Re: IESG Review: draft-ietf-fax-ffpim-05.txt
Graham Klyne <[email protected]> Fri, 09 Jul 2004 11:24:33 +0100
| Newsgroups | gmane.ietf.fax |
|---|---|
| Message-ID | <[email protected]> |
At 16:09 09/07/04 +0700, Dave Crocker wrote: >Scott and Working Group Participants, > >Here are my thoughts on the IESG comments. > >Anyone care to comment on my comments? > > >SH> Steve Bellovin: >SH> Discuss: >SH> [2004-07-06] Format conversions by intermediaries breaks S/MIME. 2305, on >SH> which this builds, specifically suggests using S/MIME and PGP. > >RFC2305 says that they "can be used to provide end-to-end encryption". >That is rather different from suggesting that s/mime or pgp get used >at the expense of other functions. > >Let's remember that there are other privacy techniques. > >If we view content encryption and content conversion as examples of >functional options for FFPIM then the observation is that these two >options do not interact well. > >It seems entirely reasonable to note that fact in the specification, >in case implementors have not already noticed that a content >conversion cannot work when the contents are encrypted. ... unless the content-conversion platform has access to the decryption keys. (This isn't just a theoretical point -- I think one version of MIMEsweeper actually implemented something this.) But it seems that signing a message and also giving permission for the message to be modified are somewhat contradictory functions, and it might be worth saying that permission to convert SHOULD NOT normally be used with signed messages? #g ------------ Graham Klyne For email: http://www.ninebynine.org/#Contact