DocFence 0.50.0 Blocks MD5 Digest Algorithm in OOXML Package Signature Coverage
DocFence version 0.50.0 introduces a hard rejection of the MD5 digest algorithm across all DigestMethod URIs within its bounded package-signature coverage chain, including SignedInfo references, manifest references, and relationship references. Any binding using MD5 renders declaration coverage unavailable, while SHA-1 and other algorithms remain structurally accepted for compatibility with OPC conformance language. The tool examines only stored Algorithm URIs and does not recompute digests, verify certificates, or establish cryptographic trust, leaving those responsibilities to a dedicated XMLDSIG verifier. A 69-test suite validated the changes, and a scan of public OOXML Signature Security artifacts found 243 DigestMethod declarations using SHA-256 with none using MD5. DocFence's rules DFP092 and DFP093 function strictly as declaration gates, not as a cryptographic policy engine.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in