Phase 3: XML signature — Apache Santuario sign/verify (+ xmlsec1/signxml/.NET refs) - #3
Merged
karlkauc merged 1 commit intoMay 15, 2026
Conversation
XML_Signature/: enveloped XML-DSig, RSA-SHA256 / exclusive-C14N, ds:Signature appended as last child of <FundsXML4> (schema-allowed). Java/Apache Santuario (xmlsec 4.0.4) sign + verify verified locally incl. tamper detection and that the signed file stays XSD-valid; secure validation enabled on verify. generate-test-key.sh makes a throwaway RSA keypair (keys/ gitignored). xmlsec1 CLI, Python signxml and .NET SignedXml provided as references with the same profile so files cross-verify. tools/fetch-tools.sh also fetches Santuario (xmlsec + commons-codec + slf4j). CI gains a sign->verify->tamper roundtrip step (verified locally). Top-level index row -> done. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 3 of the enterprise FundsXML showcase. Stacked on PR #2 (base =
feature/enterprise-showcase-phase2); merge that first. Diff is Phase 3 only.Added —
XML_Signature/Enveloped XML-DSig, one profile across all stacks (RSA-SHA256, exclusive C14N, SHA-256,
ds:Signatureas the last child of<FundsXML4>— exactly where the 4.2.9 schema allows it via thexmldsig-core-schema.xsdimport).xmlsec 4.0.4) —SignFundsXml+VerifyFundsXml. Verified locally: sign → verify (embedded key and pinned cert) → signed file still XSD-valid → tampered file correctly rejected. Verify runs with Santuario secure validation on.generate-test-key.sh— throwaway self-signed RSA-2048 (PKCS#12 + PEM);XML_Signature/keys/is gitignored (never commit private keys).xmlsec1CLI, Pythonsignxml, .NETSignedXml.tools/fetch-tools.shalso fetches Santuario; CI gains a sign→verify→tamper roundtrip step (verified locally). Pairs with the committedSigned_Fund_Skeleton.xmlplaceholder (xmlsec1 signs an existing template).No real signed file is committed — the signature binds to the per-run throwaway key; CI exercises the roundtrip instead.
Roadmap remaining: Phase 4 DB integration (code only) · 5 large-file/stream · 6 data binding/JSON.
🤖 Generated with Claude Code