RE: MIME-based Secure EDI -- AS1
"David Fischer" <[email protected]>
| Newsgroups | gmane.ietf.ediint |
|---|---|
| Message-ID | <[email protected]> |
You want to remove the option for someone to use AS1 without security? David Fischer Drummond Group. -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Paul V Ford-Hutchinson Sent: Monday, January 14, 2002 5:00 AM To: [email protected] Subject: Re: MIME-based Secure EDI -- AS1 David Fischer wrote: >After reading the comments from the Last Call on AS1, it seems there >are two concerns: >1) The name might suggest that all EDI on the Internet would be done >this way. > >2) There is some dissent to the way in which security is applied >in this spec. I also raised the issues that - there are too many options (in general options are considered bad in a protocol) - there are proposed modes of operation that offer no security whatsoever. And so .. - options should be reduced/removed - all proposed mechanisms should offer a basic level of security (confidentiality, authentication and integrity) The IETF should be asserting the security high-ground and not allow insecure, lowest common denominator mechanisms to be defined. Perhaps we should ask for guidance from the SAAG ? Paul -- Paul Ford-Hutchinson : eCommerce application security : [email protected] MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 462005 http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html