[xmlsec] Problem with excluding signature

Jon Lind jlind at ign.com
Wed Aug 2 09:53:57 PDT 2006

Hello.  I have found discussion of excluding the signature with the
command line utility using --node-xpath, but I can't find an example.
When I use this I get "failed to find default node with
name='Signature'".  Am I misusing the --node-xpath param?


xmlsec sign --pkcs12 private.pfx --store-signatures --print-debug 

--node-xpath /Response/Assertion/Subject 

--output xmlsec_signed.xml template_dsig.xml


Here is a snippet of my template.  What I'm trying to do is create a
digest for the Subject only.




    <Subject id="Subject">


      <SubjectConfirmation Method="urn:oasis:names:tc:2.0:cm:bearer">

        <SubjectConfirmationData Address=""
NotOnOrAfter="2005-11-04T03:55:49.633Z" />




  <dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">


Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315" />

Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />

      <dsig:Reference URI="#Subject">


Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />


Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />









-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.aleksey.com/pipermail/xmlsec/attachments/20060802/2787ef57/attachment-0002.htm

More information about the xmlsec mailing list