RE: [TLS] Please discuss: draft-housley-evidence-extns-00<

Stefan Santesson <stefans@microsoft.com> Thu, 11 January 2007 18:33 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1H54jk-0001h7-GO; Thu, 11 Jan 2007 13:33:16 -0500
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1H54ji-0001gR-J0 for tls@ietf.org; Thu, 11 Jan 2007 13:33:14 -0500
Received: from smtp-dub.microsoft.com ([213.199.138.191]) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1H54jh-0005j8-6f for tls@ietf.org; Thu, 11 Jan 2007 13:33:14 -0500
Received: from dub-exhub-c302.europe.corp.microsoft.com (65.53.213.92) by DUB-EXGWY-E801.partners.extranet.microsoft.com (10.251.129.1) with Microsoft SMTP Server (TLS) id 8.0.685.24; Thu, 11 Jan 2007 18:33:11 +0000
Received: from EA-EXMSG-C307.europe.corp.microsoft.com ([65.53.221.19]) by dub-exhub-c302.europe.corp.microsoft.com ([65.53.213.92]) with mapi; Thu, 11 Jan 2007 18:33:10 +0000
From: Stefan Santesson <stefans@microsoft.com>
To: "martin.rex@sap.com" <martin.rex@sap.com>
Date: Thu, 11 Jan 2007 18:33:08 +0000
Subject: RE: [TLS] Please discuss: draft-housley-evidence-extns-00<
Thread-Topic: [TLS] Please discuss: draft-housley-evidence-extns-00<
Thread-Index: Acc09nJXaUMxkIYVSVO/0E/w6MaxagAtzMeg
Message-ID: <A15AC0FBACD3464E95961F7C0BCD1FF01D6E0EAA@EA-EXMSG-C307.europe.corp.microsoft.com>
References: <A15AC0FBACD3464E95961F7C0BCD1FF01B064CBF@EA-EXMSG-C307.europe.corp.microsoft.com> from "Stefan Santesson" at Jan 10, 7 06:52:40 pm <200701102032.VAA12262@uw1048.wdf.sap.corp>
In-Reply-To: <200701102032.VAA12262@uw1048.wdf.sap.corp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Spam-Score: 0.5 (/)
X-Scan-Signature: 2409bba43e9c8d580670fda8b695204a
Cc: "tls@ietf.org" <tls@ietf.org>
X-BeenThere: tls@lists.ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.lists.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/tls>
List-Post: <mailto:tls@lists.ietf.org>
List-Help: <mailto:tls-request@lists.ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@lists.ietf.org?subject=subscribe>
Errors-To: tls-bounces@lists.ietf.org

> OK, I'll try to make it short:
>
> There is absolutely NONE, ZERO, NIL chance that this can be used
> in customer<->business relationsships in the European Union, because
> it is incompatible with the EU data protection directive in many ways.
>
> -Martin

Martin,

Could you elaborate in what ways this would be incompatible with the EU data protection directive?
I went over this with one of the leading Lawyers in Sweden on electronic signature implementations within the EU directives and we could not identify any significant problems.

He could see no problem with recording data during a session and save it as an audit record. Signed or not.
If there would be an issue (due to collection of personal data from the certificate etc), it could be solved by an agreement between the customer and the merchant or alternatively between the certificate holder and the CA.


Stefan Santesson
Senior Program Manager
Windows Security, Standards


_______________________________________________
TLS mailing list
TLS@lists.ietf.org
https://www1.ietf.org/mailman/listinfo/tls