RE: comments on draft-ietf-impp-cpim-pidf-05

"Adrian Bateman" <[email protected]>
Newsgroups gmane.ietf.impp
Organization VisionTech Limited
Message-ID <004301c24ecb$b986c4e0$6405010a@ADRIANXP>
On 28 August 2002 19:28, John D. Ramsdell wrote:
> "Peterson, Jon" <[email protected]> writes:
> 
> > Well, I would be surprised if anyone seriously contended that 
> > RFC2779
> > did not require us to adopt a common format for end-to-end security.

> > Several of the requirements entail that directly. In the absence of 
> > some baseline common security mechanism (and ciphersuite) secure 
> > implementations will not be interoperable. I think we have a mandate

> > to come to consensus on a format.
> 
> I fully agree with Jon Peterson on this point.  It's the same 
> situation we faced with notification authentication.  It's hard to 
> prove digital signatures are the only possible solution, but I have 
> heard no one advance any other practical solution.  In security text 
> books, the chapter on authentication usually begins by discussing 
> password and challenge/response systems, and then discusses digital 
> signatures.  I see no practical way to use a challenge/response 
> system, so we seem to be stuck with digital signatures.

I'm not sure that anyone would argue against digital signatures. My
point was that there are a number of choices for the format of those
signatures e.g. PGP or S/MIME and that in the past no clear consensus
has suggested that we choose one.

Adrian.
smime.p7s (application/x-pkcs7-signature, 3.1 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.