Re: ESS and Ediint RE: WG Last Call for AS2

"Sean P. Turner" <[email protected]> Wed, 21 Apr 2004 08:51:18 -0400
Newsgroups gmane.ietf.ediint
Organization IECA, Inc.
Message-ID <[email protected]>
Dale Moberg wrote:

Message

Sean P. Turner
writes:

Some
comments (many of the same comments I made on RFC 3335):

[snip]

Section 2.3.1 - Signed Receipt definition - Same comment as a
I had on RFC 3335 - CMS has a "signed receipt" service too. I think to
avoid confusion you should add "The signed Receipt service defined
herein is NOT the same as the S/MIME Extended Security Service (ESS)
Signed Receipt service as defined in ESS [RFC2634]."

[snip]

The requirements for Applicability Statements
of the EDIINT WG has included a goal of accomodating both PGP-based and
PKCS7/CMS-based message level security. The rough consensus of this WG
has been to try to both reuse available RFCs when possible and
appropriate, and not to adopt radically different AS profiles for
differing security underpinnings or transfer protocols. Because ESS
is inextricably linked to the PKCS7/CMS applied crypto technology, and
no PGP analog exists for it, it is not something we chose to profile
within EDIINT. Additionally, both AS1 and AS2 drafts had been
implemented and were in interoperability trials well before ESS was
available.

I'm actually not proposing that you switch to the ESS signed receipt.
I think it's fine that you did what you did. I am just concerned that
when people read EDIINT with S/MIME drafts and they say they get a
signed receipt that it's not the same thing as the ESS signed receipt.
That's all I just want a heads up notice.

I have seen no one else on this WG list
suggest that ESS be considered even for future applicability statement
profiles. The large existing end user and vendor base using EDIINT WG
Applicability Statements probably would not welcome your call for
deprecation also.

Again I'm acutally not asking that using PGP be deprecated. In the
latest version of CMS (3369bis) we added a key management extension
mechanisms primarily to to supports the use of PGP with CMS and I think
they're looking at it. So who knows maybe S/MIME and PGP will coexist
peacefully in the future.

I think there is no danger of confusing the
signing of a MDN (including the received content mic) with any ESS
construct, and a reference to ESS is not required for implementers to
understand either AS1, AS2 or AS3.

I have actually. One buyer was looking for an signed receipt (ESS
variety) and the vendor claimed they had one but it was a signed
receipt (MDN variety). Would have been fine except the other folks
they were trying to interoperate with were all using signed receipts
(ESS variety). They didn't realize until they started doing testing
that the two were different.

Other comments you provide may be addressed
separately in other messages. There is almost certain to be some delay
in my responses.

I'm available to clarify anything I sent along.

Since we are close to WG last call, and we
have an abundance of working code and rough consensus among both
endusers and development communities, I would encourage other WG
members who wish to see specific points of Mr Turner addressed, to
please post to the list the points you wish to see addressed and the
language you wish to see included.