Re: Last Call: MIME-based Secure EDI to Proposed Standard
Dave Crocker <[email protected]>
| Newsgroups | gmane.ietf.ediint |
|---|---|
| Message-ID | <[email protected]> |
At 07:32 AM 11/24/2001 -0800, Ricardo Johnson wrote: >If we wish to reduce the cost of VANs and expand the use of EDI then we >must substitute, not eliminate, the important functions that VANs provide: >confidentiality, integrity, non-repudiation of origin and receipt, >archival, time stamping, tracking, and others. Users of EDI are not a monolithic set. Some require the third-party services of a VAN. Others do not. Some require very high degrees of accountability, sufficient for dispute resolution in a court of law. Others do not. >My observations may be too late to change anything. However, I agree with >you: At least the title of the document should be adjusted to >"peer-to-peer EDI" in order to reflect the limitations of the current AS1 >proposal. In fact the EDI-INT specification does not force communications to be peer-to-peer. It may be, but it may not be. In a strict sense, the fact that it will tend to be email-based guarantees that it is not strictly peer-to-peer, since virtually all email is mediated by email relays. It would not be difficult for one or more of those relays to also serve as an EDI VAN. Your concern is that last-hop routing cannot be based on the EDI contents, unless the contents are first decrypted. Your technical assessment is correct, but does not represent a problem with the current specification. The issue of last-hop routing was discussed at the earliest IETF EDI meetings -- the EDI working group that preceded the current one -- and there was clear consensus to leave that issue outside of the scope the IETF effort. Routing based on email address is sufficient. If the sender wishes differential routing, they merely need to send to different email addresses. If the receiving wishes differential routing, they must first decrypt the contents. That decryption takes place within the security perimeter of the receiving organization. Hence this requirement is entirely reasonable. d/ ---------- Dave Crocker <mailto:[email protected]> Brandenburg InternetWorking <http://www.brandenburg.com> tel +1.408.246.8253; fax +1.408.273.6464