RE: More on KEKIdentifiers, and a suggested addition to CMS

"Jim Schaad (Exchange)" <jimsch@EXCHANGE.MICROSOFT.com> Wed, 10 March 1999 19:32 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15902 for <smime-archive@odin.ietf.org>; Wed, 10 Mar 1999 14:32:21 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id KAA03499 for ietf-smime-bks; Wed, 10 Mar 1999 10:15:17 -0800 (PST)
Received: from dfssl.exchange.microsoft.com (dfssl.exchange.microsoft.com [131.107.88.59]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id KAA03495 for <ietf-smime@imc.org>; Wed, 10 Mar 1999 10:15:16 -0800 (PST)
Received: by dfssl.dns.microsoft.com with Internet Mail Service (5.5.2448.0) id <GM1BP88Q>; Wed, 10 Mar 1999 10:20:47 -0800
Message-ID: <2FBF98FC7852CF11912A0000000000010ECB5D9E@DINO>
From: "Jim Schaad (Exchange)" <jimsch@EXCHANGE.MICROSOFT.com>
To: "'jsp@jgvandyke.com'" <jsp@jgvandyke.com>, ietf-smime@imc.org
Cc: burt@RSA.COM
Subject: RE: More on KEKIdentifiers, and a suggested addition to CMS
Date: Wed, 10 Mar 1999 10:20:40 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Content-Type: text/plain; charset="windows-1252"
Sender: owner-ietf-smime@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

John & Peter,

At this point in time I am not willing to support this. I have two reasons
for this

1.  I want to get CMS approved, and there are other options for how to
approach this (such as a new I-D) and we know a new version of CMS is coming
soon to deal with OEAP

2.  I don't think this is the correct set of items that are needed.  You
have not proposed an appropriate set of text for section 12.  I don't
understand why the Content Encrytion Alg should be encoded twice.  I don't
understand why the KEK Wrap algorithm is not specified.  I just don't think
this is complete yet.

jim


-----Original Message-----
From: jsp@jgvandyke.com [mailto:jsp@jgvandyke.com]
Sent: Wednesday, March 10, 1999 6:34 AM
To: ietf-smime@imc.org
Cc: burt@RSA.COM
Subject: Re: More on KEKIdentifiers, and a suggested addition to CMS


Peter, Russ and friends,

Initially, I was opposed to this proposal because it adds yet more
complexity to CMS.  However, I agree with Peter that it is better to have a
clearly defined, meaningful ASN.1 syntax rather than to kludge data into an
existing syntax.  I assume that PKCS #15 is going to be widely used, so it
is worthwhile to enhance the CMS RecipientInfo syntax to include Peter's
proposed PasswordRecipientInfo CHOICE.   

I have a few comments to Peter's proposed additions to CMS:

1) Peter's proposal uses the ALGORITHM-IDENTIFIER syntax which is not part
of the 1988 ASN.1 grammar.  Many moons ago the S/MIME WG decided that the
S/MIME v3 set of specs will only use the 1988 ASN.1 grammar, so I believe
that Peter's proposal should be re-worded to eliminate use of the
ALGORITHM-IDENTIFIER syntax.

2) Recommend that "KSG" be spelled.  

3) Also, please reword the following to use 1988 ASN.1 syntax:
>>The ContentEncryptionAlgorithmIdentifier is something like:
>> 
>>      ContentEncryptionAlgorithmIdentifier ::= {
>>        { IDENTIFIED BY des-ede3-cbc },
>>        { IDENTIFIED BY rc2CBC },
>>        { IDENTIFIED BY cast5CBC },
>>        { IDENTIFIED BY rc5CBC },
>>        { IDENTIFIED BY ideaCBC },
>>        { IDENTIFIED BY desCBC },
>>        ... -- ... and anything else you can think of, eg Skipjack
>>        }


Assuming that CMS is changed to include PasswordRecipientInfo, I don't
believe that the KEKRecipientInfo kekid needs to be changed to be OPTIONAL
(as Peter also proposed) because PKCS #15 will no longer use the
KEKRecipientInfo syntax.

=========================================================
John Pawling,  Director - Systems Engineering
J.G. Van Dyke & Associates, Inc., a Wang Global Company
========================================================