Re: SCMP ver 06 posted
Tom Arnold <[email protected]> Tue, 30 May 2000 10:14:01 -0700
| Newsgroups | gmane.ietf.scmp |
|---|---|
| Message-ID | <[email protected]> |
Thanks for the comments Peter. Answers below. At 07:34 PM 5/27/00 +0200, Peter Sylvester wrote: >hi, > >Why is there a 'commerce' in the protocol name? The first few implementations of the protocol have all been related to transport of messages related to commerce transactions. Also, as the protocol evolved, the clear use is related to a sending agent making a request from some receiving agent, then getting a reply from the receiving agent. After evaluating the implementations, it's clear the protocol is 'simple' to implement and very efficient for handling many types of commerce transactions. Ergo, the name. >Maybe somehow I am confused about the ordering of the signed and >enveloped data. It seems to me that the example does it the wrong >way, in particular the SCMP-request-id: 0123456789012345678901 >is not signed? Or do you mean by > [ OUTER MIME START ] >a signedData structure, thus triple wrapping of ESS? We looked at mandating triple wrapping, but opted not to implement this. We wanted the SCMP-request-id to be outside the encrypted payload so that the receiving agent's server could have a unique handle to the message prior to decrypting should an error condition exist. In this manner, both the receiving and sending agent's systems would have a known value to reference the error condition. >Some nit-picking: > >- Non-repudation implimentation is specified in section 7.1.2. > e doesn't exist. > 4.1.2 ? thanks for spotting this one. Guess I'm so close to the trees, I missed this reference. It is supposed to be 4.1.2 and has been fixed. >Implemen ations MAY support non-repudation of error message replies. > t > >Regards >Peter Sylvester Thomas A. Arnold Chief Technical Officer CyberSource Corporation 1295 Charleston Road Mountain View, CA 94043-1307 email: [email protected] Main: 650.965.6000 --------------------------------------------------------------------------- This Email and any attached files are confidential and may also be privileged. It is intended only for the individual or entity to whom it is addressed. If you are not the recipient or an authorized agent of the recipient, you are hereby notified that any use, dissemination, distribution or copying of this communication is strictly prohibited. If you have received this message in error, please contact CyberSource Corporation immediately at 650.965.6000. Thank you.