comments

Roger Hayes <[email protected]> Tue, 25 May 1999 13:05:15 -0700
Newsgroups gmane.ietf.scmp
Organization CyberSource
Message-ID <[email protected]>
A couple of initial comments occur to me:

Section 7.2.2 is unclear -- under what circumstances will the 3 steps "fail"?
And what is an appropriate error message?  And how does returning an error message
prevent a denial-of-service attack?

The draft is silent on the topic of charsets and transfer encodings -- these are covered in the SMIME spec, but perhaps the SCMP spec should be explicit that the SMIME transfer encoding specs apply.

                                Roger Hayes
				(not speaking as an official representative)
				[email protected]