Re: Cryptography (was: Re: draft-klensin-emailaddr-i18n-00)
Paul Hoffman / IMC <[email protected]>
| Newsgroups | gmane.ietf.imaa |
|---|---|
| Message-ID | <p06002001bbc4361fda67@[63.202.92.152]> |
At 11:03 AM +0100 10/28/03, Arnt Gulbrandsen wrote: >Paul Hoffman / IMC writes: >>At 11:23 AM +0100 10/27/03, Arnt Gulbrandsen wrote: >>>Oh please, not _another_ obstacle to signature support. The state >>>is bad enough as it is - we really don't need more obstacles. >> >>Again: this has nothing to do with "signature support". The headers >>in email messages are *not* covered by the signature (or by >>encryption). > >Sorry, I misunderstood then. I thought this (also?) applied to body text. The specification says in section 2 "for example, a mail address appearing in the plain text body of a message is not occupying a mail address slot". If there are other parts of the specification that you find confusing about changes to the body, by all means please let us know so we can clarify them. >But my point stands (in the case of sanely designed MUAs). When a >message/rfc822 is contained by a multipart/signed, a header is >signed/encrypted. Any code that treats a top-level message like a >message/rfc822 bodypart will need to deal with the >signature/normalization problems for the header as well as for the >body. Sorry, we fully disagree. Changing the body of a message is a terrible idea for many reasons, security being one of them. --Paul Hoffman, Director --Internet Mail Consortium