> I suppose forcing xml-security-c 2 to build with xerces-c 3.1 is a bad idea, isn't it?

I don't think there are real dependencies, I did it to make a point about the state of Xerces more than anything else, and because it simplified my job making sure my packages weren't accidentally pulling in Red Hat's broken, insecure version of 3.1.

FWIW, a 2.0.2 should be out today.

