-
Type: Bug
-
Status: Closed
-
Priority: Major
-
Resolution: No Action
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Graphics, Part 3 (Schema) [1.2: 1], Security
-
Labels:None
-
Proposal:
Because different consumers may present different alternatives in a <draw:frame>, one that is presented by a consumer need not be the one that was seen when a producer provided a digital signature on the document.
A signer may successfully claim that the document as presented by a consumer is not the one that was signed, even though the signature is verified.
The difficulty is magnified when one or more of the alternatives is by reference to external material that is not covered by the signature and is not cached so as to be included in the signature. (This is a general concern when the document contains links to external material that may be accessed automatically and presented as if it is an inherent part of the document without it being somehow reflected in the document package files that are signed.)