RE: Notification authentication -- more things left out of the PIDF draft

"Adrian Bateman" <[email protected]>
Newsgroups gmane.ietf.impp
Organization VisionTech Limited
Message-ID <001d01c20027$f2040730$6405010a@ADRIANXP>
On 20 May 2002 14:41, John D. Ramsdell wrote:
[snip]
> As I am sure you know, secure implementations of Email reject signed 
> messages if the attached certificate does not include the Email 
> address in the 'From' header as one of its Subject Alternate Names. By

> including Email addresses in certificates, servers and gateways can 
> perform this filtering based on the address in the 'From' header and 
> the validity of the signature.  Application of policy becomes simple 
> and uniform.

When I make a MIME attachment to the e-mail message that I sign, the
document that I am attaching doesn't have to know anything about the
signing process - the e-mail message is the transport and it deals with
the signature.

[snip]
> The purpose of the PIDF document is to define a standard format that 
> allows the exchange of presence information.  Notification request 
> accountability requires a standard format, the data to which on 
> attaches a signature.  Therefore, the PIDF is the appropriate document

> in which to define an embedding of presence information into 
> CPIM-MSGFMT.  If not in the PIDF document, where else would it go?

It is my understanding that the PIDF document defines a standard format
that describes presence information that can be exchanged but it doesn't
say anything about the process of exchange. Indeed, it may simply be
used as a format to store presence information and not care about
transport at all.

To reiterate what I said before, I am certainly not saying that this
isn't something that should be solved, but the PIDF document which
describes a data format isn't the place to do it. It's a while now since
I read CPIM, but I would have thought that was a more appropriate
location - does it not specify the usage of CPIM-MSGFMT for the transfer
of instant messages? Why shouldn't it also describe the use of
CPIM-MSGFMT for the transfer of presence data which seems arbitrarily
independent of the MIME data embedded in such a message.

The original reason for including CPIM-MSGFMT structure in the presence
document was that even presence data storage systems would have been
required to use that in order to maintain partial signatures. That is no
longer necessary which greatly simplifies the situation and makes the
storage/format and transfer to distinct problems.

Best regards,

Adrian.




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.