I think it should be "as a SOAP Header". If the intent is to put an XML
DSIG as a Header element inside the SOAP envelope.
> Section 4.1.3 Signature Generation, line 1068 states:
>
> 1) Creat a ds:SignedInfo element with ds:SignatureMethod,
> ds:CanonicalizationMethod, and ds:Reference elements for the SOAP
> Header and any required payload objects, as prescribed by [XMLDSIG].
>
> Shouldn't the phrase "SOAP Header" be replaced with "SOAP Envelope"
> instead? Don't we want to sign the SOAP Body as well?
--
Zolera Systems, Securing web services (XML, SOAP, Signatures,
Encryption)
http://www.zolera.com