RE: Notification authentication -- more things left out of the PIDF draft
"Adrian Bateman" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Organization | VisionTech Limited |
| Message-ID | <001d01c20027$f2040730$6405010a@ADRIANXP> |
On 20 May 2002 14:41, John D. Ramsdell wrote: [snip] > As I am sure you know, secure implementations of Email reject signed > messages if the attached certificate does not include the Email > address in the 'From' header as one of its Subject Alternate Names. By > including Email addresses in certificates, servers and gateways can > perform this filtering based on the address in the 'From' header and > the validity of the signature. Application of policy becomes simple > and uniform. When I make a MIME attachment to the e-mail message that I sign, the document that I am attaching doesn't have to know anything about the signing process - the e-mail message is the transport and it deals with the signature. [snip] > The purpose of the PIDF document is to define a standard format that > allows the exchange of presence information. Notification request > accountability requires a standard format, the data to which on > attaches a signature. Therefore, the PIDF is the appropriate document > in which to define an embedding of presence information into > CPIM-MSGFMT. If not in the PIDF document, where else would it go? It is my understanding that the PIDF document defines a standard format that describes presence information that can be exchanged but it doesn't say anything about the process of exchange. Indeed, it may simply be used as a format to store presence information and not care about transport at all. To reiterate what I said before, I am certainly not saying that this isn't something that should be solved, but the PIDF document which describes a data format isn't the place to do it. It's a while now since I read CPIM, but I would have thought that was a more appropriate location - does it not specify the usage of CPIM-MSGFMT for the transfer of instant messages? Why shouldn't it also describe the use of CPIM-MSGFMT for the transfer of presence data which seems arbitrarily independent of the MIME data embedded in such a message. The original reason for including CPIM-MSGFMT structure in the presence document was that even presence data storage systems would have been required to use that in order to maintain partial signatures. That is no longer necessary which greatly simplifies the situation and makes the storage/format and transfer to distinct problems. Best regards, Adrian. [reminder: [email protected] for non-technical discussions, please]