v0.7 SFL Release
[email protected] (John Pawling)
| Newsgroups | gmane.ietf.sfl |
|---|---|
| Message-ID | <[email protected]> |
All,
J.G. Van Dyke and Associates (VDA) has delivered the seventh interim
release (Version 0.7) of the S/MIME Freeware Library (SFL). It has
been successfully tested using the MS Windows NT/95 and Linux
operating systems. The SFL is a reference implementation of the IETF
S/MIME v3 CMS (draft-ietf-smime-cms-11) and ESS (draft-ietf-smime-ess-12)
(NOTE: CMS-12 will be implemented in an SFL release in April 99).
The following enhancements are included in the v0.7 SFL release:
- Integrated CMS changes into ASN.1 syntax modules used by SFL and
changed the SFL C++ Classes accordingly.
- Removed dependency of VDA-enhanced SNACC v1.3 rev 0.07 ASN.1 Library on SFL
files so that SNACC ASN.1 Library can be used independently of the SFL.
- Completed code to implement Ephemeral Static Diffie Hellman key management.
- Implemented and tested CMS-11 3DES and RC2 key wrap algorithms.
Updated Crypto++ and BSAFE CTILs accordingly.
- Added support for Crypto++ 3.0 C++ Classes.
- Enhanced multiple SignerInfo processing logic.
- Developed code to implement "C" API login. This simplifies application
login to SFL CTILs.
- Developing "C" API and documentation (see new SFL API document). Encrypt
and Decrypt work. Sign and Verify have been partially tested.
- Developing MLExpansionHistory processing code (ongoing).
- Performed further Memory leak testing.
- Further improvements to the RecipientInfo processing in Encrypt/Decrypt
The classes have been updated to reflect the shared UKM concept.
- KEKRecipientInfo has been implemented; limited interoperability testing
with Microsoft has been completed.
- Finalized receipt processing (receiptRequest attribute, verify creation of
receipts, and verification of receipts). Added capability to generate
multiple signerInfos in a signedReceipt.
- Created a new group of client level C++ classes for the test environment.
These new classes facilitate the test case implementation and
clearly demonstrate the use of the SFL C++ Classes.
- Developed new test code and configuration files to implement test cases.
NOTE: MS Visual C++ 6.0 is required on Windows platforms to compile
the v0.7 SFL due to linkage failures using MSVC++ 5.0.
The v0.7 SFL has been successfully used to sign, verify, encrypt and decrypt
CMS objects using the mandatory algorithms (DSA, E-S D-H, 3DES)
provided by the Crypto++ library and SHA-1 provided by Government-furnished
freeware. The v0.7 SFL has also been used to sign, verify, encrypt
and decrypt CMS objects using the RSA suite of algorithms provided by
the RSA BSAFE v3.0 library. The SFL uses the SNACC v1.3 ASN.1 Library to encode
and decode CMS signedData and envelopedData objects. The v0.7 SFL
release includes: SFL High-level library; SFL Crypto++ 3.0 Crypto Token
Interface Library (CTIL); BSAFE CTIL; VDA-enhanced GNU SNACC v1.3 rev 0.07
ASN.1 Compiler and Library; test drivers and test data.
The SFL has been successfully used to exchange signedData and envelopedData
messages with the Microsoft Internet Explorer Outlook Express v4.01 and Netscape
Communicator 4.X S/MIME v2 products. Signed messages have been exchanged
with the RSA S/MAIL, WorldTalk and Entrust S/MIME v2 products.
VDA is now performing S/MIME v3 interoperability testing with Microsoft.
Although we have made significant progress with the development of the
SFL, this interim release of the SFL is NOT complete. We are still in
the process of developing and testing the SFL. For example, we will
be enhancing the BSAFE CTIL to store the user's private keys in an
encrypted form. Further releases will be provided as significant
capabilities are added. The SFL is being delivered incrementally to
provide software as soon as possible to allow developers to: work with
the API; begin integrating the SFL into their applications; and to
provide feedback to the ongoing SFL development process. The SFL
documents and software are still being developed and are subject to
change. The goal for completion of the SFL is 31 May 1999. The
stability of the S/MIME v3 specifications is a prerequisite for
meeting this delivery goal.
Future releases will include: incorporate S/MIME specification
changes; Fortezza CTIL; Spyrus SPEX CTIL; continue "C" API development;
additional helper functions; enhance code that displays decoded messages;
MLExpansionHistory processing; countersignatures; enhanced
test routines; bug fixes; support for other crypto libraries; and
support for other operating systems. The SFL will be thoroughly
tested and all memory leaks fixed. Robustness testing will be
performed. The SFL will be tested for interoperability with S/MIME v2
and v3 products. Other possible future enhancements include additional
example CTILs supporting other Cryptographic APIs, such as Open
Group's Common Data Security Architecture. We will continue enhancing
utilities to generate certificates to be used as test data.
The IMC has established an SFL web page (http://www.imc.org/imc-sfl)
which includes links to the SFL files stored on the VDA SFL Page
(http://www.jgvandyke.com/services/infosec/sfl.htm) and on the
Fortezza Developer's S/MIME Page
(http://www.armadillo.huntsville.al.us/software/smime).
The VDA-enhanced SNACC ASN.1 software and SFL documentation are freely
available to everyone at the VDA SFL Page. All other portions of the SFL
software are export controlled in accordance with the U.S. Government Export
Administration Regulations. For specific details and guidance on
exporting the SFL software, contact the U.S. Department of Commerce,
Bureau of Export Administration, Export Counseling Division, (202)
482-4811. The Bureau of Export Administration maintains additional
resources online on its Commercial Encryption Export Controls page
(http://www.bxa.doc.gov/Encryption/Default.htm).
Instructions for applying for an account on the Fortezza Developer's
S/MIME Page are available from that page. An account is required to
download the SFL files from the Fortezza Developer's S/MIME Page due
to U.S. export restrictions.
The following SFL files are not export-controlled. They are available
at the Fortezza Developer's S/MIME Page and VDA SFL Page:
1) SFL Documents: SFL Fact Sheet, SFL Software Design Description, SFL
Application Programming Interface, SFL CTI API, SFL Software Test Description,
SFL Overview Briefing and SFL Public License.
2) snaccvda07.zip: Zip file containing SNACC v1.3 rev 0.07 ASN.1 Compiler and
Library source code compilable for Unix and MS Windows NT/95/98 that has been
enhanced by VDA to implement the Distinguished Encoding Rules.
project files and makefiles are included. This release of SNACC
does not depend on the SFL include files and libraries.
This file includes a sample test project demonstrating the use of the
SNACC classes.
The following SFL files are export controlled and are available at the
Fortezza Developer's S/MIME Page:
1) smimeR07.zip: Zip file containing all SFL source code including:
SFL Hi-Level source code; VDA-enhanced SNACC-generated ASN.1 source
code; SFL Crypto++ CTIL source code; SFL BSAFE CTIL source code;
project files. This file also contains test driver source code,
sample CMS test data and test X.509 Certificates. This file also
includes test utilities to create X.509 Certificates that each include
a D-H, DSA or RSA public key. SNACC release and debug libraries
are compiled for MS Windows NT/95/98 and Linux. MS Windows NT/95/98
project files and Unix makefiles are included for the SNACC code,
MIME++ and Crypto++. Note that the Crypto++ and MIME++ libraries are not
included. See (http://www.eskimo.com/~weidai/cryptlib.html) and
(http://hunnysoft.com/mimepp/) for these two libraries.
2) csmime.mdl contains SFL Class diagrams created using Microsoft
Visual Modeler (can be viewed using Releation Rose C++ Demo 4.0).
Not all classes are documented in the MDL file at this time.
All source code for the SFL is being provided at no cost and with no
financial limitations regarding its use and distribution.
Organizations can use the SFL without paying any royalties or
licensing fees. VDA is developing the SFL under contract to the U.S.
Government. The U.S. Government is furnishing the SFL software at no
cost to the vendor subject to the conditions of the "SFL Public
License" available from the VDA SFL Page and Fortezza Developer's
S/MIME Page.
The SFL is composed of a high-level library that performs generic CMS
and ESS processing independent of the crypto algorithms used to
protect a specific object. The SFL high-level library makes calls to
an algorithm-independent Crypto Token Interface API. The underlying,
external crypto token libraries are not distributed as part of the SFL
source code. The application developer must independently obtain these
libraries and then link them with the SFL. For example, the SFL uses
the freeware Crypto++ library to provide 3DES, D-H and DSA. To use
the SFL with Crypto++ the vendor must download the Crypto++ freeware
library from the Crypto++ Web Page and then compile it with the SFL
source code.
The SFL software is developed to maximize portability to 32-bit
operating systems. In the future, support may be added for the
following operating systems: Macintosh, HP/UX 9.x/10.x, IBM AIX 3.2,
Sun Solaris 2.6 and SCO ODT 3.0/5.0.
The IMC has established an SFL mail list which is used to: distribute
information regarding SFL releases; discuss SFL-related issues; and
provide a means for SFL users to provide feedback, comments, bug
reports, etc. Subscription information for the imc-sfl mailing list
is at the IMC web site listed above.
All comments regarding the SFL software and documents are welcome. We
recommend that comments should be sent to the imc-sfl mail list. We
will respond to all messages on that list.
=========================================================
John Pawling, Director - Systems Engineering
J.G. Van Dyke & Associates, Inc., a Wang Global Company
[email protected]
=========================================================