Re: dissemination of public encryption certificates

Michael Helm <helm@fionn.es.net> Thu, 14 August 2003 18:27 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA21117 for <smime-archive@lists.ietf.org>; Thu, 14 Aug 2003 14:27:20 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h7EI1wqt011632 for <ietf-smime-bks@above.proper.com>; Thu, 14 Aug 2003 11:01:58 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h7EI1wiT011631 for ietf-smime-bks; Thu, 14 Aug 2003 11:01:58 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from fionn.es.net (fionn.es.net [198.128.1.30]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h7EI1uqt011626 for <ietf-smime@imc.org>; Thu, 14 Aug 2003 11:01:57 -0700 (PDT) (envelope-from helm@fionn.es.net)
Received: from fionn.es.net (localhost.es.net [127.0.0.1]) by fionn.es.net (LBNLMWH19/LBNLMWH11/ESOCF2) with ESMTP id LAA00732; Thu, 14 Aug 2003 11:01:53 -0700 (PDT)
Message-Id: <200308141801.LAA00732@fionn.es.net>
X-Authentication-Warning: fionn.es.net: Host localhost.es.net [127.0.0.1] claimed to be fionn.es.net
To: "Hallam-Baker, Phillip" <pbaker@verisign.com>
cc: 'Steve Hole' <steve.hole@messagingdirect.com>, Julien Pierre <jpierre@netscape.com>, ietf-smime@imc.org
Reply-to: helm@fionn.es.net
Subject: Re: dissemination of public encryption certificates
In-reply-to: Your message of "Thu, 14 Aug 2003 10:30:00 PDT." <2A1D4C86842EE14CA9BC80474919782E01113021@mou1wnexm02.verisign.com>
Date: Thu, 14 Aug 2003 11:01:53 -0700
From: Michael Helm <helm@fionn.es.net>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

"Hallam-Baker, Phillip" writes:
> Again, I designed XKMS to allow enterprises to define their own trust
> evaluations. One of the main considerations was how to support the Federal

> Also, obtain buy-in from the principal stakeholders whose help is required
> to achieve deployment.
> 
> That is why the answer is XKMS and not SCVP. SCVP does not have the public
> support of any of the major stakeholders. I spent a lot of time and effort
> getting buy-in from Microsoft and RSA before we announced XKMS. I worked
> with Entrust and Baltimore so that we could produce a specification that
> they could also support.
> 
> Contrast this to what the IETF mechanism achieves, OK everyone can say what
> they like. But at the end of the day you do not have the support of a major
> software vendor, just the individuals in the working group.

Leaving aside who supports what and why, don't understand the
implied conflict between xkms and scvp.  They seem to do two 
different things -- I want to find a cert for helm@fionn.es.net
to send email to that entity; I have a cert from helm@fionn.es.net --
what is it good for?  I didn't think SCVP would help much with
the first, and I clearly don't see what XKMS would do with the
second question.  Would like a better understanding of this.

Thanks, ==mwh
Michael Helm
ESnet