[dispatch] Review of draft-campbell-sip-messaging-smime-00
Subject: [dispatch] Review of draft-campbell-sip-messaging-smime-00
Relevant comments ... I have implement S/MIME for encryption with SIP and Simple and I think this document provides some excellent clarifications and updates. I agree with the the new MTI ciphers. Overall, I think the update in this draft improves the security defined in SIMPLE and MSRP. Some random food for thought .... Getting a cert that says sip:fluffy@cisco.com signed by a LE^H^H some CA is hard. However, getting a cert that says fluffy._sip._users.cisco.com is easy and now can be highly automated. Why not allow certs that looks like that. I realize this is going to cause people to just go "that is so wrong", issues certs with the right thing. But back up for a second and ask what the hardest part of any PKI is. If th cisco.com domain issues me the email address fluffy, it is pretty easy for it to also publish the TXT records I need for domain validation with the CA. This suggestion does not relevantly reduce the security and is is pretty pragmatic. The problem is not making it hard for the bad guys, the thing we need most is making it easy for the good guys.
