Re: IESG Review: draft-ietf-fax-esmtp-conneg-10.txt
Graham Klyne <[email protected]> Sun, 11 Jul 2004 11:34:04 +0100
| Newsgroups | gmane.ietf.fax |
|---|---|
| Message-ID | <[email protected]> |
At 18:12 10/07/04 +0700, Dave Crocker wrote: >I propose to add to: > > 1. Content Negotiation section: > > Content conversion will invalidate a message's signature and will not > be possible to perform with encrypted content. Therefore, permission > to convert SHOULD NOT normally be given with signed or encrypted > messages. Dave, I recognize that this reflects, in part, a comment that I made. But on reflection I find that I'm uncomfortable with the implication that content negotiation and security are mutually exclusive options. In the case of encryption, as you note elsewhere, the conversion can be performed by an intermediary with access to the appropriate keys. In the case of signature, I can imagine the possibility of a trusted intermediary that performs a conversion and then signs it as being a conversion of some original document. In such circumstances, maybe the original signed document should also be delivered. I think these are significant issues to explore with respect to content negotiation and security, but also think there's a reasonable concern about how much detail is required. I'm thinking that the text should cover the following points (and avoid the SHOULD NOT used above): 1. If a document-converting intermediary fails to ensure that the resulting converted content is similarly protected, then the benefits of the originally applied security are lost. [Note: this comment does not exclude the possibility that the conversion and onward transmission occurs without added on a trusted network.] 2. Conversion of an encrypted document requires a (presumably trusted) intermediary to have access to the decryption key. Such intermediaries should take steps to ensure the resulting concerted content is similarly protected (e.g. by re-encryption). 3. Conversion of a signed document results in a document that is not covered by the original signature. An intermediary that performs conversion should assure some level of integrity is applied to the result of the conversion (e.g. by itself signing the converted document together with a hash of the original, and possibly including a copy of the original signed document). 4. A full discussion of mechanisms for applying security to converted documents is beyond the scope of this specification. [But maybe a mini-survey, drawn from the comments above?] Maybe it should also be stated that, in any case, the intermediary MUST at least pass information to the ultimate recipient indicating that the sender applied encryption and/or signature to the original content? #g ------------ Graham Klyne For email: http://www.ninebynine.org/#Contact