Apps/Security/Distribution: Difference between revisions

Line 25: Line 25:
The W3C has a standard for [http://www.w3.org/TR/widgets-digsig/ XML Widget Digital Signatures] that, on close inspection, shows that it fulfils the requirements.  This diagram shows the relationships:
The W3C has a standard for [http://www.w3.org/TR/widgets-digsig/ XML Widget Digital Signatures] that, on close inspection, shows that it fulfils the requirements.  This diagram shows the relationships:


{img}
[[File:Digsigchain.png]]


* Files (media, images, HTML, JS, CSS) are in a [http://www.w3.org/TR/widgets-digsig/#widget-package widget package]
* Files (media, images, HTML, JS, CSS) are in a [http://www.w3.org/TR/widgets-digsig/#widget-package widget package]
 
* [[http://www.w3.org/TR/widgets-digsig/#author-signature Authors digitally-sign]] the package
* [[http://www.w3.org/TR/widgets-digsig/#distributor-signature Distributors digitally-sign]] the package ''and'' the author's signature.


=== Trusted store with permissions delegation ===
=== Trusted store with permissions delegation ===
177

edits