Re: Loops (RE: CPIM changes)

Dave Crocker <[email protected]> Sat, 16 Nov 2002 07:39:43 -0800
Newsgroups gmane.ietf.impp
Organization TribalWise
Message-ID <[email protected]>
Derek,


Saturday, November 16, 2002, 5:56:00 AM, you wrote:
Derek> Dave Crocker <[email protected]> writes:

>> if one side of the gateway uses key/value and the other side uses compact
>> binary, then how does end-to-end security work?

Derek> The Signature is over the canonical form, but that form is NOT
Derek> necessarily the form transmitted over the wire.

sounds interesting.  where has this sort of abstraction-based,
intermediary-friendly signing been done?  Given the fact that the goal you
are seeking is an end-to-end mechanism, the sort of syntactic change by an
intermediary, would be pretty unusual.

Derek> The question you SHOULD have asked is how does _encryption_ work?  In
Derek> that case you do need to encrypt the canonical form.

i said 'security', in order to include both signing and sealing.

d/
-- 
 Dave Crocker  <mailto:[email protected]>
 TribalWise <http://www.tribalwise.com>
 t +1.408.246.8253; f +1.408.850.1850




  [reminder: [email protected] for non-technical discussions, please]