Re: Last Call: MIME-based Secure EDI to Proposed Standard

Ricardo Johnson <[email protected]>
Newsgroups gmane.ietf.ediint
Message-ID <[email protected]>
At 09:51 a.m. 19/11/01 -0500, The IESG wrote:
>To propose email based security protocols such as S/MIME as a "the 
>standard" to be used for transmiting EDI messages over the internet is 
>fundamentally wrong !. Before you advance any further with such a limited 
>idea your group must evaluate other alternatives and give serious 
>consideration to the work that has been done by the EDI standards bodies 
>(ANSI X.12 and EDIFACT) on the matter of security.

1. S/MIME is not even a standard for email yet, how can it be adopted as a 
standard for EDI
2. Email protocols such as S/MIME protect entire envelopes not EDI messages 
or parts thereof. That means that security is dependent on the messaging 
protocol. Thus messages can not be exchanged among different messaging 
protocols such as X.400, EDI, and others.
3. EDI messages must be secured at the transaction level not the envelope 
level, so that ISA headers can be read and messages be routed without 
having to decrypt the message.
4. A message should be able to travel from sender A to receiver B encrypted 
and digitally signed regardless of the mailbox type, messaging protocol, or 
communications protocol (email, x.400, VAN, etc).
5. Security rules for EDI transactions (X 12.58 and EDIFACT) are well 
defined and adopted standards. The EDI security rules been implemented and 
proven worldwide (i.e. banks). They are concenced and efficient to handle 
EDI messages. EDI security standards have obvious benefits over S/MIME. Why 
then re-invent the wheel ? Let EDI messages be handled by EDI security 
standards and assure inter-operability (VAN-internet), simplicity 
(authentication, non repudiation, key management, etc), and evolution (VAN 
to ISP ?).
6. S/MIME is not a good email security protocol. It was simply not 
conceived to handle EDI transactions and therefore is not well suited for that.

Before you conclude that S/MIME or any other protocol should be used as a 
standard for sending EDI messages over the internet (EDIINT), you should 
seriously evaluate X 12.58 and EDIFACT security rules as viable and 
superior alternatives. The long term consequences of disregarding the 
accomplishments and knowledge that the EDI standards bodies and users have 
achieved in the security areas over the last 20 years would be a big mistake !

Give us the benefit of the doubt, allow us to demonstrate the advantages of 
EDI security protocols with practical and theoretical examples.
Respectfully
Dr. Ricardo S. Johnson



>The IESG has received a request from the Electronic Data
>Interchange-Internet Integration Working Group to consider MIME-based
>Secure EDI <draft-ietf-ediint-as1-14.txt> as a Proposed Standard.
>
>In the same action, the IESG will also consider publication of
>  Requirements for Inter-operable Internet EDI
><draft-ietf-ediint-req-09.txt> as an Informational RFC.
>
>The IESG plans to make a decision in the next few weeks, and solicits
>final comments on this action.  Please send any comments to the
>[email protected] or [email protected] mailing lists by December 3, 2001.
>
>Files can be obtained via
>http://www.ietf.org/internet-drafts/draft-ietf-ediint-as1-14.txt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.