Re: [plasma] Plasma and File protection Question

Phillip Hallam-Baker <hallam@gmail.com> Wed, 20 April 2011 00:14 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: plasma@ietfc.amsl.com
Delivered-To: plasma@ietfc.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfc.amsl.com (Postfix) with ESMTP id 09EE0E075C for <plasma@ietfc.amsl.com>; Tue, 19 Apr 2011 17:14:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.242
X-Spam-Level:
X-Spam-Status: No, score=-3.242 tagged_above=-999 required=5 tests=[AWL=0.356, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([208.66.40.236]) by localhost (ietfc.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8Uls2PtWe7y9 for <plasma@ietfc.amsl.com>; Tue, 19 Apr 2011 17:14:24 -0700 (PDT)
Received: from mail-vw0-f44.google.com (mail-vw0-f44.google.com [209.85.212.44]) by ietfc.amsl.com (Postfix) with ESMTP id C264FE0715 for <plasma@ietf.org>; Tue, 19 Apr 2011 17:14:24 -0700 (PDT)
Received: by vws12 with SMTP id 12so207191vws.31 for <plasma@ietf.org>; Tue, 19 Apr 2011 17:14:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=C/8MmWxzSxTMX9w5sbi6kmMmXTqZZcah9w+XHtx547U=; b=uQqmQOFspWc36Uf+BuMuzM+pgidzoYqebyvVY92jcqNVCsiO9vSPPDfss0ypPxZyk+ VfE3pWJTuNaPRIcNPD3q/Yy8VQr31D9NJVtGuIUy26jFTR5V2N4Qdhvl2cKWUmSB1qop b9Ck5G2S3gz76gHQ54SD91i842UpxZZpFTN4I=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=v6qVnRqN3qYrk+sypsligC3+oXb0x16ErcnkAgF/ZL2seGGmmo/d/ZbtFA7LkecfLu X71wlrqxwCSj2dJ+sQv57q0paDHISm8AybfoGnyB3XS6TZTSEtRO+/rAKGZytu7BR0+K fSshPrwWtsi5fF1unVNhZYeTP1/YtxOx/bjdI=
MIME-Version: 1.0
Received: by 10.52.186.102 with SMTP id fj6mr5983493vdc.205.1303258464247; Tue, 19 Apr 2011 17:14:24 -0700 (PDT)
Received: by 10.52.161.3 with HTTP; Tue, 19 Apr 2011 17:14:24 -0700 (PDT)
In-Reply-To: <E545B914D50B2A4B994F198378B1525D33A00438@DF-M14-12.exchange.corp.microsoft.com>
References: <E545B914D50B2A4B994F198378B1525D33A0036D@DF-M14-12.exchange.corp.microsoft.com> <4DAE012B.9030809@cs.tcd.ie> <E545B914D50B2A4B994F198378B1525D33A00438@DF-M14-12.exchange.corp.microsoft.com>
Date: Tue, 19 Apr 2011 20:14:24 -0400
Message-ID: <BANLkTin3bq-MvwV7NzKOkynGr__+NET4+w@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Trevor Freeman <trevorf@exchange.microsoft.com>
Content-Type: multipart/alternative; boundary="bcaec5489df3cfde6704a14e8100"
Cc: "plasma@ietf.org" <plasma@ietf.org>
Subject: Re: [plasma] Plasma and File protection Question
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Apr 2011 00:14:26 -0000

OPC sounds like an appropriate container then.


On Tue, Apr 19, 2011 at 7:13 PM, Trevor Freeman <
trevorf@exchange.microsoft.com> wrote:

>  OPC = Open Packaging Convention; it’s the official standard name for zip
> files.
>
>
>
> The attraction of an OPC solution is you can protect anything just as you
> can zip anything so it would generate a universal solution.
>
>
>
> Both OOXML and ODF are widely used standards with multi-vendor support.
>   The reason to cited them as examples is that they have a documented file
> format with extension points we could use to build a solution.
>
>
>
> I doubt the OOXML\ODF thing will go away just like pkix has cmc and cmpJ
>
>
>
> Would you consider OPC a more neutral solution?
>
>
>
> -----Original Message-----
> From: Stephen Farrell [mailto:stephen.farrell@cs.tcd.ie]
> Sent: Tuesday, April 19, 2011 2:40 PM
> To: Trevor Freeman
> Cc: plasma@ietf.org
> Subject: Re: [plasma] Plasma and File protection Question
>
>
>
>
>
> I've no idea what OPC is but I'd have thought that OOXML would likely be
> controversial - or have all the word processing types made up since the
> OOXML/ODF kerfuffle [1] of a few years ago?
>
>
>
> S.
>
>
>
> [1] http://en.wikipedia.org/wiki/Office_Open_XML#Standardization_process
>
>
>
> On 19/04/11 22:19, Trevor Freeman wrote:
>
> > Having agreed that files and are the conceptually the same as email
>
> > from a policy access control perspective, there is one important
> distinction.
>
> >
>
> >
>
> >
>
> > Email has a standard mechanism to define multiple parts of a message
>
> > to represent different aspects of the message i.e. MIME.
>
> >
>
> >
>
> >
>
> > We don’t have that for files so we don’t have a simple generic way to
>
> > attach the extra metadata to a file.
>
> >
>
> >
>
> >
>
> > Some standard file formats have specific extension mechanisms we can
>
> > use e.g. OOXML which would allow you to define a way to attach the
>
> > plasma metadata to the file type in question.
>
> >
>
> >
>
> >
>
> > Alternatively there exist generic file container standards what can
>
> > hold any combination of files and data e.g. OPC which would provide a
>
> > generic solution for any file type.
>
> >
>
> >
>
> >
>
> > If we were to expand files for consideration with Plasma, which would
>
> > be the best first step, a specific solution like OOXML or a generic
>
> > solution such as OPC?
>
> >
>
> >
>
> >
>
> > *Dr Trevor Freeman*  Senior Security Strategist
>
> >
>
> > *End to End Trust Team
>
> > <http://www.microsoft.com/mscorp/twc/endtoendtrust/default.mspx>*
>
> >
>
> > *Microsoft Trustworthy
>
> > Computing<http://www.microsoft.com/mscorp/twc/default.mspx>*
>
> >
>
> >
>
> >
>
> >
>
> >
>
> > _______________________________________________
>
> > plasma mailing list
>
> > plasma@ietf.org
>
> > https://www.ietf.org/mailman/listinfo/plasma
>
> _______________________________________________
> plasma mailing list
> plasma@ietf.org
> https://www.ietf.org/mailman/listinfo/plasma
>
>


-- 
Website: http://hallambaker.com/