Re: More on KEKIdentifiers, and a suggested addition to CMS

Paul Hoffman / IMC <phoffman@imc.org> Tue, 16 March 1999 21:12 UTC

Received: from mail.proper.com (mail.proper.com [206.86.127.224]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA14209 for <smime-archive@odin.ietf.org>; Tue, 16 Mar 1999 16:12:41 -0500 (EST)
Received: (from majordomo@localhost) by mail.proper.com (8.8.8/8.8.5) id MAA25519 for ietf-smime-bks; Tue, 16 Mar 1999 12:12:40 -0800 (PST)
Received: from aum (ts010d12.min-mn.concentric.net [209.31.113.216]) by mail.proper.com (8.8.8/8.8.5) with ESMTP id MAA25514; Tue, 16 Mar 1999 12:12:30 -0800 (PST)
Message-Id: <4.2.0.25.19990316125239.00cc49e0@mail.imc.org>
X-Sender: phoffman@mail.imc.org
X-Mailer: QUALCOMM Windows Eudora Pro Version 4.2.0.25 (Beta)
Date: Tue, 16 Mar 1999 12:56:40 -0600
To: Bruce Greenblatt <bgreenblatt@directory-applications.com>, Russ Housley <housley@spyrus.com>, ietf-smime@imc.org
From: Paul Hoffman / IMC <phoffman@imc.org>
Subject: Re: More on KEKIdentifiers, and a suggested addition to CMS
In-Reply-To: <3.0.6.32.19990316094910.007baa30@pop.walltech.com>
References: <4.1.19990313171127.009d8cc0@mail.spyrus.com> <4.2.0.29.19990311134917.0096df00@mail.imc.org> <00e901be6c2a$ded01e40$0400000a@jrwork>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: owner-ietf-smime@imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

>I have a question about this.  Are you producing a document with a known
>deficiency that you intend to correct later in the standards process?

There is a difference between a deficiency and a security flaw. The desire 
for passwords was brought up very late in the process, an indication that 
there are not pressing market needs for it. It would be nice to have, but 
there are significant technical issues, and thus Peter is proposing an 
extension to CMS.

>  It
>appears to me that making the change that has been suggested using the
>extension mechanism after it has been released as PS would likely cause CMS
>to move backwards in the standards process, and not forwards.

I don't understand why. The separate proposal does not have to be bound to 
CMS. If we want to later bind it to CMS, we can postpone going from 
Proposed Standard to Draft Standard by enough months to let the extension 
catch up. Otherwise, they can independently move to Draft Standard. Both 
are quite common in the IETF.

>  Thus, the
>whole process would be substantially delayed.

Just the opposite: there is no delay at all.

>  You're better off correcting
>the problem now with the "..." or extension mechanism or whatever as part
>of WG last call, and moving on rather than attempting to correct it later,
>and then being shifted back in the standardization process...

I respectfully disagree.


--Paul Hoffman, Director
--Internet Mail Consortium