Re: comments

Jason Eaton <[email protected]> Tue, 25 May 1999 13:55:58 -0700
Newsgroups gmane.ietf.scmp
Message-ID <[email protected]>
At 01:05 PM 5/25/99, Roger Hayes wrote:
>A couple of initial comments occur to me:
>
>Section 7.2.2 is unclear -- under what circumstances will the 3 steps "fail"?

The ability to reply to a duplicate request id with the original reply is
currently slated to be removed from the draft. It has been noted by other
people that this feature is the proverbial "can of worms".

I am inclined to agree. Additionally this feature does not exist in all
known implimentations. 

Unless we get strong feedback otherwise, this feature will be removed.

>And what is an appropriate error message?  

And how does returning an error message prevent a denial-of-service attack?

I think the term "denial-of-service attack" is used incorrectly. It should
be replaced with "replay attack".

>The draft is silent on the topic of charsets and transfer encodings -- these 
>are covered in the SMIME spec, but perhaps the SCMP spec should be explicit 
>that the SMIME transfer encoding specs apply.

Other people have mentioned this too. We need to specify the data types for
all the headers.

Working on it ;)

>
>                                Roger Hayes
>				(not speaking as an official representative)
>				[email protected]


Jason Eaton			CyberSource Corporation
Phone 408.260.6044		Security Engineering Manager
[email protected]	http://www.cybersource.com