Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions docs/bugs.html
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@
<p>Before writing bug reports or questions do not hesitate to check <a href="faq.html">FAQ</a>.
If you are writing your own code based on the XMLSec library then you should
try to reproduce your problem with <a href="xmlsec-man.html">xmlsec command
line utiliy</a> first. And if it works just fine then you know whom to blame,
line utility</a> first. And if it works just fine then you know whom to blame,
don't you? :)
</p>

Expand Down Expand Up @@ -84,7 +84,7 @@
<div align="center">
<a href="http://www.google.com"><img src="images/bart.gif" alt="Ask google" border="0"></a>
</div>
<small>Unfortunatelly, I don't know the author of this picture and I was not
<small>Unfortunately, I don't know the author of this picture and I was not
able to ask permissions to publish it. If you are the author or know
the author then I would appreciate if you send me a message on GitHub so I can ask
permissions and put author's name here.</small>
Expand Down
4 changes: 2 additions & 2 deletions docs/faq.html
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
<h1>Frequently Asked Questions</h1>
</div>
<h3>0. Where can I read more about XML Signature and XML Encryption?</h3>
<p>First of all, read the original specifications: <a href="http://www.w3.org/Signature/">XML Digital Signature</a> and <a href="http://www.w3.org/Encryption/">XML Encrytpion</a>. Also there <a href="related.html#books">several books</a> available that can
<p>First of all, read the original specifications: <a href="http://www.w3.org/Signature/">XML Digital Signature</a> and <a href="http://www.w3.org/Encryption/">XML Encryption</a>. Also there <a href="related.html#books">several books</a> available that can
help you get started.<br></p>
<h3>1. License(s).</h3>
<h4> <a name="section_1_1"></a>1.1. Licensing Terms for
Expand Down Expand Up @@ -390,7 +390,7 @@ <h4>
|= XMLSEC_DSIG_FLAGS_USE_VISA3D_HACK</code> or <code>--enable-visa3d-hack</code>
option for xmlsec command line utility).</li>
</ul>
<b>This is a hack</b><b>. You are warned!</b><br><p><b>UPDATE:</b> It appears that recent version (Novemeber, 2005)
<b>This is a hack</b><b>. You are warned!</b><br><p><b>UPDATE:</b> It appears that recent version (November, 2005)
of Visa3D DTD does have this problem corrected and now "id" attribute
is declared as ID. Just get the new DTD and everything should work
without this hack.</p>
Expand Down
6 changes: 5 additions & 1 deletion docs/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,10 @@ <h1>XML Security Library</h1>
<li>(xmlsec-core) Hardened XML parser defaults for XXE mitigation across libxml2 versions.</li>
<li>(xmlsec-core) Added stronger overflow and conversion safety checks.</li>
<li>(xmlsec-core) Fixed multiple memory/resource issues on error paths.</li>
<li>(xmlsec-core) Enforced the max nesting depth when processing EncryptedKey elements (default is 1);
documents with deeper nested EncryptedKey structures will now fail to decrypt. Use the
`--max-encrypted-key-level &lt;level&gt;` option in the xmlsec command line tool (or set
`xmlSecKeyInfoCtx->maxEncryptedKeyLevel` in your application code) to adjust the limit.</li>
<li>(xmlsec-openssl) Improved X.509/CRL verification flow with verification-time-aware revocation checks and stricter CRL validity handling.</li>
<li>(xmlsec-gnutls) Prevented certificate-chain self-loop cases and improved SKI comparison behavior when SKI extension is absent.</li>
<li>(xmlsec-nss) Fixed certificate lookup memory handling in issuer/serial resolution paths.</li>
Expand Down Expand Up @@ -118,7 +122,7 @@ <h1>XML Security Library</h1>

<li>
July 11 2024<br>
The legacy a href="download.html">XML Security Library 1.2.40</a> release includes the following changes:
The legacy <a href="download.html">XML Security Library 1.2.40</a> release includes the following changes:
<ul>
<li>(xmlsec-core) Fixed functions deprecated in LibXML2 2.13.1 (including disabling HTTP support by default).</li>
<li>(xmlsec-nss) Increased keys size in all tests to support NSS 3.101.</li>
Expand Down
5 changes: 3 additions & 2 deletions docs/mailing-list.html
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<title>XML Security Library: Related</title>
<title>XML Security Library: Mailing List</title>
<link rel="stylesheet" href="css/main.css">
</head>
<body><table width="100%" valign="top"><tr valign="top">
Expand Down Expand Up @@ -52,5 +52,6 @@ <h1>XMLSec Mailing list is retired as of October, 2022</h1>
<p>The read-only <a href="http://www.aleksey.com/pipermail/xmlsec">XMLSec mailing list archive</a> will
continue to be available.</p>
</div>

</td></tr></table></td>
</tr></table></body>
</html>
4 changes: 4 additions & 0 deletions docs/news.html
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,10 @@ <h1>XML Security Library News</h1>
<li>(xmlsec-core) Hardened XML parser defaults for XXE mitigation across libxml2 versions.</li>
<li>(xmlsec-core) Added stronger overflow and conversion safety checks.</li>
<li>(xmlsec-core) Fixed multiple memory/resource issues on error paths.</li>
<li>(xmlsec-core) Enforced the max nesting depth when processing EncryptedKey elements (default is 1);
documents with deeper nested EncryptedKey structures will now fail to decrypt. Use the
`--max-encrypted-key-level &lt;level&gt;` option in the xmlsec command line tool (or set
`xmlSecKeyInfoCtx->maxEncryptedKeyLevel` in your application code) to adjust the limit.</li>
<li>(xmlsec-openssl) Improved X.509/CRL verification flow with verification-time-aware revocation checks and stricter CRL validity handling.</li>
<li>(xmlsec-gnutls) Prevented certificate-chain self-loop cases and improved SKI comparison behavior when SKI extension is absent.</li>
<li>(xmlsec-nss) Fixed certificate lookup memory handling in issuer/serial resolution paths.</li>
Expand Down
57 changes: 48 additions & 9 deletions docs/xmldsig.html
Original file line number Diff line number Diff line change
Expand Up @@ -285,7 +285,7 @@ <h4 style="text-align: center;">XML Digital Signature 1.0 (<a href="http://www.i
</tr>
<tr>
<td style="width: 40%;" align="left" valign="top">
<a href="http://www.w3.org/TR/xml-exc-c14n">Exlusive Canonical XML 1.0</a>
<a href="http://www.w3.org/TR/xml-exc-c14n">Exclusive Canonical XML 1.0</a>
</td>
<td valign="top">Y</td>
<td valign="top">Y</td>
Expand Down Expand Up @@ -341,7 +341,7 @@ <h4 style="text-align: center;">XML Digital Signature 1.0 (<a href="http://www.i
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
</tr>
Expand Down Expand Up @@ -386,7 +386,7 @@ <h4 style="text-align: center;">XML Digital Signature 1.0 (<a href="http://www.i
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
</tr>
Expand Down Expand Up @@ -440,7 +440,7 @@ <h4 style="text-align: center;">XML Digital Signature 1.0 (<a href="http://www.i
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
</tr>
Expand Down Expand Up @@ -494,7 +494,7 @@ <h4 style="text-align: center;">XML Digital Signature 1.0 (<a href="http://www.i
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y</td>
<td valign="top">N</td>
<td valign="top">Y</td>
</tr>
Expand Down Expand Up @@ -675,27 +675,66 @@ <h4 style="text-align: center;">Other algorithms</h4>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST94 digests</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST2001 signatures</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST-2012 (256 bit) digests</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST-2012 (512 bit) digests</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST-2012 (256 bit) signatures</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
<tr>
<td style="vertical-align: top; width: 40%;">GOST-2012 (512 bit) signatures</td>
<td valign="top">Y<a href="#gost-openssl"><sup>(3)</sup></a></td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">N</td>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a>
<td valign="top">Y<a href="#gost-mscrypto"><sup>(2)</sup></a></td>
<td valign="top">N</td>
</tr>
</tbody></table>
<br><br><a name="dsa-sha1"></a><sup>(1)</sup> Defining <a href="http://www.w3.org/TR/xmldsig-core/#sec-DSAKeyValue"> DSA key</a>
with Seed and PgenCounter is not supported.
<br><a name="gost-mscrypto"></a><sup>(2)</sup> Requires install of a CSP
providing these algorithms.<br><p>Test vectors (from <a href="http://www.w3.org/Signature/2001/04/05-xmldsig-interop.html">IETF/W3C
providing these algorithms.
<br><a name="gost-openssl"></a><sup>(3)</sup> Requires install of a GOST-capable OpenSSL
engine and the corresponding build options to be enabled
(<code>--enable-gost</code> for GOST94/2001 and <code>--enable-gost2012</code> for GOST-2012).<br><p>Test vectors (from <a href="http://www.w3.org/Signature/2001/04/05-xmldsig-interop.html">IETF/W3C
XML Signature WG: XML Signature Interoperability page</a>): <br><a href="http://lists.w3.org/Archives/Public/w3c-ietf-xmldsig/2002AprJun/att-0016/01-merlin-xmldsig-twenty-three.tar.gz">merlin-xmldsig-twenty-three.tar.gz</a>
<br><a href="http://lists.w3.org/Archives/Public/w3c-ietf-xmldsig/2001AprJun/att-00%2033/01-merlin-xmldsig-sixteen.tar.gz">merlin-xmldsig-sixteen.tar.gz</a>
(features, deprecated)<br><a href="http://lists.w3.org/Archives/Public/w3c-ietf-xmldsig/2001JanMar/att-0155/04-merlin-xmldsig-fifteen.tar.gz">merlin-xmldsig-fifteen.tar.gz</a>
Expand Down
2 changes: 1 addition & 1 deletion docs/xmlenc.html
Original file line number Diff line number Diff line change
Expand Up @@ -427,7 +427,7 @@ <h4 style="text-align: center;">XML Encryption 1.0 (<a href="http://www.w3.org/T
<td valign="top">Y</td>
</tr>
<tr>
<td style="width: 40%;" align="left" valign="top"><a href="http://www.w3.org/TR/xml-exc-c14n">Exlusive Canonical XML 1.0</a></td>
<td style="width: 40%;" align="left" valign="top"><a href="http://www.w3.org/TR/xml-exc-c14n">Exclusive Canonical XML 1.0</a></td>
<td valign="top">Y</td>
<td valign="top">Y</td>
<td valign="top">Y</td>
Expand Down
26 changes: 24 additions & 2 deletions docs/xmlsec-man.html
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,14 @@ <h1>XMLSEC1</h1>
<dd> display help information for command &lt;cmd&gt; and exit </dd>
<dt><b>--version</b></dt>
<dd> print version information and exit </dd>
<dt><b>--list-key-data</b></dt>
<dd> prints the list of known key data klasses </dd>
<dt><b>--check-key-data</b> &lt;key-data-name&gt; [&lt;key-data-name&gt; ...]</dt>
<dd> checks the given key-data against the list of known key-data klasses </dd>
<dt><b>--list-transforms</b></dt>
<dd> prints the list of known transform klasses </dd>
<dt><b>--check-transforms</b> &lt;transform-name&gt; [&lt;transform-name&gt; ...]</dt>
<dd> checks the given transforms against the list of known transform klasses </dd>
<dt><b>--keys</b></dt>
<dd> keys XML file manipulation </dd>
<dt><b>--sign</b></dt>
Expand All @@ -70,6 +78,8 @@ <h1>XMLSEC1</h1>
<dd> encrypt data and output XML document </dd>
<dt><b>--decrypt</b></dt>
<dd> decrypt data from XML document </dd>
<dt><b>--encrypt-tmpl</b></dt>
<dd> creates a simple dynamic template and calculates XML Encryption (for testing only) </dd>
</dl>
<a name="lbAE"> </a><h2>OPTIONS</h2>
<dl compact> <dt> <b>--ignore-manifests</b> <dt></dt>
Expand Down Expand Up @@ -140,6 +150,10 @@ <h1>XMLSEC1</h1>
</dt>
<dd> <dd>adds attributes &lt;attr-name&gt; (default value "id") from all nodes with&lt;node-name&gt; and namespace &lt;node-namespace-uri&gt; to the list of known ID attributes; this is a hack and if you can use DTD or schema to declare ID attributes instead (see "--dtd-file" option), I don't know what else might be broken in your application when you use this hack </dd>
</dd>
<dt> <b>--max-encrypted-key-level</b> &lt;level&gt; <dt></dt>
</dt>
<dd> <dd>sets the max depth level when processing encrypted keys, key agreements, etc. to &lt;level&gt;; default is 1 </dd>
</dd>
<dt> <b>--enabled-key-data</b> &lt;list&gt; <dt></dt>
</dt>
<dd> <dd>comma separated list of enabled key data (list of registered key data klasses is available with "--list-key-data" command); by default, all registered key data are enabled </dd>
Expand All @@ -166,11 +180,11 @@ <h1>XMLSEC1</h1>
</dd>
<dt> <b>--pkcs8-pem[</b>:&lt;name&gt;] &lt;file&gt;[,&lt;cafile&gt;[,&lt;cafile&gt;[...]]] <dt></dt>
</dt>
<dd> <dd>load private key from PKCS8 PEM file and PEM certificates that verify this key </dd>
<dd> <dd>load private key from PKCS8 PEM file and PEM certificates that verify this key (alias: --privkey-p8-pem) </dd>
</dd>
<dt> <b>--pkcs8-der[</b>:&lt;name&gt;] &lt;file&gt;[,&lt;cafile&gt;[,&lt;cafile&gt;[...]]] <dt></dt>
</dt>
<dd> <dd>load private key from PKCS8 DER file and DER certificates that verify this key </dd>
<dd> <dd>load private key from PKCS8 DER file and DER certificates that verify this key (alias: --privkey-p8-der) </dd>
</dd>
<dt> <b>--pubkey-pem[</b>:&lt;name&gt;] &lt;file&gt; <dt></dt>
</dt>
Expand Down Expand Up @@ -232,6 +246,10 @@ <h1>XMLSEC1</h1>
</dt>
<dd> <dd>the local time in "YYYY-MM-DD HH:MM:SS" format used certificates verification </dd>
</dd>
<dt> <b>--verification-gmt-time</b> &lt;time&gt; <dt></dt>
</dt>
<dd> <dd>the GMT time in "YYYY-MM-DD HH:MM:SS" format used certificates verification </dd>
</dd>
<dt> <b>--depth</b> &lt;number&gt; <dt></dt>
</dt>
<dd> <dd>maximum certificates chain depth </dd>
Expand All @@ -244,6 +262,10 @@ <h1>XMLSEC1</h1>
</dt>
<dd> <dd>do not verify certificates </dd>
</dd>
<dt> <b>--privkey-openssl-engine[</b>:&lt;name&gt;] &lt;openssl-engine&gt;;&lt;openssl-key-id&gt;[,&lt;crtfile&gt;[,&lt;crtfile&gt;[...]]] <dt></dt>
</dt>
<dd> <dd>load private key by OpenSSL ENGINE interface; specify the name of engine (like with "-engine" params), the key specs (like with "-inkey" or "-key" params) and optionally certificates that verify this key </dd>
</dd>
<dt> <b>--crypto</b> &lt;name&gt; <dt></dt>
</dt>
<dd> <dd>the name of the crypto engine to use from the following list: openssl, mscrypto, nss, gnutls, gcrypt (if no crypto engine is specified then the default one is used) </dd>
Expand Down
2 changes: 1 addition & 1 deletion include/xmlsec/app.h
Original file line number Diff line number Diff line change
Expand Up @@ -415,7 +415,7 @@ XMLSEC_EXPORT xmlSecTransformId xmlSecTransformRsaPkcs1GetKlass
/**
* xmlSecTransformRsaOaepId:
*
* The RSA PKCS1 key transport transform klass.
* The RSA-OAEP key transport transform klass.
*/
#define xmlSecTransformRsaOaepId xmlSecTransformRsaOaepGetKlass()
XMLSEC_EXPORT xmlSecTransformId xmlSecTransformRsaOaepGetKlass (void);
Expand Down
9 changes: 8 additions & 1 deletion include/xmlsec/errors.h
Original file line number Diff line number Diff line change
Expand Up @@ -380,7 +380,14 @@ extern "C" {
*
* Impossible to cast from one type to another.
*/
#define XMLSEC_ERROR_R_CAST_IMPOSSIBLE 101
#define XMLSEC_ERRORS_R_CAST_IMPOSSIBLE 101

/**
* XMLSEC_ERROR_R_CAST_IMPOSSIBLE:
*
* DEPRECATED. Use #XMLSEC_ERRORS_R_CAST_IMPOSSIBLE instead.
*/
#define XMLSEC_ERROR_R_CAST_IMPOSSIBLE XMLSEC_ERRORS_R_CAST_IMPOSSIBLE

/**
* XMLSEC_ERRORS_MAX_NUMBER:
Expand Down
4 changes: 2 additions & 2 deletions include/xmlsec/keys.h
Original file line number Diff line number Diff line change
Expand Up @@ -237,8 +237,8 @@ XMLSEC_EXPORT xmlSecKeyPtr xmlSecKeyReadMemory (xmlSecKeyDataId dataId,
* xmlSecKeyIsValid:
* @key: the pointer to key.
*
* Macro. Returns 1 if @key is not NULL and @key->id is not NULL
* or 0 otherwise.
* Macro. Returns 1 if @key is not NULL, @key->value is not NULL
* and @key->value->id is not NULL or 0 otherwise.
*/
#define xmlSecKeyIsValid(key) \
((( key ) != NULL) && \
Expand Down
10 changes: 4 additions & 6 deletions include/xmlsec/keysmngr.h
Original file line number Diff line number Diff line change
Expand Up @@ -242,13 +242,11 @@ struct _xmlSecKeyStoreKlass {


/**
* xmlSecKeyDataDsaWrite:
* @id: the key data data.
* @data: the pointer to input @xmlSecKeyData.
* @dsaValue: the pointer to input @xmlSecKeyValueDsa.
* @writePrivateKey: the flag indicating if private key component should be output or not.
* xmlSecSimpleKeysStoreAdoptKeyFunc:
* @store: the pointer to key store.
* @key: the pointer to key.
*
* Writes @xmlSecKeyData to @xmlSecKeyValueDsa.
* Adds @key to the @store. On success, the @store owns the @key.
*
* Returns: 0 on success or a negative value if an error occurs.
*/
Expand Down
4 changes: 2 additions & 2 deletions include/xmlsec/openssl/crypto.h
Original file line number Diff line number Diff line change
Expand Up @@ -471,7 +471,7 @@ XMLSEC_CRYPTO_EXPORT xmlSecTransformId xmlSecOpenSSLTransformGostR3411_94GetKlas
*******************************************************************/

/**
* xmlSecOpenSSLKeyDataGostR4310_2012_256Id:
* xmlSecOpenSSLKeyDataGostR3410_2012_256Id:
*
* The GOST R 34.10-2012 256 key klass.
*/
Expand All @@ -481,7 +481,7 @@ XMLSEC_CRYPTO_EXPORT xmlSecKeyDataId xmlSecOpenSSLKeyDataGostR3410_2012_256Ge


/**
* xmlSecOpenSSLKeyDataGostR4310_2012_512Id:
* xmlSecOpenSSLKeyDataGostR3410_2012_512Id:
*
* The GOST R 34.10-2012 512 key klass.
*/
Expand Down
5 changes: 5 additions & 0 deletions man/xmlsec1.1
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,11 @@ to declare ID attributes instead (see "\-\-dtd\-file" option),
I don't know what else might be broken in your application when
you use this hack
.HP
\fB\-\-max\-encrypted\-key\-level\fR <level>
.IP
sets the max depth level when processing encrypted keys, key agreements, etc.
to <level>; default is 1
.HP
\fB\-\-enabled\-key\-data\fR <list>
.IP
comma separated list of enabled key data (list of
Expand Down
Loading
Loading