RE: baseline CPIM security
Beckmann Mark ICM MP P PS 4 SAL 2 <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
I don't like the idea of mandating the implementation of S/MIME. Please keep in mind that this would have to be implemented in all kind of devices, including mobile phones, which may be limited with regards to computing power and available memory. Also, some network configurations may rely on different mechanisms like IPSec to ensure confidentiality of the presence information over the interfaces and consider intermediate proxies and the presence server as "trusted entities". In this case S/MIME would not be necessary. Regards, Mark Mark Beckmann Siemens AG ICM MP P PS 4S2 P.O.Box 100702 phone: +49 (5341) 906 1814 D-38228 Salzgitter fax: +49 (5341) 906 2010 mailto: [email protected] > -----Original Message----- > From: Peterson, Jon [mailto:[email protected]] > Sent: Tuesday, September 24, 2002 9:10 AM > To: '[email protected]' > Subject: baseline CPIM security > > > > I believe that without a mandatory-to-implement baseline > security mechanism, > including a ciphersuite, the prospects of CPIM passing the > IESG are slim. > Moreover, if different presence protocols/applications do not > use common > security mechanisms to apply to security properties to MSGFMT > and PIDF, the > prospects for interoperability through CPIM gateways are > equally slim. It is > also desirable, I think, to use the same mechanism to secure > MSGFMT and > PIDF, in order to minimize the number of security mechanisms that > CPIM-compliant applications and protocols must support. > > Since both PIDF and MSGFMT are MIME-based, I'd like to > suggest that S/MIME > should be the mandatory-to-implement security mechanism for > CPIM-compliant > devices. In my experience, this option is currently preferred by the > Security ADs to the alternatives. > > If we grant that S/MIME should be the mandatory-to-implement security > mechanism, we must also select a minimum ciphersuite. Today, > 3DES is most > commonly used for this purpose. However, an S/MIME > ciphersuite for AES is > also underway; for example, see: > > http://www.ietf.org/internet-drafts/draft-ietf-smime-aes-alg-04.txt > > Ultimately, I think it is probably the right choice for CPIM > to normatively > depend on AES rather than 3DES, even those the CMS AES work > is mostly still > at the I-D stage. > > In terms of textual changes, I'd further like to suggest that > the baseline > CPIM specification is the appropriate place to declare the > mandatory-to-implement security mechanism, and that both the > PIDF document > and the MSGFMT document should normatively reference the security > requirements in CPIM. > > Comments? If not, this will be added to impp-cpim-04. > > Jon Peterson > NeuStar, Inc. > > > > [reminder: [email protected] for non-technical > discussions, please] > [reminder: [email protected] for non-technical discussions, please]