Re: Last Call: MIME-based Secure EDI to Proposed Standard

Dave Crocker <[email protected]>
Newsgroups gmane.ietf.ediint
Message-ID <[email protected]>
At 07:32 AM 11/24/2001 -0800, Ricardo Johnson wrote:
>If we wish to reduce the cost of VANs and expand the use of EDI then we 
>must substitute, not eliminate, the important functions that VANs provide: 
>confidentiality, integrity, non-repudiation of origin and receipt, 
>archival, time stamping, tracking, and others.

Users of EDI are not a monolithic set.  Some require the third-party 
services of a VAN.  Others do not.  Some require very high degrees of 
accountability, sufficient for dispute resolution in a court of 
law.  Others do not.


>My observations may be too late to change anything. However, I agree with 
>you: At least the title of the document should be adjusted to 
>"peer-to-peer EDI" in order to reflect the limitations of the current AS1 
>proposal.

In fact the EDI-INT specification does not force communications to be 
peer-to-peer.  It may be, but it may not be.

In a strict sense, the fact that it will tend to be email-based guarantees 
that it is not strictly peer-to-peer, since virtually all email is mediated 
by email relays.  It would not be difficult for one or more of those relays 
to also serve as an EDI VAN.

Your concern is that last-hop routing cannot be based on the EDI contents, 
unless the contents are first decrypted.  Your technical assessment is 
correct, but does not represent a problem with the current specification.

The issue of last-hop routing was discussed at the earliest IETF EDI 
meetings -- the EDI working group that preceded the current one -- and 
there was clear consensus to leave that issue outside of the scope the IETF 
effort.  Routing based on email address is sufficient.

If the sender wishes differential routing, they merely need to send to 
different email addresses.  If the receiving wishes differential routing, 
they must first decrypt the contents.  That decryption takes place within 
the security perimeter of the receiving organization.  Hence this 
requirement is entirely reasonable.

d/


----------
Dave Crocker  <mailto:[email protected]>
Brandenburg InternetWorking  <http://www.brandenburg.com>
tel +1.408.246.8253;  fax +1.408.273.6464
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.