Re: baseline CPIM security

Derek Atkins <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
Dave Crocker <[email protected]> writes:

> a gateway specification needs a canonical form.  indeed, gateways that
> are designed for extensibility usually implement a canonical internal
> form and then map to and from it.

This is true....

> that was the intent behind the original effort on CPIM, as I
> understood it at the time.  the larger and longer-term likelihood of
> propagating change out to the participating systems was thought to be
> just that.  likelihood.  not requirement.

I'm not sure I agree with this.  My understanding was that IMPP, CPIM,
and PDIF were supposed to be "The Way" to get SIMPLE, APEX, et. al. to
talk to each other.  This still requires a gateway -- the transport
protocols are different.  What IMPP is standardizing is the CONTENT
format, not the TRANSPORT format.

A CPIM-compliant IMPP system can be gatewayed because the CONTENT
(which can be encrypted end-to-end) can be transported to system B,
across a gateway from system A, successfully.  The key is that the
client in system A encrypts the message, and the client in system B
decrypts the message.  As the message _IS_ encrypted, the gateway
cannot perform any translation.

As we are tasked with definiting the interoperability, that implies
that we must define the core pieces of interop that must survive
gatewaying.  The message format, PDIF format, and end-to-end security
requirements fall into that role.  Clearly how the messages are
transported does not.

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       [email protected]             www.ihtfp.com



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.