[Oisf-wg-ruleslanguage] On encrypting rule files (xml example)

Scott MacGregor shadowbq at gmail.com
Mon Sep 21 00:02:15 UTC 2009

My personal opinion :=> "lets please not do this.." (sniffle)

FYI: There are some decent articles on encrypting xml data..




If the organization as whole wants to encrypt some of the rules so
that we can get "pre-release patches" this would be my route:

Create an CA and X.509 certificate chain for the root signing of
Asymmetric encryption of the rules.

Have anyone/company who wants to have access to utilize encrypted
rules register for a certificate with the OSIF organization
Certificate Authority.

Anyone without a certificate can utilize the /rule file/ without
error, but the system just skips the encrypted rules.

Allow multiple X.509 chains for rule decryption, such that an
organization can create its own encryption cert and have "propriety
rules" mixed with "org subscription rules" and "org community rules".

This is never going to be trivial....

Having something like this.. rough sketch of an xml encrypted rule file...

The below uses RSA to decode off a keychain named OSIF

Reference: http://www.w3.org/TR/xmlenc-core/

<?xml version="1.0" standalone="no"?>
    <title>OSIF Pre-Release $soft GDI overflow </title>
      <title>$soft GDI overflow </title>
      <para>This space can have a more detailed description.</para>
      <para>This space can have additional description.</para>
      <author>OSIF blah....</author>
	  <status>Limited Public Release</status>
    <EncryptedData Type="http://www.w3.org/2001/04/xmlenc#Element"
	  <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" />
	  <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">

~~~~ shadowbq

More information about the Oisf-wg-ruleslanguage mailing list