Reposted Comments on SCMP ( Chris Newman )

Jason Eaton <[email protected]> Tue, 25 May 1999 16:54:00 -0700
Newsgroups gmane.ietf.scmp
Message-ID <[email protected]>
Submitted by Chris Newnam, on 5/4/99:

  This document has a normative reference to S/MIMEv2, an informational RFC. 
  That RFC has the following deficiencies with respect to use in an IETF
  standard: 

  (1) It fails to disclose patent encumberances on the permitted algorithms,
    in violation of RFC 2026.

  (2) It violates the Danver's Doctrine by failing to include a
    mandatory-to-implement cipher suite which is not export crippled.

  (3) It violates the Munich Mandate by having a patent-encumbered algorithm
    (RSA) as mandatory-to-implement.

  I see three alternatives to resolve these issues for this last call:

  (A) Include text in the SCMP protocol spec which amends S/MIMEv2 to fix
    the three problems above.  You may wish to ask the
    ietf-smime[-request]@imc.org mailing list for advice if you choose
    this path.

  (B) Use IETF standards track technology for this purpose: PGP/MIME (RFC
    2015) with the DSA/El-Gamal cipher suites (RFC 2440) as mandatory to
    implement.

  (C) Wait for S/MIMEv3 to be standardized and reference that.

  The document is also lacking the mandatory "Security Considerations" 
  section.  Therefore I did not review other security issues that might
  concern me. 


Jason Eaton			CyberSource Corporation
Phone 408.260.6044		Security Engineering Manager
[email protected]	http://www.cybersource.com