Re: Are certificates _required_ by the sender?

"Housley, Russ" <rhousley@rsasecurity.com> Wed, 15 May 2002 14:23 UTC

Received: from above.proper.com (mail.imc.org [208.184.76.43]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA06714 for <smime-archive@odin.ietf.org>; Wed, 15 May 2002 10:23:47 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]]) by above.proper.com (8.11.6/8.11.3) id g4FE76S23811 for ietf-smime-bks; Wed, 15 May 2002 07:07:06 -0700 (PDT)
Received: from vulcan.rsasecurity.com (mail.rsasecurity.com [204.167.114.123]) by above.proper.com (8.11.6/8.11.3) with SMTP id g4FE74L23802 for <ietf-smime@imc.org>; Wed, 15 May 2002 07:07:04 -0700 (PDT)
Received: from no.name.available by vulcan.rsasecurity.com via smtpd (for mail.imc.org [208.184.76.43]) with SMTP; 15 May 2002 14:05:24 UT
Received: from ebola.securitydynamics.com (ebola.securid.com [192.80.211.4]) by sdtihq24.securid.com (Pro-8.9.3/Pro-8.9.3) with ESMTP id KAA21830 for <ietf-smime@imc.org>; Wed, 15 May 2002 10:07:05 -0400 (EDT)
Received: from exna00.securitydynamics.com (localhost [127.0.0.1]) by ebola.securitydynamics.com (8.10.2+Sun/8.10.2) with ESMTP id g4FE5DJ11112 for <ietf-smime@imc.org>; Wed, 15 May 2002 10:05:13 -0400 (EDT)
Received: by exna00.securitydynamics.com with Internet Mail Service (5.5.2653.19) id <K2ZLC29H>; Wed, 15 May 2002 10:07:03 -0400
Received: from HOUSLEY-LAP.rsasecurity.com (HOUSLEY-LAP [10.3.16.50]) by exna00.securitydynamics.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id K2ZLC29F; Wed, 15 May 2002 10:07:01 -0400
From: "Housley, Russ" <rhousley@rsasecurity.com>
To: Terje Tollisen <tt@post.com>
Cc: ietf-smime@imc.org
Message-Id: <5.1.0.14.2.20020515100504.037a4d68@exna07.securitydynamics.com>
X-Sender: rhousley@exna07.securitydynamics.com
X-Mailer: QUALCOMM Windows Eudora Version 5.1
Date: Wed, 15 May 2002 10:06:58 -0400
Subject: Re: Are certificates _required_ by the sender?
In-Reply-To: <20020508092613.47880.qmail@mail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Terry:

To sign a message, the originator needs to have a certificate that contains 
the public key that will be used by the recipient to validate the signature.

To encrypt a message, the originator need not have a certificate; however, 
the recipient will generally not be able to authenticate the source of the 
message unless it is signed.

Russ

At 04:26 AM 5/8/2002 -0500, Terje Tollisen wrote:

>Is the sender of an email required to have a certificate, or is it 
>sufficient for the sender to have a copy of the certificate of the 
>recipient? I am thinking of an automated system, where one party will 
>always be the sender, and never receive emails. In addition, no signatures 
>are required. Thus nobody will ever actually need the public key for the 
>automated system. However, I'm uncertain if the sender can send S/MIME 
>messages without having a certificate of it's own.
>
>Thanks for your time
>-Terry Tollisen
>
>--
>_______________________________________________
>Sign-up for your own FREE Personalized E-mail at Mail.com
>http://www.mail.com/?sr=signup