Re: SCMP ver 06 posted

Tom Arnold <[email protected]> Tue, 30 May 2000 10:14:01 -0700
Newsgroups gmane.ietf.scmp
Message-ID <[email protected]>
Thanks for the comments Peter. Answers below.

At 07:34 PM 5/27/00 +0200, Peter Sylvester wrote:
>hi,
>
>Why is there a 'commerce' in the protocol name?

The first few implementations of the protocol have all been related to 
transport of messages related to commerce transactions. Also, as the 
protocol evolved, the clear use is related to a sending agent making a 
request from some receiving agent, then getting a reply from the receiving 
agent. After evaluating the implementations, it's clear the protocol is 
'simple' to implement and very efficient for handling many types of 
commerce transactions. Ergo, the name.


>Maybe somehow I am confused about the ordering of the signed and
>enveloped data. It seems to me that the example does it the wrong
>way, in particular the SCMP-request-id: 0123456789012345678901
>is not signed? Or do you mean by
>  [ OUTER MIME START ]
>a signedData structure, thus triple wrapping of ESS?

We looked at mandating triple wrapping, but opted not to implement this. We 
wanted the SCMP-request-id to be outside the encrypted payload so that the 
receiving agent's server could have a unique handle to the message prior to 
decrypting should an error condition exist. In this manner, both the 
receiving and sending agent's systems would have a known value to reference 
the error condition.


>Some nit-picking:
>
>-  Non-repudation implimentation is specified in section 7.1.2.
>                       e                                  doesn't exist. 
> 4.1.2 ?

thanks for spotting this one. Guess I'm so close to the trees, I missed 
this reference. It is supposed to be 4.1.2 and has been fixed.



>Implemen ations MAY support non-repudation of error message replies.
>         t
>
>Regards
>Peter Sylvester



Thomas A. Arnold
Chief Technical Officer
CyberSource Corporation
1295 Charleston Road
Mountain View, CA 94043-1307
email: [email protected]
Main: 650.965.6000
---------------------------------------------------------------------------
This Email and any attached files are confidential and may also be
privileged. It is intended only for the individual or entity to whom
it is addressed. If you are not the recipient or an authorized agent
of the recipient, you are hereby notified that any use, dissemination,
distribution or copying of this communication is strictly prohibited.
If you have received this message in error, please contact CyberSource
Corporation immediately at 650.965.6000.

Thank you.