 October 2006 - Apple Inc. build 13), see" />
  <meta http-equiv="Content-Type" content=
  "text/html; charset=us-ascii" />

  <title>W3C XML Security Working Group</title>
  <link rel="stylesheet" type="text/css" href=
  "" />

  <p><a href="../"><img src=""
  alt="W3C" /></a> <a href=""><img src=
  "" alt=
  "Technology and Society Domain" width="212" height=
  "48" /></a></p>

  <h1>XML Security Working Group</h1>

    <dt>On this page:</dt>

    <dd><a href="#Mission">Mission</a> | <a href="#news">News</a> |  <a href=
    "#CurrentDrafts">Current Drafts</a> | 
      <a href="#meetings">Meetings</a> | 
      <a href="#Code">Code &amp; Toolkits</a> |
      <a href="#Responsibilities">The Chairs</a> |
      <a href="#Background">Background Reading</a></dd>


    <dd><a rel="charter" href=
    "">Charter</a> |
      <a rel="roadmap" 
        Roadmap</a> |
      <a rel="publicationstatus" 
        Publication Status</a> |
      <a rel="minutes" 
        Approved meeting minutes</a> |
      <a rel="implementations" 
      Implementations</a> |
      <a rel="interop" 
      | <a rel="participants" href=
    Participants</a> | 
    <!-- <a href="Contributor.html">Contributor Policies</a> |
       --> <a href=
"">Patent Policy
Status</a> | <a rel="activity" href=
"">Security Activity
Statement</a> | <a href=
"">WG Members
        Page</a> |
<a href="papers/">Papers</a></dd>

    <dt>Historic Working Group Pages:</dt>

    <dd><a href="">XML

    <dd><a href="">XML

    <dd><a href="">XML Security
    Maintenance WG</a></dd>

    <dt id="Responsibilities">Chair(s):</dt>

    <dd>Frederick Hirsch &lt;<a href=

    <dt><a id="lists" name="lists">Mailing Lists</a></dt>

    <dd>General, Technical and Public Discussions: <a href=

    <dd>Administrative issue Discussions: <a href=

    <dd>Public Comment List: <a href=
    <a href=

    <dd>Public General Discussion List: <a href=
    <a href=

    <dd>W3C IETF XML Signature Discussion List: <a href=
    <a href=

    <dd>Join the Working Group: Apply <a href=

    <dd>Public Archive: <a href=

    <dd>Member Archive: <a href=

    <dd>Historical XML Sec Maintenance WG Archive: <a href=

  <h2 id="Mission">Mission</h2>

  <p>The Group is part of the <a href=
  "">Security Activity</a>. It takes up
  prior W3C Work on <a href="">XML
  Signature</a> and <a href=
  "">XML Encryption</a>, as well
  as work from the <a href="">XML
  Security Specifications Maintenance Working 
  Group</a>, that produced <a href="">XML Signature, Second Edition</a>.</p>

  <h2 id="news">News</h2>
<span class="date">
  <a href="">2012-01-05</a>:
The <a href="">XML Security Working Group</a> has published a new Last Call 
Working Draft of "<a href="">XML Encryption 1.1</a>" to 
solicit review of changes since the previous CR publication. These
<li> make 
 the AES-128-GCM algorithm mandatory to implement, to address newly publicized chosen-ciphertext attacks against the CBC
 class of algorithms,</li>
<li>add new security considerations related to chosen-ciphertext attacks, timing attacks, 
 CBC block encryption vulnerabilities, and the insecure use of error
<li>add a new algorithm for the RSA-OAEP key transport  
 that does not require SHA-1 with the mask generation function,
 enabling use of various hash MGF combinations, and</li>
<li>include various editorial corrections. </li>
 The XML Security WG is also soliciting review of the Last Call working draft of
"<a href="">XML Encryption 1.1 CipherReference Processing using 2.0 Transforms</a>". 
This specification brings the simplification benefits 
of the ongoing  XML Security 2.0 effort to XML Encryption CipherReference transform processing. 
Feedback on both of these Last Call drafts is requested by 16 February 2012.
An update to the Note-track "<a href="">XML Security Algorithm Cross-Reference</a>" 
Working Draft reflects new algorithm definitions in XML Encryption 1.1. 
The XML Security working group has also published First Public Working Drafts 
of "<a href="">Test Cases for XML Encryption 1.1</a>" and 
"<a href="">Test Cases for Canonical XML 2.0</a>" and encourages 
community participation in developing further tests and performing testing.
<span class="date">
<a href="">2011-08-30</a>:
  Updated working draft of "<a
  href="">XML Security RELAX NG Schemas</a>" published.</span> 
This version of this specification is significantly different from the
  previous version. </p> 
<li>The prose has been completely rewritten. In particular, Taxonomy
  of schemas, Schema authoring techniques, and Schema indexes have
  been introduced.</li>
<li>xmldsig-filter2.rnc for XML-Signature XPath Filter 2.0 has been added.</li>
<li>xmldsig11-schema.rnc has been modified by adding X509Digest and invoking xmldsig-filter2.rnc.</li>
<li>Small bugs in xenc-schema-11.rnc and xmlsec-ghc-schema.rnc have been fixed.</li>
<li>any.rnc has been renamed as security_any.rnc</li>
<li>exclusiveC14N.rnc has been renamed as exc-c14n.rnc</li>
<li>Driver schemas have been thoroughly renamed.</li>

<p>For earlier news, visit the <a href="news.html">Previous News</a>

  <div class="blogitem">
    <h2 id="CurrentDrafts">Current Drafts</h2>
Current drafts are available from the 
      <a rel="publicationstatus" 
        Publication Status</a> page. Please send comments related to
        these documents to   
There is a <a
archive</a> of comments received. 
See also the <a
list of the XML Security published Technical Reports.
    <h2 id="meetings">Meetings</h2>

    <p>Optional teleconferences happen as required. See the WG 
<a href=
"">Members Page</a>
for upcoming meeting information.
Minutes are posted
    to the list; WG members are obligated to review, correct, or
    counter any proposals or consensus achieved on the call on the
    list. Minutes approved by the WG are <a href="minutes.html">publicly archived</a>.</p>

    <h2 id="Code">Test Suites, Public Code and Toolkits</h2>

    <p><em>If you would like to appear in this list, send an
    announcement to the <a href="">XML
    Security public mailing list</a>.</em></p>

      <!--      <li><a href="">EXI test
	   corpus</a> hosted by Naval Postgraduate school, Monterey,
	   CA</li> -->
      <li><a href="">Test Cases for C14N
      1.1 and XMLDSig Interoperability</a>, W3C Working Group Note, 2008-06-10</li>
      <li><a href="">XML-Signature
      Interoperability</a>, 2003-07-10</li>

    <h2 id="Background">Background Reading</h2>

      <li><a href=
      "">Working Group

      <li><a href=
      Signature Syntax and Processing, Second Edition</a>, W3C
      Recommendation, (<a href=
      of changes</a>, <a href=

      <li><a href=
      Report</a> from <a href=
      "">W3C Workshop
      on Next Steps for XML Signature and XML Encryption</a>.</li>

      <li><a href="">Using XML
      Digital Signatures in the 2006 XML Environment</a>, W3C
      Working Group Note</li>

      <li><a href="">Canonical XML
      1.1</a>, W3C Recommendation</li>

      <li><a href="">XML-Signature
          XPath Filter 2.0</a>,  W3C Recommendation</li>

      <li><a href="">XML
      Encryption</a>, W3C Recommendation.</li>

      <li><a href="">Decryption
      Transform for XML Signature</a> and 

<a href=
      Transform Errata</a></li>
  <hr />

  <address id="contact">
    Chair: <a href="">Frederick
    Hirsch</a><br />
    Team Contact and Security Activity Lead: <a href=
    "">Thomas Roessler</a><br />
    $Id: Overview.html,v 1.114 2012/01/06 14:44:10 fhirsch3 Exp $

  <p class="copyright"><a rel="Copyright" href=
  2007-2008 <a href=""><acronym title=
  "World Wide Web Consortium">W3C</acronym></a> (<a href=
  ""><acronym title=
  "Massachusetts Institute of Technology">MIT</acronym></a>,
  <a href=""><acronym title=
  "European Research Consortium for Informatics and Mathematics">ERCIM</acronym></a>,
  <a href="">Keio</a>), All Rights Reserved.
  W3C <a href=
  <a href=
  <a rel="Copyright" href=
  use</a> and <a rel="Copyright" href=
  licensing</a> rules apply. Your interactions with this site are
  in accordance with our <a href=
  and <a href=
  privacy statements.</p>