Re: Signed Receipts and Mail Lists

"Sean P. Turner" <turners@ieca.com> Tue, 24 June 2003 19:18 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA05323 for <smime-archive@lists.ietf.org>; Tue, 24 Jun 2003 15:18:19 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h5OIjErb085415 for <ietf-smime-bks@above.proper.com>; Tue, 24 Jun 2003 11:45:14 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h5OIjEJl085414 for ietf-smime-bks; Tue, 24 Jun 2003 11:45:14 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp002.bizmail.yahoo.com (smtp002.bizmail.yahoo.com [216.136.172.126]) by above.proper.com (8.12.9/8.12.8) with SMTP id h5OIiurb085400 for <ietf-smime@imc.org>; Tue, 24 Jun 2003 11:44:56 -0700 (PDT) (envelope-from turners@ieca.com)
Received: from 1cust58.tnt1.manassas.va.da.uu.net (HELO ieca.com) (turners@ieca.com@67.201.101.58 with plain) by smtp2.bm.vip.sc5.yahoo.com with SMTP; 24 Jun 2003 18:44:57 -0000
Message-ID: <3EF89A0B.4000901@ieca.com>
Date: Tue, 24 Jun 2003 14:35:55 -0400
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
CC: ietf-smime <ietf-smime@imc.org>
Subject: Re: Signed Receipts and Mail Lists
References: <001301c33a56$13ca7660$d2353fc1@nexor.co.uk>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit

Graeme,

I'm not sure that the MLA returns a receipt on behalf of the ML members. 
 I looked through ESS again and I couldn't find anything that said if a 
message enters an MLA with a signed receipt request that it shouldn't or 
should return a receipt.    Typically (I think), originators want to 
know that the final recipient got the message not whether the MLA got it.

Then again maybe I didn't understand your scenario.

spt

Graeme Lunt wrote:

>Hi,
>
>We have recently encountered an issue when trying to correlate signed
>receipts when using mail lists.
>
>Issue:
>
>When a MLA supports multiple lists using a single public/private key
>pair, it appears that there is insufficient information within a signed
>receipt generated by the MLA to determine to which recipient the signed
>receipt relates. 
>
>Take the case where a message is sent to two recipients, R1 and R2, and
>the user makes an "all" signed receipt request.
>
>R1 is actually a Mail List supported by an MLA using a single
>public/private key pair, MLA1.
>
>MLA1 receives the message for R1, expands the list, and sends a signed
>receipt "on behalf of" R1 back to the originator.
>
>The originator can identify the message to which the signed receipt
>relates (from the signedContentIdentifier) but not the recipient as the
>signature on the receipt is from MLA1. There is no way to relate this
>receipt to either R1 or R2.
>
>Possible resolution:
>
>One way to resolve this problem would be to add an extension to the
>Receipt syntax to include
>
>   ....
>   receiptFrom GeneralNames OPTIONAL
>}
>
>This field would allow the indication of whom the signed receipt was
>sent from and consequently correlation with the original recipient list.
>This also allows other scenarios where a third party may acknowledge
>receipt for a given recipient for example an assistant reading a
>managers mail. 
>
>This functionality is comparable to that of the "IPM Intended Recipient"
>field of an X.400 IPN.
>
>Also, if considering changing the Receipt structure it may be worthwhile
>adding an extension bucket at the same time (or even to support
>receiptFrom).
>
>Am I missing something?
>
>Graeme
>
>
>  
>