Re: rough sketch of a potential solution

Steve Hole <[email protected]> Mon, 17 Nov 2003 08:59:04 -0700
Newsgroups gmane.ietf.imaa
Message-ID <[email protected]>
On Mon, 17 Nov 2003 03:08:26 -0500 Martin Duerst <[email protected]> wrote:


> > > * Secure e-mail.  What should MUAs display as the sender address?  The
> > >   ASCII version or non-ASCII, looked up via the service you propose?
> >
> >They should show the address in the sender's certificate as the party
> >who signed the message, which shouldn't have to be the same as the From
> >address anyway.  The addresses in the message header should be displayed
> >separately.

Actually, that's not a very good idea.   I would say that the address (or 
one of the addresses if we want to syntactically correct) MUST match the 
address held in the signing certificate or you lose much of the benefit of
digital signature wrt to recipient trust.  

Cheers.

---
Steve Hole
Chief Technology Officer - Billing and Payment Systems
ACI Worldwide
<mailto:[email protected]>
Phone: 780-424-4922