RE : AS2-SMIME : has the certificate to be included inside thesig natu re?

[email protected] Thu, 5 Jun 2003 16:57:29 +0100
Newsgroups gmane.ietf.ediint
Message-ID <014CBC6C32FDD611BB6400D0B78F6AD7089FDE@mg21w306.siege.intra.groupe-casino.fr>
The administration work could be reduced if all the certificates exchanges
were dynamic; still the partner cert is always required to encrypt
messages...

I agree with you. If you use the cert included in the message (assuming it
is valid CA certified etc.) you can make clear that someone has signed the
message and that it hasn't changed since, but how can you be sure of who is
the signer?
I mean, there must be an identity check somewhere else?
If you use the good certificate that you trust to check the signature you
can authenticate at the same time, can't you?


-----Message d'origine-----
De : Rishel,Wes [mailto:[email protected]] 
Envoyé : jeudi 5 juin 2003 15:24
À : Jess Sightler; [email protected]
Cc : [email protected]
Objet : RE: AS2-SMIME : has the certificate to be included inside thesignatu
re?

What is the benefit of sending the cert with the message? If you truly want
to authenticate the originator you have to acquire the cert by independent,
trusted means, don't you?

-----Original Message-----
From: [email protected]
[mailto:[email protected]]On Behalf Of Jess Sightler
Sent: Thursday, June 05, 2003 6:36 AM
To: [email protected]
Cc: [email protected]
Subject: Re: AS2-SMIME : has the certificate to be included inside
thesignatu re?



I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, [email protected] wrote:
> Hello,
> 
>  
> 
> I am new on this list - and I need your help.
> 
>  
> 
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
> 
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case they
> would try to find a certificate on the local key store etc.) 
> 
>  
> 
> Regards,
> 
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
> 
> 04 77 45 48 01
> 
> [email protected]
> -----------------------------------------
> 
> 
>  
> 
> 
>  
-- 
=======================================
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=======================================