RE: More on KEKIdentifiers, and a suggested addition to CMS
"Jim Schaad (Exchange)" <jimsch@EXCHANGE.MICROSOFT.com> Wed, 10 March 1999 19:32 UTC
Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA15902 for <smime-archive@odin.ietf.org>; Wed, 10 Mar 1999 14:32:21 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id KAA03499 for ietf-smime-bks; Wed, 10 Mar 1999 10:15:17 -0800 (PST)
Received: from dfssl.exchange.microsoft.com (dfssl.exchange.microsoft.com [131.107.88.59]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id KAA03495 for <ietf-smime@imc.org>; Wed, 10 Mar 1999 10:15:16 -0800 (PST)
Received: by dfssl.dns.microsoft.com with Internet Mail Service (5.5.2448.0) id <GM1BP88Q>; Wed, 10 Mar 1999 10:20:47 -0800
Message-ID: <2FBF98FC7852CF11912A0000000000010ECB5D9E@DINO>
From: "Jim Schaad (Exchange)" <jimsch@EXCHANGE.MICROSOFT.com>
To: "'jsp@jgvandyke.com'" <jsp@jgvandyke.com>, ietf-smime@imc.org
Cc: burt@RSA.COM
Subject: RE: More on KEKIdentifiers, and a suggested addition to CMS
Date: Wed, 10 Mar 1999 10:20:40 -0800
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2448.0)
Content-Type: text/plain; charset="windows-1252"
Sender: owner-ietf-smime@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
John & Peter, At this point in time I am not willing to support this. I have two reasons for this 1. I want to get CMS approved, and there are other options for how to approach this (such as a new I-D) and we know a new version of CMS is coming soon to deal with OEAP 2. I don't think this is the correct set of items that are needed. You have not proposed an appropriate set of text for section 12. I don't understand why the Content Encrytion Alg should be encoded twice. I don't understand why the KEK Wrap algorithm is not specified. I just don't think this is complete yet. jim -----Original Message----- From: jsp@jgvandyke.com [mailto:jsp@jgvandyke.com] Sent: Wednesday, March 10, 1999 6:34 AM To: ietf-smime@imc.org Cc: burt@RSA.COM Subject: Re: More on KEKIdentifiers, and a suggested addition to CMS Peter, Russ and friends, Initially, I was opposed to this proposal because it adds yet more complexity to CMS. However, I agree with Peter that it is better to have a clearly defined, meaningful ASN.1 syntax rather than to kludge data into an existing syntax. I assume that PKCS #15 is going to be widely used, so it is worthwhile to enhance the CMS RecipientInfo syntax to include Peter's proposed PasswordRecipientInfo CHOICE. I have a few comments to Peter's proposed additions to CMS: 1) Peter's proposal uses the ALGORITHM-IDENTIFIER syntax which is not part of the 1988 ASN.1 grammar. Many moons ago the S/MIME WG decided that the S/MIME v3 set of specs will only use the 1988 ASN.1 grammar, so I believe that Peter's proposal should be re-worded to eliminate use of the ALGORITHM-IDENTIFIER syntax. 2) Recommend that "KSG" be spelled. 3) Also, please reword the following to use 1988 ASN.1 syntax: >>The ContentEncryptionAlgorithmIdentifier is something like: >> >> ContentEncryptionAlgorithmIdentifier ::= { >> { IDENTIFIED BY des-ede3-cbc }, >> { IDENTIFIED BY rc2CBC }, >> { IDENTIFIED BY cast5CBC }, >> { IDENTIFIED BY rc5CBC }, >> { IDENTIFIED BY ideaCBC }, >> { IDENTIFIED BY desCBC }, >> ... -- ... and anything else you can think of, eg Skipjack >> } Assuming that CMS is changed to include PasswordRecipientInfo, I don't believe that the KEKRecipientInfo kekid needs to be changed to be OPTIONAL (as Peter also proposed) because PKCS #15 will no longer use the KEKRecipientInfo syntax. ========================================================= John Pawling, Director - Systems Engineering J.G. Van Dyke & Associates, Inc., a Wang Global Company ========================================================
- More on KEKIdentifiers, and a suggested addition … Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… Russ Housley
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… Rich Ankney
- RE: More on KEKIdentifiers, and a suggested addit… Jim Schaad (Exchange)
- Re: More on KEKIdentifiers, and a suggested addit… Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… Magnus Nystrom
- Re: More on KEKIdentifiers, and a suggested addit… John Ross
- Re: More on KEKIdentifiers, and a suggested addit… Paul Hoffman / IMC
- Re: More on KEKIdentifiers, and a suggested addit… Russ Housley
- Re: More on KEKIdentifiers, and a suggested addit… Bruce Greenblatt
- Re: More on KEKIdentifiers, and a suggested addit… Paul Hoffman / IMC
- Re: More on KEKIdentifiers, and a suggested addit… Bruce Greenblatt
- Re: More on KEKIdentifiers, and a suggested addit… Russ Housley
- RE: More on KEKIdentifiers, and a suggested addit… Darren Harter
- Re: More on KEKIdentifiers, and a suggested addit… Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… John Ross
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- RE: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… ross@secstan
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… Peter Gutmann
- Re: More on KEKIdentifiers, and a suggested addit… ross@secstan
- Re: More on KEKIdentifiers, and a suggested addit… Rich Ankney
- Re: More on KEKIdentifiers, and a suggested addit… John Pawling
- Re: More on KEKIdentifiers, and a suggested addit… ross@secstan
- Re: More on KEKIdentifiers, and a suggested addit… Russ Housley