non-repudiation of message origin

[email protected] Mon, 29 Jul 2002 11:23:58 -0400
Newsgroups gmane.ietf.idwg
Message-ID <397E0659AA2DD411843500508B64F1CE04310311@USBOSMX01>
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Just as an FYI, here is the text from Section 5 of the current
draft-ietf-idwg-beep-idxp-05:

   The [protocol] SHOULD be able to ensure non-repudiation of the
origin
   of IDMEF messages.

      IDXP supports non-repudiation of session origin through the use
of
      an appropriate underlying BEEP security profile.  An IDXP peer
      application MAY use IDMEF content and/or BEEP session
credentials
      to provide for non-repudiation of message origin.  The TLS
profile
      is an example of a security profile that offers non-repudiation
of
      session origin through the authentication of public-key
      certificates.  TLS MUST be offered as a mechanism to provide
non-
      repudiation of session origin, and TLS SHOULD be used to
provide
      non-repudiation of session origin.

Cheers,
Ben

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.4

iQA+AwUBPUVfYPt7bOk+HH2bEQKkegCeObX5TFBMvZ9G512ivEAvHF7aEbgAkwTG
MKDB+AA63HHd+rmmkZx5J4c=
=90bI
-----END PGP SIGNATURE-----