RE: baseline CPIM security

Dave Crocker <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 02:03 AM 10/3/2002 -0400, Peterson, Jon wrote:
>The requirements of RFC2779 entail an end-to-end security model - this
>suggests that either transport or network layer security would not meet the

1.  The subject line of this thread refers to CPIM, but 2779 refers to a 
protocol.  CPIM is not a protocol.  It is a gateway mechanism.  In a 
gateway, there is no "end to end".  For that matter, a gateway translates 
between protocol environments, so the concept of end to end is difficult 
there, too.

2.  In a variety of venues, there has occasionally been discussion of 
separating object-oriented security mechanisms to permit re-use of the data 
encryption key (ie, the computational cheap "session" key) from the public 
key mechanism, so that multiple messages can use the same encryption key.

d/


----------
Dave Crocker <mailto:[email protected]>
TribalWise, Inc. <http://www.tribalwise.com>
tel +1.408.246.8253; fax +1.408.850.1850




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.