Re: comments on draft-ietf-impp-cpim-pidf-05
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
Adrian, In my previous message, my comments were meant to apply only to the content that is being signed. I was not arguing that we pick one format to encapsulate the signed content. My point was we need to define the analog of PIDF for subscription requests. You are correct in that we must deal with the issue you raise at some point. I just wanted to note that my message did not address your topic. I have never broached this topic, however, I seem to remember Jon Peterson suggesting that S/MIME have a distinguished role at one time. John "Adrian Bateman" <[email protected]> writes: > On 28 August 2002 19:28, John D. Ramsdell wrote: > > "Peterson, Jon" <[email protected]> writes: > > > > > Well, I would be surprised if anyone seriously contended that > > > RFC2779 > > > did not require us to adopt a common format for end-to-end security. > > > > Several of the requirements entail that directly. In the absence of > > > some baseline common security mechanism (and ciphersuite) secure > > > implementations will not be interoperable. I think we have a mandate > > > > to come to consensus on a format. > > > > I fully agree with Jon Peterson on this point. It's the same > > situation we faced with notification authentication. It's hard to > > prove digital signatures are the only possible solution, but I have > > heard no one advance any other practical solution. In security text > > books, the chapter on authentication usually begins by discussing > > password and challenge/response systems, and then discusses digital > > signatures. I see no practical way to use a challenge/response > > system, so we seem to be stuck with digital signatures. > > I'm not sure that anyone would argue against digital signatures. My > point was that there are a number of choices for the format of those > signatures e.g. PGP or S/MIME and that in the past no clear consensus > has suggested that we choose one. > > Adrian. [reminder: [email protected] for non-technical discussions, please]