|
Developer
Downloads
Tutorial
Licensing
Mac
OS X
Success Stories
|

|
XML Digital Signature
articles,
The solution to these
problems is the use of one or more trusted third parties to associate an
identified signer with a
specific public key.
|
That trusted third party is referred to as a XML Digital Signature
articles and "certification authority"
in most technical standards and in these Guidelines. To associate a key
pair with a prospective signer, a certification authority issues a
certificate, an electronic record which lists or XML Digital
Signature articles a public key as the
"subject" of the certificate, and confirms that the prospective signer
identified in the certificate holds the corresponding private key. The
prospective signer is termed the "subscriber. A certificate's principal
function is to bind a key pair with a particular subscriber. A
"recipient" of the certificate desiring to rely upon a digital signature
created by the subscriber named in the certificate (whereupon the
recipient becomes a "relying party") can use the public key listed in
the certificate to verify that the digital signature was created with
the corresponding private key - XML Digital Signature articles. If such verification is successful, this
chain of reasoning provides assurance that the corresponding private key
is held by the subscriber named in the certificate, and that the digital
signature and XML Digital Signature articles was created by that particular subscriber.
The issuing XML Digital Signature
articles on the certificate can be verified by using the public key
of the certification authority listed in another certificate by another
certificate authority (which may but need not be on a higher level in a
hierarchy), and that other certificate can in turn be authenticated by
the public key listed in yet another certificate, and so on, until the
person relying on the digital signature is adequately assured of its
genuineness. In each case, the issuing certification authority must
digitally sign
its own certificate during the operational period of the other
certificate used to verify the XML Digital Signature articles.
|
|