diff options
author | Miklos Vajna <vmiklos@collabora.co.uk> | 2016-02-01 11:16:15 +0100 |
---|---|---|
committer | Miklos Vajna <vmiklos@collabora.co.uk> | 2016-02-01 11:36:56 +0100 |
commit | e6aaf64cfc378d0daa0709c40c85ee1e9c0fd151 (patch) | |
tree | 71d427bcf402d4157d72b8e526f4734afd63f00d /unusedcode.exclude | |
parent | 513d5c5781ec14f8512432f31290a3d54c8d57df (diff) |
xmlsecurity: validate OOXML <Manifest> references
ODF uses no <Manifest> references, so this doesn't change anything for
ODF.
Previously we only validated the hash of a <Manifest> element, but not
reference hashes inside the <Manifest> element. This means now we can
detect not only changes to the signature metadata (signing data, signing
comment), but also changes in other streams, i.e. everything else.
libxmlsec already validated the manifest references hashes, the only
missing piece was that it's up to the client if it wants to validate
them, so libxmlsec doesn't do so by default -> our code has to.
This commit only affects the nss backend, still need to adapt the
mscrypto backend later presumably.
Change-Id: I0b11519d3eb003783048a00c4cada74762c6462f
Diffstat (limited to 'unusedcode.exclude')
0 files changed, 0 insertions, 0 deletions