Re: rough sketch of a potential solution
Steve Hole <[email protected]> Mon, 17 Nov 2003 11:36:59 -0700
| Newsgroups | gmane.ietf.imaa |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 17 Nov 2003 13:02:15 -0500 Keith Moore <[email protected]> wrote: > Well, we've already got the capability for multiple From addresses, and > now we'll have a situation where each of those From addresses can have > multiple representations. So we inherently have a situation where the > parties who sign a message may not match the list of addresses in the > From field. The only question is how the recipient's MUA should > represent this situation to the recipient. It can say "message is > signed but the signature doesn't match the From addresses" (which is > misleading), or it can say "signature invalid" (which is worse), > or it can say "message is signed by [email protected]". It only has to match one of the representations. Sigh ... to be fair, this is somewhat of a misnomer. IFF MUA's provided some really obvious and user friendly means of saying "this content was issued by this signer" then it wouldn't matter. But. Most (every MUA that matters) only sign messages, not parts of messages. Most verify/validate that the From address (usually singular) matches the email address in the signing cert. If they don't, then you get the big black screen of uninformed user panic "There is something wrong with this message". It is difficult to argue that this isn't a good policy if signing always occurs in the real world at the top MIME level -- which it does. So, at least, we really SHOULD NOT do more to damage the already precarious usage issues with S/MIME processing. A definition for "proper" security processing is well beyond the scope of this group, but we definitely need to take existing practice into account. > But now I remember another one of the reasons for allowing the mapping > service to sign address mappings (and to include those signatures in > the address mapping header extensions) - it was so that if a message were > signed by [email protected] but shown to the recipient as if it were from > [email protected], it would be possible for the recipient's MUA to verify > that the two addresses really were equivalent. Interesting. Whatever comes of imaa will seriously need to be discussed in the S/MIME working group so that some definition of the right way to do address matching is well defined enough that even MS can get it right. Cheers. --- Steve Hole Chief Technology Officer - Billing and Payment Systems ACI Worldwide <mailto:[email protected]> Phone: 780-424-4922