Fwd: [lamps] S/MIME 4+

Ira McDonald via ipp <[email protected]> Wed, 27 May 2026 12:30:35 -0400
Newsgroups gmane.ietf.ipp
Message-ID <CAN40gStHt2U+Zj=a6Ey70XiFm7ywweC_SoyezteXqQ8HeW-r2w@mail.gmail.com>
--===============0411853975258536354==
Content-Type: multipart/alternative; boundary="0000000000007e981f0652cf229f"

--0000000000007e981f0652cf229f
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi,

FYI - for IPP Encrypted Jobs and Documents

Cheers,
- Ira

---------- Forwarded message ---------
From: Sean Turner <[email protected]>
Date: Wed, May 27, 2026 at 11:26=E2=80=AFAM
Subject: [lamps] S/MIME 4+
To: IETF LAMPS <[email protected]>


Hi! Blake and I submitted drafts that we are hoping will be the basis for
S/MIME 4+. Four things I would like to draw your attention to:

1. Authors

Jim Schaad passed away in 2020. Out of acknowledgement for the amount of
work he put into previous versions, we have moved him to the new
"Contributors=E2=80=9D section.

2. Formatting

The drafts are as close to RFCs 8550 & 8551 as I could get them; previous
versions had some formatting that I could not recreate with the current
tools (s7.1 in RFCs 8550 & 8551 was moved to s1.2 in the bis drafts). We
can then make changes and everybody can then see what=E2=80=99s changed. Dr=
afts are
here:

https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8550bis/
https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8551bis/

Diffs to RFCs 8550 & 8551 are here:

https://author-tools.ietf.org/iddiff?url1=3Drfc8550&url2=3Ddraft-turner-lam=
ps-rfc8550bis-00&difftype=3D--html
https://author-tools.ietf.org/iddiff?url1=3Drfc8551&url2=3Ddraft-turner-lam=
ps-rfc8551bis-00&difftype=3D--html

3. Version Number

I picked 4+ because how much we change will dictate what number we use.

4. Changes to Incorporate !?!

I started an issue to track what we are going to change - we can then
create sub-issues to track each one we agree to do; see
https://github.com/seanturner/smime/issues/1.

The one thing I absolutely sure we need to include in this update is a
=E2=80=9Cfix=E2=80=9D that addresses the Falco attack; see
https://github.com/seanturner/smime/issues/2. BUT, the question is do we do
that simply by requiring signed attributes always be present or do we do
what -cms-euf-cma-signeddata recommends for new protocols and use the
id-ct-mimeData content type?

I am sure others will come up with more, but here are more changes to
consider:
    =E2=80=A2 Deprecate use of EnvelopedData except for backward compatibil=
ity?
    =E2=80=A2 Deprecate RSA encryption?
    =E2=80=A2 Keep RSA-OAEP?
    =E2=80=A2 Add PQ algorithms?
    =E2=80=A2 Drop =E2=80=9988 ASN.1 Module?

Let the games begin!

Cheers,
spt

_______________________________________________
Spasm mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--0000000000007e981f0652cf229f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi,</div><div><br></div><div>FYI - for IPP Encrypted =
Jobs and Documents</div><div><br></div><div>Cheers,</div><div>- Ira</div><b=
r><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=
=3D"gmail_attr">---------- Forwarded message ---------<br>From: <b class=3D=
"gmail_sendername" dir=3D"auto">Sean Turner</b> <span dir=3D"auto">&lt;<a h=
ref=3D"mailto:[email protected]">[email protected]</a>&gt;</span><br>Date: Wed, M=
ay 27, 2026 at 11:26=E2=80=AFAM<br>Subject: [lamps] S/MIME 4+<br>To: IETF L=
AMPS &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt;<br></div>=
<br><br>Hi! Blake and I submitted drafts that we are hoping will be the bas=
is for S/MIME 4+. Four things I would like to draw your attention to:<br>
<br>
1. Authors<br>
<br>
Jim Schaad passed away in 2020. Out of acknowledgement for the amount of wo=
rk he put into previous versions, we have moved him to the new &quot;Contri=
butors=E2=80=9D section.<br>
<br>
2. Formatting<br>
<br>
The drafts are as close to RFCs 8550 &amp; 8551 as I could get them; previo=
us versions had some formatting that I could not recreate with the current =
tools (s7.1 in RFCs 8550 &amp; 8551 was moved to s1.2 in the bis drafts). W=
e can then make changes and everybody can then see what=E2=80=99s changed. =
Drafts are here:<br>
<br>
<a href=3D"https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8550bis/"=
 rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/doc/draf=
t-turner-lamps-rfc8550bis/</a><br>
<a href=3D"https://datatracker.ietf.org/doc/draft-turner-lamps-rfc8551bis/"=
 rel=3D"noreferrer" target=3D"_blank">https://datatracker.ietf.org/doc/draf=
t-turner-lamps-rfc8551bis/</a><br>
<br>
Diffs to RFCs 8550 &amp; 8551 are here:<br>
<br>
<a href=3D"https://author-tools.ietf.org/iddiff?url1=3Drfc8550&amp;url2=3Dd=
raft-turner-lamps-rfc8550bis-00&amp;difftype=3D--html" rel=3D"noreferrer" t=
arget=3D"_blank">https://author-tools.ietf.org/iddiff?url1=3Drfc8550&amp;ur=
l2=3Ddraft-turner-lamps-rfc8550bis-00&amp;difftype=3D--html</a><br>
<a href=3D"https://author-tools.ietf.org/iddiff?url1=3Drfc8551&amp;url2=3Dd=
raft-turner-lamps-rfc8551bis-00&amp;difftype=3D--html" rel=3D"noreferrer" t=
arget=3D"_blank">https://author-tools.ietf.org/iddiff?url1=3Drfc8551&amp;ur=
l2=3Ddraft-turner-lamps-rfc8551bis-00&amp;difftype=3D--html</a><br>
<br>
3. Version Number<br>
<br>
I picked 4+ because how much we change will dictate what number we use.<br>
<br>
4. Changes to Incorporate !?!<br>
<br>
I started an issue to track what we are going to change - we can then creat=
e sub-issues to track each one we agree to do; see <a href=3D"https://githu=
b.com/seanturner/smime/issues/1" rel=3D"noreferrer" target=3D"_blank">https=
://github.com/seanturner/smime/issues/1</a>.<br>
<br>
The one thing I absolutely sure we need to include in this update is a =E2=
=80=9Cfix=E2=80=9D that addresses the Falco attack; see <a href=3D"https://=
github.com/seanturner/smime/issues/2" rel=3D"noreferrer" target=3D"_blank">=
https://github.com/seanturner/smime/issues/2</a>. BUT, the question is do w=
e do that simply by requiring signed attributes always be present or do we =
do what -cms-euf-cma-signeddata recommends for new protocols and use the id=
-ct-mimeData content type?<br>
<br>
I am sure others will come up with more, but here are more changes to consi=
der:<br>
=C2=A0 =C2=A0 =E2=80=A2 Deprecate use of EnvelopedData except for backward =
compatibility?<br>
=C2=A0 =C2=A0 =E2=80=A2 Deprecate RSA encryption?<br>
=C2=A0 =C2=A0 =E2=80=A2 Keep RSA-OAEP?<br>
=C2=A0 =C2=A0 =E2=80=A2 Add PQ algorithms?<br>
=C2=A0 =C2=A0 =E2=80=A2 Drop =E2=80=9988 ASN.1 Module?<br>
<br>
Let the games begin!<br>
<br>
Cheers,<br>
spt<br>
<br>
_______________________________________________<br>
Spasm mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">s=
[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar=
get=3D"_blank">[email protected]</a><br>
</div></div>

--0000000000007e981f0652cf229f--

--===============0411853975258536354==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp

--===============0411853975258536354==--