Re: baseline CPIM security

Dave Crocker <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 05:57 PM 10/5/2002 -0400, Derek Atkins wrote:
>A CPIM-compliant IMPP system can be gatewayed because the CONTENT
>(which can be encrypted end-to-end) can be transported to system B,
>across a gateway from system A, successfully.

I am slowly coming to appreciate just how broadly and thoroughly the nature 
of the original CPIM exercise was not understood.

A gateway does translation between heterogeneous environments.  When the 
only thing that is different is the underlying transfer mechanism, the 
thing that does the switching is a relay (or router) not a gateway.

Think real hard about IP.  IP is common content.  The exchange "medium" is 
all that differs.  That, indeed, is what you folks are describing for CPIM.

That's not gatewaying.

Gatewaying is what is done between Internet Mail and X.400, for 
example.  Two, independent and complete systems.

One of the expectations for CPIM was that it would permit interconnect with 
existing IM services.  All of the work that imposes new, end-to-end 
services guarantees that interconnect will not be possible with those 
rather large, successful services.

And, by the way, folks need to study the track record of efforts that have 
sought to impose particular security mechanisms on the messaging 
world.  Take a look at how long S/Mime and PGP have been around.

We don't yet have a clear winner.  We therefore have no basis for asserting 
a particular choice.

When doing this sort of standards work, the fact that something is 
implementable is necessary, but it is a very long way from 
sufficient.  Minor matters such as likelihood of adoption need to factor in.

d/


----------
Dave Crocker <mailto:[email protected]>
TribalWise, Inc. <http://www.tribalwise.com>
tel +1.408.246.8253; fax +1.408.850.1850




  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.