Fwd: [lamps] S/MIME 4+
Ira McDonald via ipp <[email protected]> Wed, 27 May 2026 12:30:35 -0400
| Newsgroups | gmane.ietf.ipp |
|---|---|
| Message-ID | <CAN40gStHt2U+Zj=a6Ey70XiFm7ywweC_SoyezteXqQ8HeW-r2w@mail.gmail.com> |
--===============0411853975258536354== Content-Type: multipart/alternative; boundary="0000000000007e981f0652cf229f" --0000000000007e981f0652cf229f Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi, FYI - for IPP Encrypted Jobs and Documents Cheers, - Ira ---------- Forwarded message --------- From: Sean Turner <[email protected]> Date: Wed, May 27, 2026 at 11:26=E2=80=AFAM Subject: [lamps] S/MIME 4+ To: IETF LAMPS <[email protected]> Hi! Blake and I submitted drafts that we are hoping will be the basis for S/MIME 4+. Four things I would like to draw your attention to: 1. Authors Jim Schaad passed away in 2020. Out of acknowledgement for the amount of work he put into previous versions, we have moved him to the new "Contributors=E2=80=9D section. 2. Formatting The drafts are as close to RFCs 8550 & 8551 as I could get them; previous versions had some formatting that I could not recreate with the current tools (s7.1 in RFCs 8550 & 8551 was moved to s1.2 in the bis drafts). We can then make changes and everybody can then see what=E2=80=99s changed. Dr= afts are here: https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8550bis/ https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8551bis/ Diffs to RFCs 8550 & 8551 are here: https://author-tools.ietf.org/iddiff?url1=3Drfc8550&url2=3Ddraft-turner-lam= ps-rfc8550bis-00&difftype=3D--html https://author-tools.ietf.org/iddiff?url1=3Drfc8551&url2=3Ddraft-turner-lam= ps-rfc8551bis-00&difftype=3D--html 3. Version Number I picked 4+ because how much we change will dictate what number we use. 4. Changes to Incorporate !?! I started an issue to track what we are going to change - we can then create sub-issues to track each one we agree to do; see https://github.com/seanturner/smime/issues/1. The one thing I absolutely sure we need to include in this update is a =E2=80=9Cfix=E2=80=9D that addresses the Falco attack; see https://github.com/seanturner/smime/issues/2. BUT, the question is do we do that simply by requiring signed attributes always be present or do we do what -cms-euf-cma-signeddata recommends for new protocols and use the id-ct-mimeData content type? I am sure others will come up with more, but here are more changes to consider: =E2=80=A2 Deprecate use of EnvelopedData except for backward compatibil= ity? =E2=80=A2 Deprecate RSA encryption? =E2=80=A2 Keep RSA-OAEP? =E2=80=A2 Add PQ algorithms? =E2=80=A2 Drop =E2=80=9988 ASN.1 Module? Let the games begin! Cheers, spt _______________________________________________ Spasm mailing list -- [email protected] To unsubscribe send an email to [email protected] --0000000000007e981f0652cf229f Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hi,</div><div><br></div><div>FYI - for IPP Encrypted = Jobs and Documents</div><div><br></div><div>Cheers,</div><div>- Ira</div><b= r><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class= =3D"gmail_attr">---------- Forwarded message ---------<br>From: <b class=3D= "gmail_sendername" dir=3D"auto">Sean Turner</b> <span dir=3D"auto"><<a h= ref=3D"mailto:[email protected]">[email protected]</a>></span><br>Date: Wed, M= ay 27, 2026 at 11:26=E2=80=AFAM<br>Subject: [lamps] S/MIME 4+<br>To: IETF L= AMPS <<a href=3D"mailto:[email protected]">[email protected]</a>><br></div>= <br><br>Hi! Blake and I submitted drafts that we are hoping will be the bas= is for S/MIME 4+. Four things I would like to draw your attention to:<br> <br> 1. Authors<br> <br> Jim Schaad passed away in 2020. Out of acknowledgement for the amount of wo= rk he put into previous versions, we have moved him to the new "Contri= butors=E2=80=9D section.<br> <br> 2. Formatting<br> <br> The drafts are as close to RFCs 8550 & 8551 as I could get them; previo= us versions had some formatting that I could not recreate with the current = tools (s7.1 in RFCs 8550 & 8551 was moved to s1.2 in the bis drafts). W= e can then make changes and everybody can then see what=E2=80=99s changed. = Drafts are here:<br> <br> <a href=3D"https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8550bis/"= rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/doc/draf= t-turner-lamps-rfc8550bis/</a><br> <a href=3D"https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8551bis/"= rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/doc/draf= t-turner-lamps-rfc8551bis/</a><br> <br> Diffs to RFCs 8550 & 8551 are here:<br> <br> <a href=3D"https://author-tools.ietf.org/iddiff?url1=3Drfc8550&url2=3Dd= raft-turner-lamps-rfc8550bis-00&difftype=3D--html" rel=3D"noreferrer" t= arget=3D"_blank">https://author-tools.ietf.org/iddiff?url1=3Drfc8550&ur= l2=3Ddraft-turner-lamps-rfc8550bis-00&difftype=3D--html</a><br> <a href=3D"https://author-tools.ietf.org/iddiff?url1=3Drfc8551&url2=3Dd= raft-turner-lamps-rfc8551bis-00&difftype=3D--html" rel=3D"noreferrer" t= arget=3D"_blank">https://author-tools.ietf.org/iddiff?url1=3Drfc8551&ur= l2=3Ddraft-turner-lamps-rfc8551bis-00&difftype=3D--html</a><br> <br> 3. Version Number<br> <br> I picked 4+ because how much we change will dictate what number we use.<br> <br> 4. Changes to Incorporate !?!<br> <br> I started an issue to track what we are going to change - we can then creat= e sub-issues to track each one we agree to do; see <a href=3D"https://githu= b.com/seanturner/smime/issues/1" rel=3D"noreferrer" target=3D"_blank">https= ://github.com/seanturner/smime/issues/1</a>.<br> <br> The one thing I absolutely sure we need to include in this update is a =E2= =80=9Cfix=E2=80=9D that addresses the Falco attack; see <a href=3D"https://= github.com/seanturner/smime/issues/2" rel=3D"noreferrer" target=3D"_blank">= https://github.com/seanturner/smime/issues/2</a>. BUT, the question is do w= e do that simply by requiring signed attributes always be present or do we = do what -cms-euf-cma-signeddata recommends for new protocols and use the id= -ct-mimeData content type?<br> <br> I am sure others will come up with more, but here are more changes to consi= der:<br> =C2=A0 =C2=A0 =E2=80=A2 Deprecate use of EnvelopedData except for backward = compatibility?<br> =C2=A0 =C2=A0 =E2=80=A2 Deprecate RSA encryption?<br> =C2=A0 =C2=A0 =E2=80=A2 Keep RSA-OAEP?<br> =C2=A0 =C2=A0 =E2=80=A2 Add PQ algorithms?<br> =C2=A0 =C2=A0 =E2=80=A2 Drop =E2=80=9988 ASN.1 Module?<br> <br> Let the games begin!<br> <br> Cheers,<br> spt<br> <br> _______________________________________________<br> Spasm mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">s= [email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a><br> </div></div> --0000000000007e981f0652cf229f-- --===============0411853975258536354== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ ipp mailing list [email protected] https://www.pwg.org/mailman/listinfo/ipp --===============0411853975258536354==--