<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:Courier;
        panose-1:2 7 4 9 2 2 5 2 4 4;}
@font-face
        {font-family:Courier;
        panose-1:2 7 4 9 2 2 5 2 4 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page Section1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=FR link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal>Hi everybody<o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><span lang=EN-US>I am actually developing a software based
on the German EBICS norm, which specifies that one’s got to use <o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><ds:Reference URI="#xpointer(//*[@authenticate='true'])"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>as signature’s URI. <o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>So long so well, when I sign a xml file with
xmlsec<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>(using command line : “xmlsec sign
--node-xpath //*[@authenticate='true'] --output $outputName --keys-file
$keyfile”)<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>and then I verify it with xmlsec, <o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>(using command line : “"xmlsec
verify --node-xpath //*[@authenticate='true'] --keys-file $keyfile $inputName”)<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>everything works perfect.<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>But here comes the trouble : I’m
actually working on the server side of the EBICS norm, and I’m testing my
developments on the client side thanks to a software called Travic (which is
commercialized in Germany and then, I can assume, works well).<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>And when Travic sends me its signature…
Verification fails… I keep getting this message :<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>“error=18:data do not match:signature
do not match FAIL SignedInfo References (ok/all): 1/1 Manifests References
(ok/all): 0/0 Error: failed to verify file”.<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>It seems like the hash is ok (?), but not
the signature.<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>(Moreover, there’s no problem with the
client public key, has I can decipher text asymmetrical encrypted by this same key.)<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>I read here <a
href="http://www.w3.org/2007/xmlsec/ws/papers/10-ertel/">http://www.w3.org/2007/xmlsec/ws/papers/10-ertel/</a>
that the handling of this type of ("#xpointer) URI can be subject to two
different handling, due to two interpretations (both right !) of the same norm,
i.e :<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal style='text-autospace:none'><span lang=EN-US
style='font-family:"Arial","sans-serif"'>One interpretation says that the
signed URI must remain unchanged:<o:p></o:p></span></p>
<p class=MsoNormal style='text-autospace:none'><span lang=EN-US
style='font-size:10.0pt;font-family:Courier'>"#xpointer(//*[@authenticate='true'])",<o:p></o:p></span></p>
<p class=MsoNormal style='text-autospace:none'><span lang=EN-US
style='font-family:"Arial","sans-serif"'>while the other one demands escaping
which makes the URI look like this:<o:p></o:p></span></p>
<p class=MsoNormal style='text-autospace:none'><span lang=EN-US
style='font-size:10.0pt;font-family:Courier'>"#xpointer(%2F%2F*%5B%40authenticate%3D%27true%27%5D)"</span><span
lang=EN-US style='font-size:10.0pt;font-family:"Arial","sans-serif"'><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>So the main question is : could it be this
type of problem in my case, or is the problem that I’m facing due to another
totally different cause? <o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>Thanks for your kind help!<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal>Sébastien Brossard<o:p></o:p></p>
<p class=MsoNormal>sebastien.brossard@turbosa.banquepopulaire.fr<o:p></o:p></p>
<p class=MsoNormal><o:p> </o:p></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>PS : <o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>By the way, here’s the xml string
that I try to verify :<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US><?xml version="1.0"
encoding="UTF-8"?><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><ebicsNoPubKeyDigestsRequest
Revision="1" Version="H001"
xsi:schemaLocation="http://www.ebics.org/H001
http://www.ebics.org/H001/ebics_keymgmt_request.xsd"
xmlns="http://www.ebics.org/H001" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <header
authenticate="true"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <static><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <HostID>EBICSFR</HostID><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<Nonce>DB545BDC437B95999202C6EA69393A6E</Nonce><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <Timestamp>2008-04-22T09:29:24.838Z</Timestamp><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<PartnerID>SEB</PartnerID><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <UserID>USERID</UserID><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <OrderDetails><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<OrderType>HPB</OrderType><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<OrderAttribute>DZHNN</OrderAttribute><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </OrderDetails><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<SecurityMedium>0400</SecurityMedium><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </static><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <mutable/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </header><o:p></o:p></span></p>
<p class=MsoNormal> <Signature
xmlns="http://www.w3.org/2000/09/xmldsig#"><o:p></o:p></p>
<p class=MsoNormal> <span lang=EN-US><ds:SignedInfo><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:CanonicalizationMethod
Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:SignatureMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:Reference
URI="#xpointer(//*[@authenticate='true'])"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:Transforms><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:Transform
Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </ds:Transforms><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <ds:DigestMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US>
<ds:DigestValue>jyF+PD4mQ6P5q4krG/spn0tNc7w=</ds:DigestValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </ds:Reference><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </ds:SignedInfo>
<ds:SignatureValue>EhinV8z06LDoNdeeYebT/Z9UGF0EZViPHexD6H2e5EgPWD8OBV1hYnro2KJ48N9WMyIf4UkZzKLWSIV4IfIcjtDYzUsLZFke6kL3BKGeFe2jAuAlGyHVD/MUxEU3Fsg6QkqknkQrybjiX1FA9SFdBzyjN8d/9qksRQZXmjkuBNM=</ds:SignatureValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> </</span>Signature<span lang=EN-US>><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US> <body/><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US></ebicsNoPubKeyDigestsRequest><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US>And here’s the public key of the client
software :<o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US><?xml version="1.0"
encoding="UTF-8"?><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><Keys
xmlns="http://www.aleksey.com/xmlsec/2002"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><KeyInfo
xmlns="http://www.w3.org/2000/09/xmldsig#"><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><KeyValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><RSAKeyValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><Modulus>AMWVUq4RSou1Dy4VaNIEkIBLddfysftYsXI5Hg+bncOYuDQFlU31B2kqSyzYhXXelhvhkSXTgNuBGwnf1VFw+VbVR/kVjDhvt2vgPjfKpbXJEEmy8QxJpSpsUFW9DbVbWocnzkxEZJzM7VKKyBdKXiMWT3wdhRIrqxaLc/NX+S+H</Modulus><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><Exponent>AQAB</Exponent><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US></RSAKeyValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US></KeyValue><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US></KeyInfo><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US></Keys><o:p></o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>
</div>
</body>
</html>