baseline CPIM security

"Peterson, Jon" <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
I believe that without a mandatory-to-implement baseline security mechanism,
including a ciphersuite, the prospects of CPIM passing the IESG are slim.
Moreover, if different presence protocols/applications do not use common
security mechanisms to apply to security properties to MSGFMT and PIDF, the
prospects for interoperability through CPIM gateways are equally slim. It is
also desirable, I think, to use the same mechanism to secure MSGFMT and
PIDF, in order to minimize the number of security mechanisms that
CPIM-compliant applications and protocols must support.

Since both PIDF and MSGFMT are MIME-based, I'd like to suggest that S/MIME
should be the mandatory-to-implement security mechanism for CPIM-compliant
devices. In my experience, this option is currently preferred by the
Security ADs to the alternatives.

If we grant that S/MIME should be the mandatory-to-implement security
mechanism, we must also select a minimum ciphersuite. Today, 3DES is most
commonly used for this purpose. However, an S/MIME ciphersuite for AES is
also underway; for example, see:

http://www.ietf.org/internet-drafts/draft-ietf-smime-aes-alg-04.txt

Ultimately, I think it is probably the right choice for CPIM to normatively
depend on AES rather than 3DES, even those the CMS AES work is mostly still
at the I-D stage.

In terms of textual changes, I'd further like to suggest that the baseline
CPIM specification is the appropriate place to declare the
mandatory-to-implement security mechanism, and that both the PIDF document
and the MSGFMT document should normatively reference the security
requirements in CPIM.

Comments? If not, this will be added to impp-cpim-04.

Jon Peterson
NeuStar, Inc.



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.