Re: [kitten] Group/Enterprise encrypted email

Benjamin Kaduk <kaduk@MIT.EDU> Sat, 30 May 2015 00:17 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: kitten@ietfa.amsl.com
Delivered-To: kitten@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 809F51AC3AB for <kitten@ietfa.amsl.com>; Fri, 29 May 2015 17:17:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wZqH2MGb1FFM for <kitten@ietfa.amsl.com>; Fri, 29 May 2015 17:17:03 -0700 (PDT)
Received: from dmz-mailsec-scanner-6.mit.edu (dmz-mailsec-scanner-6.mit.edu [18.7.68.35]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BB4531AC3A7 for <kitten@ietf.org>; Fri, 29 May 2015 17:17:03 -0700 (PDT)
X-AuditID: 12074423-f79496d000000d43-16-5569017e1514
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-6.mit.edu (Symantec Messaging Gateway) with SMTP id F3.B0.03395.E7109655; Fri, 29 May 2015 20:17:02 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id t4U0H1TB029516; Fri, 29 May 2015 20:17:02 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t4U0Gx7o024162 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Fri, 29 May 2015 20:17:01 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t4U0GxnY023055; Fri, 29 May 2015 20:16:59 -0400 (EDT)
Date: Fri, 29 May 2015 20:16:59 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: "Nordgren, Bryce L -FS" <bnordgren@fs.fed.us>
In-Reply-To: <82E7C9A01FD0764CACDD35D10F5DFB6E7DF8C3@001FSN2MPN1-046.001f.mgd2.msft.net>
Message-ID: <alpine.GSO.1.10.1505292012130.22210@multics.mit.edu>
References: <82E7C9A01FD0764CACDD35D10F5DFB6E7DF8C3@001FSN2MPN1-046.001f.mgd2.msft.net>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrOIsWRmVeSWpSXmKPExsUixG6nrlvHmBlqcPG7lsXVNz9ZLY5uXsXi wORx+81ZFo8lS34yBTBFcdmkpOZklqUW6dslcGXs2dLKXrCVveLKH94Gxha2LkZODgkBE4mO V43sELaYxIV764HiXBxCAouZJNYtf8oIkhAS2MgoMfWMJUTiEJPEogUtTBBOA6PEpb5HQO0c HCwC2hI/mzNBGtgEVCRmvtkItkFEwFCie+kxsEHMAuoS3868AbOFBcwkXj9rAqvhFIiQ2P2i jxnE5hVwlFjbfYoNYnG4xN+tS5lAbFEBHYnV+6ewQNQISpyc+YQFYqaWxPLp21gmMArOQpKa hSS1gJFpFaNsSm6Vbm5iZk5xarJucXJiXl5qka6ZXm5miV5qSukmRnCYuijvYPxzUOkQowAH oxIPr8G19FAh1sSy4srcQ4ySHExKory7v2WECvEl5adUZiQWZ8QXleakFh9ilOBgVhLh9X8E lONNSaysSi3Kh0lJc7AoifNu+sEXIiSQnliSmp2aWpBaBJOV4eBQkuDlZsgMFRIsSk1PrUjL zClBSDNxcIIM5wEaPhOkhre4IDG3ODMdIn+KUZfjzpT/i5iEWPLy81KlxHlzQYoEQIoySvPg 5sDSyytGcaC3hHmtQap4gKkJbtIroCVMQEu+K4J8UFySiJCSamA0rpu3rf6q9tZfuz75Rc+u YChdtLLf/sV9lht1Vyf61dYGcRa1hFcGrVjp/szaNpM5ozzuR+vuNd9//X3uGerZs+uHcHJI iOuZiiCuINuNtW+PS3EsS943SdnFJOL7NMuXj7ItChfW3bykepn/7vXPzj/2zW/kDDmlWcer +2uvufk8k0tiWT5KLMUZiYZazEXFiQD1rKF4CgMAAA==
Archived-At: <http://mailarchive.ietf.org/arch/msg/kitten/9Z_uoefqWnm7X-Dp6oatGgUxFak>
Cc: "kitten@ietf.org" <kitten@ietf.org>
Subject: Re: [kitten] Group/Enterprise encrypted email
X-BeenThere: kitten@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Common Authentication Technologies - Next Generation <kitten.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/kitten>, <mailto:kitten-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/kitten/>
List-Post: <mailto:kitten@ietf.org>
List-Help: <mailto:kitten-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/kitten>, <mailto:kitten-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 30 May 2015 00:17:05 -0000

Hi Bryce,

On Fri, 29 May 2015, Nordgren, Bryce L -FS wrote:

> This is a "what if" message, centered around trying to make email
> encryption as painless as email signing. I want to be able to encrypt an
> email message once, no matter how many recipients there are. An
> enterprise should be able to decrypt employees' email to ensure there's
> no misbehavior. I want as little "extra" supporting infrastructure as
> possible. I also want to minimize the amount of inter-organizational
> coordination required.

You might have better luck on the endymail list, which is considering ways
to improve email privacy.  I don't recall whether a scheme substantially
similar to your proposal has been discussed there, but there should be a
good crop of people interested in improving the state of email to comment
there.

The endymail list was kicked off at
http://www.ietf.org/mail-archive/web/endymail/current/msg00000.html

-Ben