Re: ESS and Ediint RE: WG Last Call for AS2
"Sean P. Turner" <[email protected]> Wed, 21 Apr 2004 08:51:18 -0400
| Newsgroups | gmane.ietf.ediint |
|---|---|
| Organization | IECA, Inc. |
| Message-ID | <[email protected]> |
Dale Moberg wrote: Message Sean P. Turner writes: Some comments (many of the same comments I made on RFC 3335): [snip] Section 2.3.1 - Signed Receipt definition - Same comment as a I had on RFC 3335 - CMS has a "signed receipt" service too. I think to avoid confusion you should add "The signed Receipt service defined herein is NOT the same as the S/MIME Extended Security Service (ESS) Signed Receipt service as defined in ESS [RFC2634]." [snip] The requirements for Applicability Statements of the EDIINT WG has included a goal of accomodating both PGP-based and PKCS7/CMS-based message level security. The rough consensus of this WG has been to try to both reuse available RFCs when possible and appropriate, and not to adopt radically different AS profiles for differing security underpinnings or transfer protocols. Because ESS is inextricably linked to the PKCS7/CMS applied crypto technology, and no PGP analog exists for it, it is not something we chose to profile within EDIINT. Additionally, both AS1 and AS2 drafts had been implemented and were in interoperability trials well before ESS was available. I'm actually not proposing that you switch to the ESS signed receipt. I think it's fine that you did what you did. I am just concerned that when people read EDIINT with S/MIME drafts and they say they get a signed receipt that it's not the same thing as the ESS signed receipt. That's all I just want a heads up notice. I have seen no one else on this WG list suggest that ESS be considered even for future applicability statement profiles. The large existing end user and vendor base using EDIINT WG Applicability Statements probably would not welcome your call for deprecation also. Again I'm acutally not asking that using PGP be deprecated. In the latest version of CMS (3369bis) we added a key management extension mechanisms primarily to to supports the use of PGP with CMS and I think they're looking at it. So who knows maybe S/MIME and PGP will coexist peacefully in the future. I think there is no danger of confusing the signing of a MDN (including the received content mic) with any ESS construct, and a reference to ESS is not required for implementers to understand either AS1, AS2 or AS3. I have actually. One buyer was looking for an signed receipt (ESS variety) and the vendor claimed they had one but it was a signed receipt (MDN variety). Would have been fine except the other folks they were trying to interoperate with were all using signed receipts (ESS variety). They didn't realize until they started doing testing that the two were different. Other comments you provide may be addressed separately in other messages. There is almost certain to be some delay in my responses. I'm available to clarify anything I sent along. Since we are close to WG last call, and we have an abundance of working code and rough consensus among both endusers and development communities, I would encourage other WG members who wish to see specific points of Mr Turner addressed, to please post to the list the points you wish to see addressed and the language you wish to see included.