Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityGetting Repeated No Caller ID Calls? Here’s What’s Really Going On(22.09.2026 um 22:31 Uhr)
Windows Tipps & SecurityHöllenmaschine: Gaming-Peripherie für gut 1.800 Euro für die HMX 6(23.09.2026 um 10:20 Uhr)
Windows Tipps & SecurityDas nächste große Ding: KI-Agenten(23.09.2026 um 10:30 Uhr)
Sichere ProgrammierungHow AI Is Making Restaurant Menus Easier to Navigate(23.09.2026 um 10:55 Uhr)
Windows Tipps & SecurityGetting Repeated No Caller ID Calls? Here’s What’s Really Going On(22.09.2026 um 22:31 Uhr)
Windows Tipps & SecurityHöllenmaschine: Gaming-Peripherie für gut 1.800 Euro für die HMX 6(23.09.2026 um 10:20 Uhr)
Windows Tipps & SecurityDas nächste große Ding: KI-Agenten(23.09.2026 um 10:30 Uhr)
Sichere ProgrammierungHow AI Is Making Restaurant Menus Easier to Navigate(23.09.2026 um 10:55 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

A package binding needs a real Reference

A package binding needs a real Reference A local URI such as #idPackageObject names an OPC package-specific Object, but the URI alone is not an XMLDSIG Reference. The SignedInfo declaration that claims to bind the Object also has a…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




A package binding needs a real Reference



A local URI such as #idPackageObject names an OPC package-specific

Object, but the URI alone is not an XMLDSIG Reference. The SignedInfo

declaration that claims to bind the Object also has a required child order and

transform boundary.



DocFence 0.48.0

requires that stored Reference shape before it credits bounded static

package-signature coverage.






A URI is only the start



The XMLDSIG Reference schema

defines optional Transforms followed by DigestMethod and DigestValue. OPC

restricts package-signature transforms to canonicalization and its Relationships

transform; the latter has defined input only under a Manifest. A Reference to

the package Object can therefore have no transform, or a direct nonempty list

of OPC's two XML Canonicalization forms.




ds:SignedInfo
└─ ds:Reference URI="#idPackageObject"
├─ optional ds:Transforms
│ └─ ds:Transform Algorithm="OPC C14N"
├─ ds:DigestMethod Algorithm="…"
└─ ds:DigestValue (plain, nonempty)
~~~

DocFence requires the direct child order. DigestMethod needs a nonblank
Algorithm; DigestValue must be direct, attribute-free, child-free, and
nonempty. A present transform list must be direct, nonempty, and use only
normal or comment-preserving XML Canonicalization.

## Strict syntax, not XMLDSIG validation

Unknown, relationship, empty, or duplicate transform lists—and missing,
reordered, malformed, nested, extra, or text-bearing digest children—leave
static declaration coverage unavailable.

DocFence does not decode or recompute a digest, execute a transform, verify a
signature, inspect a certificate, establish trust, or predict an Office
client. It checks only the small stored shape necessary for the bounded
coverage declaration it reports.

~~~yaml
version: 1
rules:
require_complete_package_signature_coverage: true
no_package_signature_coverage_changes: true
~~~

DFP092 and DFP093 remain review gates over declared scope, not claims that a
signature is valid or trusted.

## Evidence and use

The 69-test suite accepts a binding with no transform and both permitted
canonicalization forms. It rejects unsupported, relationship, empty, and
duplicate transform lists plus missing, misordered, malformed, nested, extra,
and text-bearing digest children. DCAB's complete reference adapter passed
against a fresh DocFence wheel.

A fresh wheel and source-distribution installation retained complete bounded
coverage for a signed baseline in the public
[OOXML Signature Security artifacts](https://github.com/RUB-NDS/OOXML_Signature_Security).
The published content-injection, universal-signature-forgery,
duplicate-document, and evil-type variants still exposed uncovered or
unavailable declaration surfaces. This is a stored-structure compatibility
smoke test, never a safety or trust verdict.

Main and tagged CI passed. Source and wheel artifacts were built twice under
the commit timestamp and matched byte-for-byte; public GitHub release downloads
were byte-compared to those verified builds.

~~~bash
python -m pip install https://github.com/SybilGambleyyu/docfence/releases/download/v0.48.0/docfence-0.48.0-py3-none-any.whl

docfence check approved.docx candidate.docx --policy docfence.yml --format sarif --output docfence.sarif
~~~

Read the canonical [DocFence 0.48 release note](https://sybilgambleyyu.github.io/posts/docfence-480.html)
for the exact policy, threat-model, and validation boundaries.


Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96258 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktio…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick