RE: comments on draft-ietf-impp-cpim-pidf-05
"Adrian Bateman" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Organization | VisionTech Limited |
| Message-ID | <004301c24ecb$b986c4e0$6405010a@ADRIANXP> |
On 28 August 2002 19:28, John D. Ramsdell wrote: > "Peterson, Jon" <[email protected]> writes: > > > Well, I would be surprised if anyone seriously contended that > > RFC2779 > > did not require us to adopt a common format for end-to-end security. > > Several of the requirements entail that directly. In the absence of > > some baseline common security mechanism (and ciphersuite) secure > > implementations will not be interoperable. I think we have a mandate > > to come to consensus on a format. > > I fully agree with Jon Peterson on this point. It's the same > situation we faced with notification authentication. It's hard to > prove digital signatures are the only possible solution, but I have > heard no one advance any other practical solution. In security text > books, the chapter on authentication usually begins by discussing > password and challenge/response systems, and then discusses digital > signatures. I see no practical way to use a challenge/response > system, so we seem to be stuck with digital signatures. I'm not sure that anyone would argue against digital signatures. My point was that there are a number of choices for the format of those signatures e.g. PGP or S/MIME and that in the past no clear consensus has suggested that we choose one. Adrian.
smime.p7s
(application/x-pkcs7-signature, 3.1 KB) - not displayed