Re: MIME-based Secure EDI -- AS1

"Paul V Ford-Hutchinson" <[email protected]>
Newsgroups gmane.ietf.ediint
Message-ID <[email protected]>
David Fischer wrote:

>After reading the comments from the Last Call on AS1, it seems there
>are two concerns:
>1)  The name might suggest that all EDI on the Internet would be done 
>this way.
>
>2)  There is some dissent to the way in which security is applied 
>in this spec.

I also raised the issues that 

- there are too many options  (in general options are considered bad in a 
protocol)
- there are proposed modes of operation that offer no security whatsoever.

And so ..

- options should be reduced/removed
- all proposed mechanisms should offer a basic level of security 
(confidentiality, authentication and integrity)

The IETF should be asserting the security high-ground and not allow 
insecure, lowest common denominator mechanisms to be defined.  Perhaps we 
should ask for guidance from the SAAG ?

Paul

--
Paul Ford-Hutchinson :  eCommerce application security : 
[email protected]
MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 
462005
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.