Reposted Comments on SCMP ( Chris Newman )
Jason Eaton <[email protected]> Tue, 25 May 1999 16:54:00 -0700
| Newsgroups | gmane.ietf.scmp |
|---|---|
| Message-ID | <[email protected]> |
Submitted by Chris Newnam, on 5/4/99:
This document has a normative reference to S/MIMEv2, an informational RFC.
That RFC has the following deficiencies with respect to use in an IETF
standard:
(1) It fails to disclose patent encumberances on the permitted algorithms,
in violation of RFC 2026.
(2) It violates the Danver's Doctrine by failing to include a
mandatory-to-implement cipher suite which is not export crippled.
(3) It violates the Munich Mandate by having a patent-encumbered algorithm
(RSA) as mandatory-to-implement.
I see three alternatives to resolve these issues for this last call:
(A) Include text in the SCMP protocol spec which amends S/MIMEv2 to fix
the three problems above. You may wish to ask the
ietf-smime[-request]@imc.org mailing list for advice if you choose
this path.
(B) Use IETF standards track technology for this purpose: PGP/MIME (RFC
2015) with the DSA/El-Gamal cipher suites (RFC 2440) as mandatory to
implement.
(C) Wait for S/MIMEv3 to be standardized and reference that.
The document is also lacking the mandatory "Security Considerations"
section. Therefore I did not review other security issues that might
concern me.
Jason Eaton CyberSource Corporation
Phone 408.260.6044 Security Engineering Manager
[email protected] http://www.cybersource.com