XML signature examples
Sample XML structures showing enveloping, enveloped, cXML, and other signature formats produced by TrustWeaver.
Enveloping signature
An enveloping signature is a signature where the signed document (or, in some cases, the signed fields) will be part of the signature element. The following example shows an enveloping XAdES-T signature.
<Signature Id="signature" xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"
/>
<SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" />
<Reference URI="#signatureProperties"
Type="http://www.w3.org/2000/02/xmldsig#SignatureProperties">
<DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<DigestValue>KcdpJu81a6KFJD2ZZnD36Mh6Uaw=</DigestValue>
</Reference>
<Reference URI="#SignedContent" Type="http://www.w3.org/2000/09/xmldsig#Object">
<DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
<DigestValue>g+TT+TvbROIHNi5Tt6eXePIs0g4=</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>...</SignatureValue>
<KeyInfo>
<X509Data xmlns="http://www.w3.org/2000/09/xmldsig#">
<X509Certificate>...</X509Certificate>
</X509Data>
</KeyInfo>
<Object>
<xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#
Target="#cXMLSignature">
<xades:SignedProperties Id="XAdESSignedProps">
<xades:SignedSignatureProperties>
<xades:SigningTime>...</xades:SigningTime>
<xades:SigningCertificate>...</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>...</xades:SignaturePolicyIdentifier>
</xades:SignedSignatureProperties>
</xades:SignedProperties>
<xades:UnsignedProperties>
<xades:UnsignedSignatureProperties>
<xades:SignatureTimeStamp>...</xades:SignatureTimeStamp>
</xades:UnsignedSignatureProperties>
</xades:UnsignedProperties>
</xades:QualifyingProperties>
</ds:Object>
<Object Id="SignedContent">
<Doc>...<Doc>
</Object>
</Signature>
Enveloped cXML signature for single signer
-
All cXML signatures are enveloped and there can be one or two signatures embedded in cXML.
-
The signatureVersion "1.0" attribute is added to the cXML element.
-
The
Request,Response, orMessageelement is signed in its entirety, identified by theId="cXMLData"attribute. -
The
Idattribute of theds:Signatureelement is set to"cXMLSignature"and the Target attribute ofxades:QualifyingPropertiesis"#cXMLSignature". -
A
ds:Objectis added which contains acXMLSignedInfoelement with the Id attribute set to"cXMLSignedInfo"and the values ofsignatureVersionandpayloadIDare copied from the same attributes in the cXML element. -
The following example shows a cXML document with one XAdES-A signature; both XAdES-T and XAdES-A signatures are supported.
-
If XAdES-A is used a ds:Object is added which contains an Extrinsic element with the name attribute set to "ValidationPolicyId". The value for this Extrinsic element is the object identifier for the validation policy. This ds:Object will always be placed after the cXMLSignedInfo ds:Object element.
-
If XAdES-A is used a ds:Object is added which contains a Extrinsic element with the name attribute set to "ValidationPolicyQualifier". The value for this Extrinsic element is the URL to the validation policy. This ds:Object will always be placed after the Extrinsic ds:Object element. See more about ValidationPolicy objects (XAdES-A)
-
Three ds:Reference elements with Algorithm "http://www.w3.org/2000/09/xmldsig#sha1" are added in the following order:
-
URI="#cXMLSignedInfo" ("#cXMLSignedInfo2" if in second signature)
-
URI="#cXMLData"
-
URI="#XAdESSignedProps" ("#XAdESSignedProps2" if in second signature)
-
-
The ds:KeyInfo of the ds:Signature element contains the signature certificate as a ds:X509Certificate element in the Base 64 DER encoded format.
-
One or two ds:Signature elements are added after the cxml:Request, cxml:Response or cxml:Message element in the cXML document.
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE cXML SYSTEM "InvoiceDetail.dtd">
<cXML payloadID="..." signatureVersion="1.0" timestamp="..." version="1.2.011">
<Header>...</Header>
<Request Id="cXMLData">...</Request>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315">
</ds:CanonicalizationMethod>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1">
</ds:SignatureMethod>
<ds:Reference URI="#cXMLSignedInfo"></ds:Reference>
<ds:Reference URI="#cXMLData"></ds:Reference>
<ds:Reference URI="#XAdESSignedProps"></ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>...</ds:SignatureValue>
<ds:KeyInfo></ds:KeyInfo>
<ds:Object>
<cXMLSignedInfo Id="cXMLSignedInfo" payloadID="..." signatureVersion="1.0" xmlns=""
/>
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyId">...</Extrinsic>
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyQualifier">...</Extrinsic>
</ds:Object>
<ds:Object>
<xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#
Target="#cXMLSignature">
<xades:SignedProperties Id="XAdESSignedProps">
<xades:SignedSignatureProperties>
<xades:SigningTime>...</xades:SigningTime>
<xades:SigningCertificate>...</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>...</xades:SignaturePolicyIdentifier>
</xades:SignedSignatureProperties>
</xades:SignedProperties>
<xades:UnsignedProperties>
<xades:UnsignedSignatureProperties>
<xades:SignatureTimeStamp>...</xades:SignatureTimeStamp>
<xades:CertificateValues...></xades:CertificateValues>
<xades:RevocationValues>...</xades:RevocationValues>
<xades:ArchiveTimeStamp>...</xades:ArchiveTimeStamp>
</xades:UnsignedSignatureProperties>
</xades:UnsignedProperties>
</xades:QualifyingProperties>
</ds:Object>
</ds:Signature>
</cXML>
Enveloped cXML signature for two signers
When two signatures are present in the same cXML document, the second ds:Signature element uses Id="cXMLSignature2" and corresponding references use the 2 suffix.
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE cXML SYSTEM "InvoiceDetail.dtd">
<cXML payloadID="..." signatureVersion="1.0" timestamp="..." version="1.2.011">
<Header>...</Header>
<Request Id="cXMLData">...</Request>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315">
</ds:CanonicalizationMethod>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1">
</ds:SignatureMethod>
<ds:Reference URI="#cXMLSignedInfo"></ds:Reference>
<ds:Reference URI="#cXMLData"></ds:Reference>
<ds:Reference URI="#XAdESSignedProps"></ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>...</ds:SignatureValue>
<ds:KeyInfo></ds:KeyInfo>
<ds:Object>
<cXMLSignedInfo Id="cXMLSignedInfo" payloadID="..." signatureVersion="1.0" xmlns=""
/>
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyId">...</Extrinsic>
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyQualifier">...</Extrinsic>
</ds:Object>
<ds:Object>
<xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#
Target="#cXMLSignature">
<xades:SignedProperties Id="XAdESSignedProps">...</xades:SignedProperties>
<xades:UnsignedProperties>...</xades:UnsignedProperties>
</xades:QualifyingProperties>
</ds:Object>
</ds:Signature>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#" Id="cXMLSignature2">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n
20010315">
</ds:CanonicalizationMethod>
<ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1">
</ds:SignatureMethod>
<ds:Reference URI="#cXMLSignedInfo2"></ds:Reference>
<ds:Reference URI="#cXMLData"></ds:Reference>
<ds:Reference URI="#XAdESSignedProps2"></ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>...</ds:SignatureValue>
<ds:KeyInfo></ds:KeyInfo>
<ds:Object>
<cXMLSignedInfo Id="cXMLSignedInfo2" payloadID="..." signatureVersion="1.0"
xmlns="" />
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyId">...</Extrinsic>
</ds:Object>
<ds:Object>
<Extrinsic name="ValidationPolicyQualifier">...</Extrinsic>
</ds:Object>
<ds:Object>
<xades:QualifyingProperties xmlns:xades=http://uri.etsi.org/01903/v1.3.2#
Target="#cXMLSignature2">
<xades:SignedProperties Id="XAdESSignedProps2">...</xades:SignedProperties>
<xades:UnsignedProperties>...</xades:UnsignedProperties>
</xades:QualifyingProperties>
</ds:Object>
</ds:Signature>
</cXML>
ValidationPolicy objects (XAdES-A)
ds:Object elements carry the validation policy identifier and its URL qualifier.
-
ValidationPolicyId: The validation policy object identifier as ads:Object element. -
ValidationPolicyQualifier: The validation policy URL as ads:Object element.
<!-- Validation policy OID -->
<ds:Object>
<Extrinsic name="ValidationPolicyId">
<xades:Identifier Qualifier="OIDAsURN">urn:oid:1.2.7.76</xades:Identifier>
</Extrinsic>
</ds:Object>
<!-- Validation policy URL -->
<ds:Object>
<Extrinsic name="ValidationPolicyQualifier">
<xades:SPURI>
http://ts.company.com/ts/rh.ashx?oid=1.2.7.76&doc=validate
</xades:SPURI>
</Extrinsic>
</ds:Object>
