Skip to content

Phase 3: XML signature — Apache Santuario sign/verify (+ xmlsec1/signxml/.NET refs) - #3

Merged
karlkauc merged 1 commit into
feature/enterprise-showcase-phase2from
feature/enterprise-showcase-phase3
May 15, 2026
Merged

karlkauc merged 1 commit into
feature/enterprise-showcase-phase2from
feature/enterprise-showcase-phase3

Conversation

@karlkauc

Copy link
Copy Markdown
Contributor

Phase 3 of the enterprise FundsXML showcase. Stacked on PR #2 (base = feature/enterprise-showcase-phase2); merge that first. Diff is Phase 3 only.

Added — XML_Signature/

Enveloped XML-DSig, one profile across all stacks (RSA-SHA256, exclusive C14N, SHA-256, ds:Signature as the last child of <FundsXML4> — exactly where the 4.2.9 schema allows it via the xmldsig-core-schema.xsd import).

  • Java / Apache Santuario (xmlsec 4.0.4) — SignFundsXml + VerifyFundsXml. Verified locally: sign → verify (embedded key and pinned cert) → signed file still XSD-valid → tampered file correctly rejected. Verify runs with Santuario secure validation on.
  • generate-test-key.sh — throwaway self-signed RSA-2048 (PKCS#12 + PEM); XML_Signature/keys/ is gitignored (never commit private keys).
  • References (same profile, cross-verify): xmlsec1 CLI, Python signxml, .NET SignedXml.
  • tools/fetch-tools.sh also fetches Santuario; CI gains a sign→verify→tamper roundtrip step (verified locally). Pairs with the committed Signed_Fund_Skeleton.xml placeholder (xmlsec1 signs an existing template).

No real signed file is committed — the signature binds to the per-run throwaway key; CI exercises the roundtrip instead.

Roadmap remaining: Phase 4 DB integration (code only) · 5 large-file/stream · 6 data binding/JSON.

🤖 Generated with Claude Code

XML_Signature/: enveloped XML-DSig, RSA-SHA256 / exclusive-C14N, ds:Signature
appended as last child of <FundsXML4> (schema-allowed). Java/Apache Santuario
(xmlsec 4.0.4) sign + verify verified locally incl. tamper detection and that
the signed file stays XSD-valid; secure validation enabled on verify.
generate-test-key.sh makes a throwaway RSA keypair (keys/ gitignored).
xmlsec1 CLI, Python signxml and .NET SignedXml provided as references with the
same profile so files cross-verify.

tools/fetch-tools.sh also fetches Santuario (xmlsec + commons-codec + slf4j).
CI gains a sign->verify->tamper roundtrip step (verified locally). Top-level
index row -> done.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@karlkauc
karlkauc merged commit f23d03a into feature/enterprise-showcase-phase2 May 15, 2026
2 checks passed
@karlkauc
karlkauc deleted the feature/enterprise-showcase-phase3 branch May 15, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant