From owner-ietf-ediint@mail.imc.org  Wed Jun  4 08:27:01 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA14126
	for <ediint-archive@lists.ietf.org>; Wed, 4 Jun 2003 08:27:00 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h54BxZAF028263
	for <ietf-ediint-bks@above.proper.com>; Wed, 4 Jun 2003 05:02:05 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h54BxZJp028262
	for ietf-ediint-bks; Wed, 4 Jun 2003 04:59:35 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h54Bv4AF028209
	for <ietf-ediint@imc.org>; Wed, 4 Jun 2003 04:59:34 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA12811;
	Wed, 4 Jun 2003 07:57:03 -0400 (EDT)
Message-Id: <200306041157.HAA12811@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-ediint@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-ediint-as2-13.txt
Date: Wed, 04 Jun 2003 07:57:03 -0400
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Electronic Data Interchange-Internet Integration Working Group of the IETF.

	Title		: MIME-based Secure Peer-to-Peer Business Data 
                          Interchange over the Internet Using HTTP AS2
	Author(s)	: D. Moberg, R. Drummond
	Filename	: draft-ietf-ediint-as2-13.txt
	Pages		: 28
	Date		: 2003-6-3
	
This document describes how to exchange structured business
data securely using HTTP transfer for XML, Binary,
Electronic Data Interchange, (EDI - either the American
Standards Committee X12 or UN/EDIFACT,  Electronic Data
Interchange for Administration, Commerce and Transport) or
other data describable in MIME used for business to business
data interchange. The data is packaged using standard MIME
content-types. Authentication and privacy are obtained by
using Cryptographic Message Syntax (S/MIME) security body
parts. Authenticated acknowledgements make use of
multipart/signed replies to the original HTTP message.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-ediint-as2-13.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-ediint-as2-13.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-ediint-as2-13.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-6-3151216.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-ediint-as2-13.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-ediint-as2-13.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-6-3151216.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-ediint@mail.imc.org  Thu Jun  5 09:40:08 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA24736
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 09:40:07 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55DCZAF022104
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 06:12:35 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55DCZjN022103
	for ietf-ediint-bks; Thu, 5 Jun 2003 06:12:35 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from relais-int8.globalintranet.net (mailgate2.globalintranet.net [194.206.181.243])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55DCWAF022098
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 06:12:33 -0700 (PDT)
	(envelope-from lstoeckle@groupe-casino.fr)
Received: from mg21w043.siege.intra.groupe-casino.fr
          ([10.255.7.40]) by relais-int8.globalintranet.net (Netscape
          Messaging Server 4.15) with ESMTP id HG0ER701.DFH for
          <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 14:59:31 +0200 
Received: by mg21w043.siege.intra.groupe-casino.fr with Internet Mail Service (5.5.2653.19)
	id <MDV19STP>; Thu, 5 Jun 2003 14:58:21 +0100
Message-ID: <014CBC6C32FDD611BB6400D0B78F6AD7089FD7@mg21w306.siege.intra.groupe-casino.fr>
From: lstoeckle@groupe-casino.fr
To: ietf-ediint@above.proper.com
Subject: AS2-SMIME : has the certificate to be included inside the signatu
	re?
Date: Thu, 5 Jun 2003 14:58:20 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32B6A.85C8E850"
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C32B6A.85C8E850
Content-Type: text/plain

Hello,

 

I am new on this list - and I need your help.

 

AS2: when sending a signed message (the original message which can also be
signed, or a signed MDN), has the signer's certificate to be included inside
of the signature MIME part?

Is it mandatory or should AS2 compliant products accept both? (signed
messages containing the cert, or not containing it, in which case they would
try to find a certificate on the local key store etc.) 

 

Regards,

-----------------------------------------
Ludan STOECKLE
DSI Groupe Casino - Etudes

04 77 45 48 01

 <mailto:lstoeckle@groupe-casino.fr> lstoeckle@groupe-casino.fr
----------------------------------------- 

 

 


------_=_NextPart_001_01C32B6A.85C8E850
Content-Type: text/html

<html>

<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">


<meta name=Generator content="Microsoft Word 10 (filtered)">

<style>
<!--
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:#606420;
	text-decoration:underline;}
span.StyleCourrierlectronique17
	{font-family:Arial;
	color:windowtext;}
@page Section1
	{size:595.3pt 841.9pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.Section1
	{page:Section1;}
-->
</style>

</head>

<body lang=FR link=blue vlink="#606420">

<div class=Section1>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>Hello,</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>I am new on this list - and I need your help.</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>AS2: when sending a signed message (the original
message which can also be signed, or a signed MDN), has the signer's
certificate to be included inside of the signature MIME part?</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>Is it mandatory or should AS2 compliant products
accept both? (signed messages containing the cert, or not containing it, in
which case they would try to find a certificate on the local key store etc.) </span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>&nbsp;</span></font></p>

<p class=MsoNormal><font size=2 face=Arial><span lang=EN-GB style='font-size:
10.0pt;font-family:Arial'>Regards,</span></font></p>

<p class=MsoNormal><font size=2 face="Times New Roman"><span style='font-size:
10.0pt'>-----------------------------------------</span></font><br>
<b><font size=2><span style='font-size:10.0pt;font-weight:bold'>Ludan STOECKLE</span></font></b><br>
<font size=2><span style='font-size:10.0pt'>DSI Groupe Casino - Etudes</span></font></p>

<p class=MsoNormal><font size=2 face="Times New Roman"><span style='font-size:
10.0pt'>04 77 45 48 01</span></font></p>

<div>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><a href="mailto:lstoeckle@groupe-casino.fr"><font size=2><span
style='font-size:10.0pt'>lstoeckle@groupe-casino.fr</span></font></a><br>
</span></font><font size=2 color=black><span style='font-size:10.0pt;
color:black'>-----------------------------------------</span></font> </p>

</div>

<div>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'>&nbsp;</span></font></p>

</div>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'>&nbsp;</span></font></p>

</div>

</body>

</html>

------_=_NextPart_001_01C32B6A.85C8E850--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 10:00:47 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA26016
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 10:00:46 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55DcrAF022711
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 06:38:53 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55Dcr7a022710
	for ietf-ediint-bks; Thu, 5 Jun 2003 06:38:53 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from fbvmail.firstbaseventures.com ([68.152.49.195])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55DcpAF022704
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 06:38:52 -0700 (PDT)
	(envelope-from jsightler@eximtechnologies.com)
Received: from [10.1.100.8] (10.1.100.8 [10.1.100.8]) by fbvmail.firstbaseventures.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)
	id MKB7X8GG; Thu, 5 Jun 2003 09:20:15 -0400
Subject: Re: AS2-SMIME : has the certificate to be included inside the
	signatu re?
From: Jess Sightler <jsightler@eximtechnologies.com>
To: lstoeckle@groupe-casino.fr
Cc: ietf-ediint@above.proper.com
In-Reply-To: <014CBC6C32FDD611BB6400D0B78F6AD7089FD7@mg21w306.siege.intra.groupe-casino.fr>
References: 
	 <014CBC6C32FDD611BB6400D0B78F6AD7089FD7@mg21w306.siege.intra.groupe-casino.fr>
Content-Type: text/plain
Organization: Exim Technologies
Message-Id: <1054820172.12950.165.camel@localhost.localdomain>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.2.4 
Date: 05 Jun 2003 09:36:13 -0400
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> Hello,
> 
>  
> 
> I am new on this list - and I need your help.
> 
>  
> 
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
> 
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case they
> would try to find a certificate on the local key store etc.) 
> 
>  
> 
> Regards,
> 
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
> 
> 04 77 45 48 01
> 
> lstoeckle@groupe-casino.fr
> -----------------------------------------
> 
> 
>  
> 
> 
>  
-- 
=======================================
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=======================================





From owner-ietf-ediint@mail.imc.org  Thu Jun  5 11:06:54 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA00357
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 11:06:53 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55ENnAF023807
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 07:23:49 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55ENn4h023806
	for ietf-ediint-bks; Thu, 5 Jun 2003 07:23:49 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from shark.ent.gartner.com (shark.gartner.com [207.140.148.105])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h55ENlAF023801
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 07:23:47 -0700 (PDT)
	(envelope-from Wes.Rishel@gartner.com)
Received: from BobCat.ent.gartner.com ([10.1.1.84]) by puma.ent.gartner.com with Microsoft SMTPSVC(5.0.2195.5329);
	 Thu, 5 Jun 2003 10:23:47 -0400
X-MimeOLE: Produced By Microsoft Exchange V6.0.6446.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Subject: RE: AS2-SMIME : has the certificate to be included inside thesignatu re?
Date: Thu, 5 Jun 2003 10:23:46 -0400
Message-ID: <161ACA5E415AD644A50E0FCC69CF6001017FEBB4@bobcat.ent.gartner.com>
Thread-Topic: AS2-SMIME : has the certificate to be included inside thesignatu re?
Thread-Index: AcMranufE03/jNqURUuQqid60iTBTQAAfD8Q
From: "Rishel,Wes" <Wes.Rishel@gartner.com>
To: "Jess Sightler" <jsightler@eximtechnologies.com>,
        <lstoeckle@groupe-casino.fr>
Cc: <ietf-ediint@above.proper.com>
X-OriginalArrivalTime: 05 Jun 2003 14:23:47.0465 (UTC) FILETIME=[13C60F90:01C32B6E]
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h55ENmAF023802
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit


What is the benefit of sending the cert with the message? If you truly want to authenticate the originator you have to acquire the cert by independent, trusted means, don't you?

-----Original Message-----
From: owner-ietf-ediint@mail.imc.org
[mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess Sightler
Sent: Thursday, June 05, 2003 6:36 AM
To: lstoeckle@groupe-casino.fr
Cc: ietf-ediint@above.proper.com
Subject: Re: AS2-SMIME : has the certificate to be included inside
thesignatu re?



I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> Hello,
> 
>  
> 
> I am new on this list - and I need your help.
> 
>  
> 
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
> 
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case they
> would try to find a certificate on the local key store etc.) 
> 
>  
> 
> Regards,
> 
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
> 
> 04 77 45 48 01
> 
> lstoeckle@groupe-casino.fr
> -----------------------------------------
> 
> 
>  
> 
> 
>  
-- 
=======================================
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=======================================






From owner-ietf-ediint@mail.imc.org  Thu Jun  5 11:22:50 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA02262
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 11:22:49 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55EvYAF026471
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 07:57:34 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55EvYkT026470
	for ietf-ediint-bks; Thu, 5 Jun 2003 07:57:34 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from fbvmail.firstbaseventures.com ([68.152.49.195])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55EvXAF026460
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 07:57:33 -0700 (PDT)
	(envelope-from jsightler@eximtechnologies.com)
Received: from [10.1.100.8] (10.1.100.8 [10.1.100.8]) by fbvmail.firstbaseventures.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)
	id MKB7X824; Thu, 5 Jun 2003 10:38:56 -0400
Subject: RE: AS2-SMIME : has the certificate to be included inside
	thesignatu re?
From: Jess Sightler <jsightler@eximtechnologies.com>
To: "Rishel,Wes" <Wes.Rishel@gartner.com>
Cc: lstoeckle@groupe-casino.fr, ietf-ediint@above.proper.com
In-Reply-To: <161ACA5E415AD644A50E0FCC69CF6001017FEBB4@bobcat.ent.gartner.com>
References: 
	 <161ACA5E415AD644A50E0FCC69CF6001017FEBB4@bobcat.ent.gartner.com>
Content-Type: text/plain
Organization: Exim Technologies
Message-Id: <1054824894.12950.180.camel@localhost.localdomain>
Mime-Version: 1.0
X-Mailer: Ximian Evolution 1.2.4 
Date: 05 Jun 2003 10:54:54 -0400
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


I was primarily thinking to do so, because it seems like it is standard
convention with S/MIME to do that when used for email.

Anyway, as a side thought, of course, one certificate has to be acquired
through an independent, trusted means.  However, that certificate does
not necessarily have to be the certificate used for signing the message.

Ie, couldn't the trusted Cert be a signing authority, and the message
itself come with a separate Cert signed by that authority?

Thanks,
Jess


On Thu, 2003-06-05 at 10:23, Rishel,Wes wrote:
> What is the benefit of sending the cert with the message? If you truly want to authenticate the originator you have to acquire the cert by independent, trusted means, don't you?
> 
> -----Original Message-----
> From: owner-ietf-ediint@mail.imc.org
> [mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess Sightler
> Sent: Thursday, June 05, 2003 6:36 AM
> To: lstoeckle@groupe-casino.fr
> Cc: ietf-ediint@above.proper.com
> Subject: Re: AS2-SMIME : has the certificate to be included inside
> thesignatu re?
> 
> 
> 
> I can't speak 100% from the spec on this, but I know that iSoft makes
> sending the Certificate with a signature optional.
> 
> Based on that, I believe that it is an option to not send the cert.  I
> believe that sending the Cert would be a good practice, however.
> 
> Thanks,
> Jess
> 
> 
> On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> > Hello,
> > 
> >  
> > 
> > I am new on this list - and I need your help.
> > 
> >  
> > 
> > AS2: when sending a signed message (the original message which can
> > also be signed, or a signed MDN), has the signer's certificate to be
> > included inside of the signature MIME part?
> > 
> > Is it mandatory or should AS2 compliant products accept both? (signed
> > messages containing the cert, or not containing it, in which case they
> > would try to find a certificate on the local key store etc.) 
> > 
> >  
> > 
> > Regards,
> > 
> > -----------------------------------------
> > Ludan STOECKLE
> > DSI Groupe Casino - Etudes
> > 
> > 04 77 45 48 01
> > 
> > lstoeckle@groupe-casino.fr
> > -----------------------------------------
> > 
> > 
> >  
> > 
> > 
> >  
-- 
=======================================
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=======================================





From owner-ietf-ediint@mail.imc.org  Thu Jun  5 11:54:13 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA04381
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 11:54:13 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55FVRAF027395
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 08:31:27 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55FVRAJ027394
	for ietf-ediint-bks; Thu, 5 Jun 2003 08:31:27 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from spyglass.cyclonecommerce.com (spyglass.cyclonecommerce.com [12.34.72.100])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h55FVQAF027384
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 08:31:26 -0700 (PDT)
	(envelope-from dmoberg@cyclonecommerce.com)
Received: from SEMINOLEVS1.cyclonecommerce.com ([10.1.0.20])
 by spyglass.cyclonecommerce.com (NAVGW 2.5.1.13) with SMTP id M2003060508290600660
 ; Thu, 05 Jun 2003 08:29:06 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32B77.33BE0704"
Subject: RE: AS2-SMIME : has the certificate to be included inside the signature?
Date: Thu, 5 Jun 2003 08:29:06 -0700
Message-ID: <9551E76040A2604BBD331F3024BFEA48EF6276@SEMINOLEVS2.cyclonecommerce.com>
Thread-Topic: AS2-SMIME : has the certificate to be included inside the signature?
Thread-Index: AcMrZkBuv3kLcbQqSu24Ch0CzBjO9gADKt1A
From: "Dale Moberg" <dmoberg@cyclonecommerce.com>
To: <lstoeckle@groupe-casino.fr>, <ietf-ediint@above.proper.com>
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This is a multi-part message in MIME format.

------_=_NextPart_001_01C32B77.33BE0704
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

PKCS7/CMS always has a the issuer serial number to identify and retrieve
a certificate (from a local store or whatever) so that it is not
essential to include a certificate or certificate chain.=20
=20
While it is normal to check or verify signer certificate validity with
respect to a site's trusted roots no matter how a certificate is
retrieved (so including or not including a certificate is not a security
gap), two considerations point to opposite conclusions on including the
certificate/certificate chain. First, saving bandwidth favors omitting
the certificate and chain.  Second, having the certificates in the
message may for some implementations speed up some message processing
operations.=20
=20
An application should be able to deal with either case.=20
 RFC 2633 is the operative RFC that is cited in AS2 and should also be
consulted.
 See for example section 3.7 which says:
=20
  A sending agent that signs messages MUST have a certificate for the
   signature so that a receiving agent can verify the signature. There
   are many ways of getting certificates, such as through an exchange
   with a certificate authority, through a hardware token or diskette,
   and so on.
=20
   S/MIME v2 [SMIMEV2] specified a method for "registering" public keys
   with certificate authorities using an application/pkcs10 body part.
   The IETF's PKIX Working Group is preparing another method for
   requesting certificates; however, that work was not finished at the
   time of this memo. S/MIME v3 does not specify how to request a
=20
   certificate, but instead mandates that every sending agent already
   has a certificate. Standardization of certificate management is being
   pursued separately in the IETF.
=20
And between 1999,  when that was published, and now, the situation
remains about the same on PKI setup, alignment, and maintenance.

So, if you are an implementer, do not depend on receiving a cert chain
in the message whose signature you will be checking.
As far as sending certificates, implementers might be well advised to be
able to configure their software to either include or omit.
The choice of a default behavior is not specified in AS2. But the motto
"Be conservative in what you send, liberal in what you can receive"
probably favors including the cert chain, and then allowing an
optimization to omit for bandwidth conservation where it is not
necessary.
=20
=20
=20
=20

	-----Original Message-----
	From: lstoeckle@groupe-casino.fr
[mailto:lstoeckle@groupe-casino.fr]=20
	Sent: Thursday, June 05, 2003 6:58 AM
	To: ietf-ediint@above.proper.com
	Subject: AS2-SMIME : has the certificate to be included inside
the signature?
=09
=09

	Hello,

	=20

	I am new on this list - and I need your help.

	=20

	AS2: when sending a signed message (the original message which
can also be signed, or a signed MDN), has the signer's certificate to be
included inside of the signature MIME part?

	Is it mandatory or should AS2 compliant products accept both?
(signed messages containing the cert, or not containing it, in which
case they would try to find a certificate on the local key store etc.)=20

	=20

	Regards,

	-----------------------------------------
	Ludan STOECKLE
	DSI Groupe Casino - Etudes

	04 77 45 48 01

	lstoeckle@groupe-casino.fr <mailto:lstoeckle@groupe-casino.fr>=20
	-----------------------------------------=20

	=20

	=20


------_=_NextPart_001_01C32B77.33BE0704
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Message</TITLE>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2800.1170" name=3DGENERATOR>
<STYLE>@page Section1 {size: 595.3pt 841.9pt; margin: 70.85pt 70.85pt =
70.85pt 70.85pt; }
P.MsoNormal {
	FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
LI.MsoNormal {
	FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
DIV.MsoNormal {
	FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman"
}
A:link {
	COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlink {
	COLOR: blue; TEXT-DECORATION: underline
}
A:visited {
	COLOR: #606420; TEXT-DECORATION: underline
}
SPAN.MsoHyperlinkFollowed {
	COLOR: #606420; TEXT-DECORATION: underline
}
SPAN.StyleCourrierlectronique17 {
	COLOR: windowtext; FONT-FAMILY: Arial
}
DIV.Section1 {
	page: Section1
}
</STYLE>
</HEAD>
<BODY lang=3DFR vLink=3D#606420 link=3Dblue>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>PKCS7/CMS always has a the issuer serial number to identify=20
and&nbsp;retrieve a certificate (from a local store or whatever) so that =
it is=20
not&nbsp;essential to include a certificate or certificate chain.=20
</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>While=20
it is normal to check or verify signer certificate validity with respect =
to a=20
site's trusted roots&nbsp;no matter how&nbsp;a certificate is retrieved =
(so=20
including or not including a certificate is not a security gap), two=20
considerations point to opposite conclusions on including the=20
certificate/certificate chain. First, saving =
bandwidth&nbsp;favors&nbsp;omitting=20
the certificate and chain.&nbsp; Second,&nbsp;having the certificates in =
the=20
message&nbsp;may for some implementations speed up some message =
processing=20
operations.&nbsp;</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>An=20
application should&nbsp;be able to deal with either=20
case.&nbsp;</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003>&nbsp;<FONT face=3DArial =
color=3D#0000ff=20
size=3D2>RFC 2633 is the operative RFC that is cited in =
AS2&nbsp;and&nbsp;should=20
also be&nbsp;consulted.</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>&nbsp;See for example section 3.7 which =
says:</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>&nbsp;=20
A sending agent that signs messages MUST have a certificate for=20
the<BR>&nbsp;&nbsp; signature so that a receiving agent can verify the=20
signature. There<BR>&nbsp;&nbsp; are many ways of getting certificates, =
such as=20
through an exchange<BR>&nbsp;&nbsp; with a certificate authority, =
through a=20
hardware token or diskette,<BR>&nbsp;&nbsp; and so =
on.</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>&nbsp;&nbsp; S/MIME v2 [SMIMEV2] specified a method for =
"registering"=20
public keys<BR>&nbsp;&nbsp; with certificate authorities using an=20
application/pkcs10 body part.<BR>&nbsp;&nbsp; The IETF's PKIX Working =
Group is=20
preparing another method for<BR>&nbsp;&nbsp; requesting certificates; =
however,=20
that work was not finished at the<BR>&nbsp;&nbsp; time of this memo. =
S/MIME v3=20
does not specify how to request a</FONT></SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>&nbsp;&nbsp; certificate, but instead mandates that every =
sending agent=20
already<BR>&nbsp;&nbsp; has a certificate. Standardization of =
certificate=20
management is being<BR>&nbsp;&nbsp; pursued separately in the=20
IETF.</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>And&nbsp;between 1999,&nbsp; when that was published, and now, =
the=20
situation remains about the same on PKI setup, alignment,&nbsp;and=20
maintenance.</DIV>
<DIV><BR></DIV></FONT></SPAN>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>So, if=20
you are an implementer, do not depend on receiving a cert chain in the =
message=20
whose signature you will be checking.</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>As far=20
as sending certificates, implementers might be well advised to be able =
to=20
configure their software to either include or omit.</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =
size=3D2>The=20
choice of a default behavior is not specified in AS2. But the motto "Be=20
conservative in what you send, liberal in what you can=20
receive"</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>probably favors including the cert chain, and then allowing an=20
optimization to omit for bandwidth conservation where it is not=20
necessary.</FONT></SPAN></DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>&nbsp;</DIV></FONT></SPAN>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D037285814-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>&nbsp;</DIV></FONT></SPAN>
<BLOCKQUOTE dir=3Dltr style=3D"MARGIN-RIGHT: 0px">
  <DIV></DIV>
  <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr =
align=3Dleft><FONT=20
  face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B>=20
  lstoeckle@groupe-casino.fr [mailto:lstoeckle@groupe-casino.fr]=20
  <BR><B>Sent:</B> Thursday, June 05, 2003 6:58 AM<BR><B>To:</B>=20
  ietf-ediint@above.proper.com<BR><B>Subject:</B> AS2-SMIME : has the=20
  certificate to be included inside the signature?<BR><BR></FONT></DIV>
  <DIV class=3DSection1>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Hello,</SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT>&nbsp;</P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">I am new on this list - =
and I need=20
  your help.</SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT>&nbsp;</P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">AS2: when sending a =
signed message=20
  (the original message which can also be signed, or a signed MDN), has =
the=20
  signer's certificate to be included inside of the signature MIME=20
  part?</SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial">Is it mandatory or =
should AS2=20
  compliant products accept both? (signed messages containing the cert, =
or not=20
  containing it, in which case they would try to find a certificate on =
the local=20
  key store etc.) </SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: Arial"></SPAN></FONT>&nbsp;</P>
  <P class=3DMsoNormal><FONT face=3DArial size=3D2><SPAN lang=3DEN-GB=20
  style=3D"FONT-SIZE: 10pt; FONT-FAMILY: =
Arial">Regards,</SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D2><SPAN=20
  style=3D"FONT-SIZE: =
10pt">-----------------------------------------</SPAN></FONT><BR><B><FONT=
=20
  size=3D2><SPAN style=3D"FONT-WEIGHT: bold; FONT-SIZE: 10pt">Ludan=20
  STOECKLE</SPAN></FONT></B><BR><FONT size=3D2><SPAN style=3D"FONT-SIZE: =
10pt">DSI=20
  Groupe Casino - Etudes</SPAN></FONT></P>
  <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D2><SPAN=20
  style=3D"FONT-SIZE: 10pt">04 77 45 48 01</SPAN></FONT></P>
  <DIV>
  <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20
  style=3D"FONT-SIZE: 12pt"><A =
href=3D"mailto:lstoeckle@groupe-casino.fr"><FONT=20
  size=3D2><SPAN=20
  style=3D"FONT-SIZE: =
10pt">lstoeckle@groupe-casino.fr</SPAN></FONT></A><BR></SPAN></FONT><FONT=
=20
  color=3Dblack size=3D2><SPAN=20
  style=3D"FONT-SIZE: 10pt; COLOR: =
black">-----------------------------------------</SPAN></FONT>=20
  </P></DIV>
  <DIV>
  <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20
  style=3D"FONT-SIZE: 12pt"></SPAN></FONT>&nbsp;</P></DIV>
  <P class=3DMsoNormal><FONT face=3D"Times New Roman" size=3D3><SPAN=20
  style=3D"FONT-SIZE: =
12pt"></SPAN></FONT>&nbsp;</P></DIV></BLOCKQUOTE></BODY></HTML>
=00
------_=_NextPart_001_01C32B77.33BE0704--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 12:29:48 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA05478
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 12:29:48 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55G4oAF031759
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 09:04:50 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55G4oPP031758
	for ietf-ediint-bks; Thu, 5 Jun 2003 09:04:50 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from d06lmsgate-2.uk.ibm.com ([195.212.29.2])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55G4mAF031534
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 09:04:48 -0700 (PDT)
	(envelope-from paulfordh@uk.ibm.com)
Received: from d06relay02.portsmouth.uk.ibm.com (d06relay02.uk.ibm.com [9.166.84.148])
	by d06lmsgate-2.uk.ibm.com (8.12.9/8.12.8) with ESMTP id h55G3WCK019598;
	Thu, 5 Jun 2003 17:03:33 +0100
Received: from d06ml035.portsmouth.uk.ibm.com (d06ml035_cs0 [9.180.35.16])
	by d06relay02.portsmouth.uk.ibm.com (8.12.9/NCO/VER6.5) with ESMTP id h55G0rM9051674;
	Thu, 5 Jun 2003 17:02:15 +0100
To: "Rishel,Wes" <Wes.Rishel@gartner.com>
Cc: <ietf-ediint@above.proper.com>
MIME-Version: 1.0
Subject: RE: AS2-SMIME : has the certificate to be included inside thesignatu re?
X-Mailer: Lotus Notes Release 5.0.7  March 21, 2001
From: "Paul V Ford-Hutchinson" <paulfordh@uk.ibm.com>
Message-ID: <OF1D20B103.78671625-ON80256D3C.005612A3@portsmouth.uk.ibm.com>
Date: Thu, 5 Jun 2003 17:02:13 +0100
X-MIMETrack: Serialize by Router on D06ML035/06/M/IBM(Release 5.0.9a |January 7, 2002) at
 05/06/2003 17:02:14,
	Serialize complete at 05/06/2003 17:02:14
Content-Type: multipart/alternative; boundary="=_alternative 0058054180256D3C_="
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This is a multipart message in MIME format.
--=_alternative 0058054180256D3C_=
Content-Type: text/plain; charset="us-ascii"

No , that's one of the main points of X.509 certificates.

[Unless you are discussing self-signed certificates (the X.509 equivalent 
of "trust me, because I say so - signed me")]

so .....

Is there a published way for an AS-2 implementation to map the "AS2-From" 
field to an X.509 DN ?
Or does AS2 assume that there is always some OOB mechanism for 
establishing identity (AS2-To/From) to certificate mappings ?

If the former - who needs to bloat messages with certificates?
If the latter - why ?

Paul
--
Paul Ford-Hutchinson :  eCommerce application security : 
paulfordh@uk.ibm.com
MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 
462005
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html





"Rishel,Wes" <Wes.Rishel@gartner.com>
Sent by: owner-ietf-ediint@mail.imc.org
05/06/2003 15:23

 
        To:     "Jess Sightler" <jsightler@eximtechnologies.com>, 
<lstoeckle@groupe-casino.fr>
        cc:     <ietf-ediint@above.proper.com>
        Subject:        RE: AS2-SMIME : has the certificate to be included inside thesignatu re?

 



What is the benefit of sending the cert with the message? If you truly 
want to authenticate the originator you have to acquire the cert by 
independent, trusted means, don't you?

-----Original Message-----
From: owner-ietf-ediint@mail.imc.org
[mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess Sightler
Sent: Thursday, June 05, 2003 6:36 AM
To: lstoeckle@groupe-casino.fr
Cc: ietf-ediint@above.proper.com
Subject: Re: AS2-SMIME : has the certificate to be included inside
thesignatu re?



I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> Hello,
>
>
>
> I am new on this list - and I need your help.
>
>
>
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
>
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case they
> would try to find a certificate on the local key store etc.)
>
>
>
> Regards,
>
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
>
> 04 77 45 48 01
>
> lstoeckle@groupe-casino.fr
> -----------------------------------------
>
>
>
>
>
>
--
=======================================
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=======================================






--=_alternative 0058054180256D3C_=
Content-Type: text/html; charset="us-ascii"


<br><font size=2 face="sans-serif">No , that's one of the main points of X.509 certificates.</font>
<br>
<br><font size=2 face="sans-serif">[Unless you are discussing self-signed certificates (the X.509 equivalent of &quot;trust me, because I say so - signed me&quot;)]</font>
<br>
<br><font size=2 face="sans-serif">so .....</font>
<br>
<br><font size=2 face="sans-serif">Is there a published way for an AS-2 implementation to map the &quot;AS2-From&quot; field to an X.509 DN ?</font>
<br><font size=2 face="sans-serif">Or does AS2 assume that there is always some OOB mechanism for establishing identity (AS2-To/From) to certificate mappings ?</font>
<br>
<br><font size=2 face="sans-serif">If the former - who needs to bloat messages with certificates?</font>
<br><font size=2 face="sans-serif">If the latter - why ?</font>
<br>
<br><font size=2 face="sans-serif">Paul<br>
--<br>
Paul Ford-Hutchinson : &nbsp;eCommerce application security : paulfordh@uk.ibm.com<br>
MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 462005<br>
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html<br>
</font>
<br>
<br>
<br>
<table width=100%>
<tr valign=top>
<td>
<td><font size=1 face="sans-serif"><b>&quot;Rishel,Wes&quot; &lt;Wes.Rishel@gartner.com&gt;</b></font>
<br><font size=1 face="sans-serif">Sent by: owner-ietf-ediint@mail.imc.org</font>
<p><font size=1 face="sans-serif">05/06/2003 15:23</font>
<br>
<td><font size=1 face="Arial">&nbsp; &nbsp; &nbsp; &nbsp; </font>
<br><font size=1 face="sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; To: &nbsp; &nbsp; &nbsp; &nbsp;&quot;Jess Sightler&quot; &lt;jsightler@eximtechnologies.com&gt;, &lt;lstoeckle@groupe-casino.fr&gt;</font>
<br><font size=1 face="sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; cc: &nbsp; &nbsp; &nbsp; &nbsp;&lt;ietf-ediint@above.proper.com&gt;</font>
<br><font size=1 face="sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; Subject: &nbsp; &nbsp; &nbsp; &nbsp;RE: AS2-SMIME : has the certificate to be included inside thesignatu re?</font>
<br>
<br><font size=1 face="Arial">&nbsp; &nbsp; &nbsp; &nbsp;</font></table>
<br>
<br>
<br>
<br><font size=2><tt>What is the benefit of sending the cert with the message? If you truly want to authenticate the originator you have to acquire the cert by independent, trusted means, don't you?<br>
</tt></font>
<br><font size=2><tt>-----Original Message-----<br>
From: owner-ietf-ediint@mail.imc.org<br>
[mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess Sightler<br>
Sent: Thursday, June 05, 2003 6:36 AM<br>
To: lstoeckle@groupe-casino.fr<br>
Cc: ietf-ediint@above.proper.com<br>
Subject: Re: AS2-SMIME : has the certificate to be included inside<br>
thesignatu re?<br>
</tt></font>
<br>
<br>
<br><font size=2><tt>I can't speak 100% from the spec on this, but I know that iSoft makes<br>
sending the Certificate with a signature optional.<br>
</tt></font>
<br><font size=2><tt>Based on that, I believe that it is an option to not send the cert. &nbsp;I<br>
believe that sending the Cert would be a good practice, however.<br>
</tt></font>
<br><font size=2><tt>Thanks,<br>
Jess<br>
</tt></font>
<br>
<br><font size=2><tt>On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:<br>
&gt; Hello,<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; I am new on this list - and I need your help.<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; AS2: when sending a signed message (the original message which can<br>
&gt; also be signed, or a signed MDN), has the signer's certificate to be<br>
&gt; included inside of the signature MIME part?<br>
&gt;<br>
&gt; Is it mandatory or should AS2 compliant products accept both? (signed<br>
&gt; messages containing the cert, or not containing it, in which case they<br>
&gt; would try to find a certificate on the local key store etc.)<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; Regards,<br>
&gt;<br>
&gt; -----------------------------------------<br>
&gt; Ludan STOECKLE<br>
&gt; DSI Groupe Casino - Etudes<br>
&gt;<br>
&gt; 04 77 45 48 01<br>
&gt;<br>
&gt; lstoeckle@groupe-casino.fr<br>
&gt; -----------------------------------------<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
--<br>
=======================================<br>
Jess Sightler<br>
Senior Developer<br>
Exim Technologies<br>
131 Falls Street<br>
Greenville SC 29601<br>
Phone: 864-679-4651<br>
=======================================<br>
</tt></font>
<br>
<br>
<br>
<br>
<br>
--=_alternative 0058054180256D3C_=--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 12:52:30 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA06085
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 12:52:29 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55GT1AF033048
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 09:29:02 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55GT1xu033047
	for ietf-ediint-bks; Thu, 5 Jun 2003 09:29:01 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from spyglass.cyclonecommerce.com (spyglass.cyclonecommerce.com [12.34.72.100])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h55GT0AF033041
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 09:29:00 -0700 (PDT)
	(envelope-from dmoberg@cyclonecommerce.com)
Received: from SEMINOLEVS1.cyclonecommerce.com ([10.1.0.20])
 by spyglass.cyclonecommerce.com (NAVGW 2.5.1.13) with SMTP id M2003060509290908702
 ; Thu, 05 Jun 2003 09:29:09 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.0.6249.0
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32B7F.974C14F0"
Subject: RE: AS2-SMIME : has the certificate to be included inside thesignatu re?
Date: Thu, 5 Jun 2003 09:29:09 -0700
Message-ID: <9551E76040A2604BBD331F3024BFEA48EF6278@SEMINOLEVS2.cyclonecommerce.com>
Thread-Topic: AS2-SMIME : has the certificate to be included inside thesignatu re?
Thread-Index: AcMrfYcZeg+kLUzsRmy7YG3WdIF7sgAAJYUw
From: "Dale Moberg" <dmoberg@cyclonecommerce.com>
To: "Paul V Ford-Hutchinson" <paulfordh@uk.ibm.com>,
        "Rishel,Wes" <Wes.Rishel@gartner.com>
Cc: <ietf-ediint@above.proper.com>
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This is a multi-part message in MIME format.

------_=_NextPart_001_01C32B7F.974C14F0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Response or two in line.

	-----Original Message-----
	From: Paul V Ford-Hutchinson [mailto:paulfordh@uk.ibm.com]=20
	Sent: Thursday, June 05, 2003 9:02 AM
	To: Rishel,Wes
	Cc: ietf-ediint@above.proper.com
	Subject: RE: AS2-SMIME : has the certificate to be included
inside thesignatu re?
=09
=09

	No , that's one of the main points of X.509 certificates.=20
=09
	[Unless you are discussing self-signed certificates (the X.509
equivalent of "trust me, because I say so - signed me")]=20
=09
	so .....=20
=09
	Is there a published way for an AS-2 implementation to map the
"AS2-From" field to an X.509 DN ? =20
	=20
	Not in IETF spec. Maybe someone has profiled AS2 for some
community/vertical but I have not heard of one.
	=20
	Or does AS2 assume that there is always some OOB mechanism for
establishing identity (AS2-To/From) to certificate mappings ? =20
	=20
	SMIME/CMS/PKCS7 has in its SignerInfo structure fields that
allow determination of the relevant signature used in producing the
signature.
	So the value for the AS2-From field is not involved in finding
the certificate. Actually, the AS2-From value should not be considered a
highly trusted piece of information-- no signature over it. Generally
spoofing would be a lot harder if you use SSL though.=20
=09
	If the former - who needs to bloat messages with certificates? =20
	AS2 follows the CMS/PKCS7 approach on identifying the
certificate used in signing.  So you are right, cert chain can be
omitted.
	If the latter - why ? =20
	=20
	Not applicable. If there were a mapping, then people might
wonder what to do if the AS2-from value did not match up with the X.509
DN.
	Should we discard the whole thing?=20
	=20
	We avoid this. What we have now is that the signed info is what
counts only. So trust that the payload is OK if you accept the signature
as one that checks out with respect to a certificate that chains up to
one of your trust anchors (which will be itself if using self-signed
certs.)=20
	=20
	Dale=20
=09
	Paul
	--
	Paul Ford-Hutchinson :  eCommerce application security :
paulfordh@uk.ibm.com
	MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44
(0)1926 462005
	http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html
=09
=09
=09
=09
	"Rishel,Wes" <Wes.Rishel@gartner.com>=20
Sent by: owner-ietf-ediint@mail.imc.org=20

05/06/2003 15:23=20


       =20
        To:        "Jess Sightler" <jsightler@eximtechnologies.com>,
<lstoeckle@groupe-casino.fr>=20
        cc:        <ietf-ediint@above.proper.com>=20
        Subject:        RE: AS2-SMIME : has the certificate to be
included inside thesignatu re?=20

      =20




	What is the benefit of sending the cert with the message? If you
truly want to authenticate the originator you have to acquire the cert
by independent, trusted means, don't you?
=09
	-----Original Message-----
	From: owner-ietf-ediint@mail.imc.org
	[mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess
Sightler
	Sent: Thursday, June 05, 2003 6:36 AM
	To: lstoeckle@groupe-casino.fr
	Cc: ietf-ediint@above.proper.com
	Subject: Re: AS2-SMIME : has the certificate to be included
inside
	thesignatu re?
=09
=09
=09
	I can't speak 100% from the spec on this, but I know that iSoft
makes
	sending the Certificate with a signature optional.
=09
	Based on that, I believe that it is an option to not send the
cert.  I
	believe that sending the Cert would be a good practice, however.
=09
	Thanks,
	Jess
=09
=09
	On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
	> Hello,
	>
	>
	>
	> I am new on this list - and I need your help.
	>
	>
	>
	> AS2: when sending a signed message (the original message which
can
	> also be signed, or a signed MDN), has the signer's certificate
to be
	> included inside of the signature MIME part?
	>
	> Is it mandatory or should AS2 compliant products accept both?
(signed
	> messages containing the cert, or not containing it, in which
case they
	> would try to find a certificate on the local key store etc.)
	>
	>
	>
	> Regards,
	>
	> -----------------------------------------
	> Ludan STOECKLE
	> DSI Groupe Casino - Etudes
	>
	> 04 77 45 48 01
	>
	> lstoeckle@groupe-casino.fr
	> -----------------------------------------
	>
	>
	>
	>
	>
	>
	--
	=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
	Jess Sightler
	Senior Developer
	Exim Technologies
	131 Falls Street
	Greenville SC 29601
	Phone: 864-679-4651
	=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
=09
=09
=09
=09
=09
=09


------_=_NextPart_001_01C32B7F.974C14F0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Message</TITLE>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2800.1170" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D220351816-05062003><FONT face=3DArial color=3D#0000ff =

size=3D2>Response or two in line.</FONT></SPAN></DIV>
<BLOCKQUOTE style=3D"MARGIN-RIGHT: 0px">
  <DIV></DIV>
  <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr =
align=3Dleft><FONT=20
  face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B> Paul =
V=20
  Ford-Hutchinson [mailto:paulfordh@uk.ibm.com] <BR><B>Sent:</B> =
Thursday, June=20
  05, 2003 9:02 AM<BR><B>To:</B> Rishel,Wes<BR><B>Cc:</B>=20
  ietf-ediint@above.proper.com<BR><B>Subject:</B> RE: AS2-SMIME : has =
the=20
  certificate to be included inside thesignatu re?<BR><BR></FONT></DIV>
  <DIV><BR><FONT face=3Dsans-serif size=3D2>No , that's one of the main =
points of=20
  X.509 certificates.</FONT> <BR><BR><FONT face=3Dsans-serif =
size=3D2>[Unless you=20
  are discussing self-signed certificates (the X.509 equivalent of =
"trust me,=20
  because I say so - signed me")]</FONT> <BR><BR><FONT face=3Dsans-serif =
size=3D2>so=20
  .....</FONT> <BR><BR><FONT face=3Dsans-serif size=3D2>Is there a =
published way for=20
  an AS-2 implementation to map the "AS2-From" field to an X.509 DN=20
  ?</FONT>&nbsp;<SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2>&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff size=3D2>Not=20
  in IETF spec. Maybe someone has profiled AS2 for some =
community/vertical but I=20
  have not heard of one.</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003>&nbsp;</SPAN><BR><FONT =
face=3Dsans-serif=20
  size=3D2>Or does AS2 assume that there is always some OOB mechanism =
for=20
  establishing identity (AS2-To/From) to certificate mappings=20
  ?</FONT>&nbsp;<SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2>&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2>SMIME/CMS/PKCS7 has in its&nbsp;SignerInfo structure fields =
that allow=20
  determination of the&nbsp;relevant signature used =
in&nbsp;producing&nbsp;the=20
  signature.</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff size=3D2>So=20
  the value&nbsp;for the AS2-From field is not involved in&nbsp;finding =
the=20
  certificate. Actually, the AS2-From value should not be considered a =
highly=20
  trusted piece of information-- no signature over it. Generally =
spoofing would=20
  be a lot harder if you use SSL though. </FONT></SPAN><BR><BR><FONT=20
  face=3Dsans-serif size=3D2>If the former - who needs to bloat messages =
with=20
  certificates?</FONT>&nbsp;<SPAN class=3D220351816-05062003><FONT =
face=3DArial=20
  color=3D#0000ff size=3D2>&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff size=3D2>AS2=20
  follows the CMS/PKCS7 approach on&nbsp;identifying the certificate =
used in=20
  signing.</FONT>&nbsp;<FONT face=3DArial color=3D#0000ff size=3D2> So =
you are right,=20
  cert chain&nbsp;can be omitted.</FONT></SPAN><BR><FONT =
face=3Dsans-serif=20
  size=3D2>If the latter - why ?</FONT>&nbsp;<SPAN =
class=3D220351816-05062003><FONT=20
  face=3DArial color=3D#0000ff size=3D2>&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff size=3D2>Not=20
  applicable. If there were a mapping, then people might wonder what to =
do if=20
  the AS2-from value did not match up with the X.509 =
DN.</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2>Should we discard the whole thing?&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2></FONT></SPAN>&nbsp;</DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff size=3D2>We=20
  avoid this. What we have now is that the signed info is what counts=20
  only.&nbsp;So&nbsp;trust that&nbsp;the payload is OK if you accept the =

  signature as one that checks out with respect&nbsp;to =
a&nbsp;certificate that=20
  chains up&nbsp;to one of your trust anchors (which will be itself if =
using=20
  self-signed certs.)</FONT></SPAN><SPAN=20
  class=3D220351816-05062003>&nbsp;</SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003></SPAN><SPAN=20
  class=3D220351816-05062003><FONT face=3DArial color=3D#0000ff=20
  size=3D2>&nbsp;</FONT></SPAN></DIV>
  <DIV><SPAN class=3D220351816-05062003><FONT face=3DArial =
color=3D#0000ff=20
  size=3D2>Dale</FONT>&nbsp;</SPAN><BR><BR><FONT face=3Dsans-serif=20
  size=3D2>Paul<BR>--<BR>Paul Ford-Hutchinson : &nbsp;eCommerce =
application=20
  security : paulfordh@uk.ibm.com<BR>MPT-6, IBM , PO Box 31, Birmingham =
Rd,=20
  Warwick, CV34 5JL +44 (0)1926=20
  =
462005<BR>http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html<BR></FON=
T><BR><BR><BR></DIV>
  <TABLE width=3D"100%">
    <TBODY>
    <TR vAlign=3Dtop>
      <TD>
      <TD><FONT face=3Dsans-serif size=3D1><B>"Rishel,Wes"=20
        &lt;Wes.Rishel@gartner.com&gt;</B></FONT> <BR><FONT =
face=3Dsans-serif=20
        size=3D1>Sent by: owner-ietf-ediint@mail.imc.org</FONT>=20
        <P><FONT face=3Dsans-serif size=3D1>05/06/2003 15:23</FONT> =
<BR></P>
      <TD><FONT face=3DArial size=3D1>&nbsp; &nbsp; &nbsp; &nbsp; =
</FONT><BR><FONT=20
        face=3Dsans-serif size=3D1>&nbsp; &nbsp; &nbsp; &nbsp; To: =
&nbsp; &nbsp;=20
        &nbsp; &nbsp;"Jess Sightler" =
&lt;jsightler@eximtechnologies.com&gt;,=20
        &lt;lstoeckle@groupe-casino.fr&gt;</FONT> <BR><FONT =
face=3Dsans-serif=20
        size=3D1>&nbsp; &nbsp; &nbsp; &nbsp; cc: &nbsp; &nbsp; &nbsp;=20
        &nbsp;&lt;ietf-ediint@above.proper.com&gt;</FONT> <BR><FONT=20
        face=3Dsans-serif size=3D1>&nbsp; &nbsp; &nbsp; &nbsp; Subject: =
&nbsp;=20
        &nbsp; &nbsp; &nbsp;RE: AS2-SMIME : has the certificate to be =
included=20
        inside thesignatu re?</FONT> <BR><BR><FONT face=3DArial =
size=3D1>&nbsp;=20
        &nbsp; &nbsp; =
&nbsp;</FONT></TR></TBODY></TABLE><BR><BR><BR><BR><FONT=20
  size=3D2><TT>What is the benefit of sending the cert with the message? =
If you=20
  truly want to authenticate the originator you have to acquire the cert =
by=20
  independent, trusted means, don't you?<BR></TT></FONT><BR><FONT=20
  size=3D2><TT>-----Original Message-----<BR>From:=20
  =
owner-ietf-ediint@mail.imc.org<BR>[mailto:owner-ietf-ediint@mail.imc.org]=
On=20
  Behalf Of Jess Sightler<BR>Sent: Thursday, June 05, 2003 6:36 =
AM<BR>To:=20
  lstoeckle@groupe-casino.fr<BR>Cc: =
ietf-ediint@above.proper.com<BR>Subject: Re:=20
  AS2-SMIME : has the certificate to be included inside<BR>thesignatu=20
  re?<BR></TT></FONT><BR><BR><BR><FONT size=3D2><TT>I can't speak 100% =
from the=20
  spec on this, but I know that iSoft makes<BR>sending the Certificate =
with a=20
  signature optional.<BR></TT></FONT><BR><FONT size=3D2><TT>Based on =
that, I=20
  believe that it is an option to not send the cert. &nbsp;I<BR>believe =
that=20
  sending the Cert would be a good practice, =
however.<BR></TT></FONT><BR><FONT=20
  size=3D2><TT>Thanks,<BR>Jess<BR></TT></FONT><BR><BR><FONT =
size=3D2><TT>On Thu,=20
  2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:<BR>&gt;=20
  Hello,<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt; I am new on this list - and I =
need your=20
  help.<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt; AS2: when sending a signed =
message (the=20
  original message which can<BR>&gt; also be signed, or a signed MDN), =
has the=20
  signer's certificate to be<BR>&gt; included inside of the signature =
MIME=20
  part?<BR>&gt;<BR>&gt; Is it mandatory or should AS2 compliant products =
accept=20
  both? (signed<BR>&gt; messages containing the cert, or not containing =
it, in=20
  which case they<BR>&gt; would try to find a certificate on the local =
key store=20
  etc.)<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt; Regards,<BR>&gt;<BR>&gt;=20
  -----------------------------------------<BR>&gt; Ludan =
STOECKLE<BR>&gt; DSI=20
  Groupe Casino - Etudes<BR>&gt;<BR>&gt; 04 77 45 48 01<BR>&gt;<BR>&gt;=20
  lstoeckle@groupe-casino.fr<BR>&gt;=20
  =
-----------------------------------------<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt;=
<BR>&gt;<BR>&gt;<BR>--<BR>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<BR>=
Jess=20
  Sightler<BR>Senior Developer<BR>Exim Technologies<BR>131 Falls=20
  Street<BR>Greenville SC 29601<BR>Phone:=20
  =
864-679-4651<BR>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<BR></TT></FO=
NT><BR><BR><BR><BR><BR></BLOCKQUOTE></BODY></HTML>
=00
------_=_NextPart_001_01C32B7F.974C14F0--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 13:09:27 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA06737
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 13:09:26 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55GhOAF033559
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 09:43:24 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55GhOk9033558
	for ietf-ediint-bks; Thu, 5 Jun 2003 09:43:24 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from relais-int7.globalintranet.net (mailgate2.globalintranet.net [194.206.181.243])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55GhMAF033553
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 09:43:22 -0700 (PDT)
	(envelope-from lstoeckle@groupe-casino.fr)
Received: from mg21w043.siege.intra.groupe-casino.fr
          ([10.255.7.40]) by relais-int7.globalintranet.net (Netscape
          Messaging Server 4.15) with ESMTP id HG0ORL00.HE2 for
          <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 18:35:45 +0200 
Received: by mg21w043.siege.intra.groupe-casino.fr with Internet Mail Service (5.5.2653.19)
	id <MDV19VW2>; Thu, 5 Jun 2003 16:27:52 +0100
Message-ID: <014CBC6C32FDD611BB6400D0B78F6AD7089FD9@mg21w306.siege.intra.groupe-casino.fr>
From: lstoeckle@groupe-casino.fr
To: ietf-ediint@above.proper.com
Subject: RE : AS2-SMIME : has the certificate to be included inside the si
	gnatu re?
Date: Thu, 5 Jun 2003 16:27:51 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32B77.06F46B50"
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C32B77.06F46B50
Content-Type: text/plain;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

Thanks for your answer.

In fact I have interoperability issues between OpenAS2 and a commercial
AS2-certified product (I will not say which one).=20

I'm pretty sure OpenAS2 doesn't send the certificate inside the =
signature
when it sends a message (the signature part is too short to be contain =
the
certificate). But this produces a signature checking error on the =
commercial
product, and I do believe it's due to the lack of certificate: this
commercial product uses OpenSSL, and in the log the command line calls =
are
visible; and with this command line OpenSSL is not able to check the
signature even if it is available on the computer.

I'd really like to know what's inside the spec about this.


Thanks,
Ludan Stoeckl=E9.


-----Message d'origine-----
De=A0: Jess Sightler [mailto:jsightler@eximtechnologies.com]=20
Envoy=E9=A0: jeudi 5 juin 2003 14:36
=C0=A0: lstoeckle@groupe-casino.fr
Cc=A0: ietf-ediint@above.proper.com
Objet=A0: Re: AS2-SMIME : has the certificate to be included inside the
signatu re?

I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> Hello,
>=20
> =20
>=20
> I am new on this list - and I need your help.
>=20
> =20
>=20
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
>=20
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case =
they
> would try to find a certificate on the local key store etc.)=20
>=20
> =20
>=20
> Regards,
>=20
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
>=20
> 04 77 45 48 01
>=20
> lstoeckle@groupe-casino.fr
> -----------------------------------------
>=20
>=20
> =20
>=20
>=20
> =20
--=20
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D



------_=_NextPart_001_01C32B77.06F46B50
Content-Type: text/html;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3DWINDOWS-1252">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2653.12">
<TITLE>RE : AS2-SMIME : has the certificate to be included inside the =
signatu re?</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2>Thanks for your answer.</FONT>
</P>

<P><FONT SIZE=3D2>In fact I have interoperability issues between =
OpenAS2 and a commercial AS2-certified product (I will not say which =
one). </FONT></P>

<P><FONT SIZE=3D2>I'm pretty sure OpenAS2 doesn't send the certificate =
inside the signature when it sends a message (the signature part is too =
short to be contain the certificate). But this produces a signature =
checking error on the commercial product, and I do believe it's due to =
the lack of certificate: this commercial product uses OpenSSL, and in =
the log the command line calls are visible; and with this command line =
OpenSSL is not able to check the signature even if it is available on =
the computer.</FONT></P>

<P><FONT SIZE=3D2>I'd really like to know what's inside the spec about =
this.</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>Thanks,</FONT>
<BR><FONT SIZE=3D2>Ludan Stoeckl=E9.</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>-----Message d'origine-----</FONT>
<BR><FONT SIZE=3D2>De=A0: Jess Sightler [<A =
HREF=3D"mailto:jsightler@eximtechnologies.com">mailto:jsightler@eximtech=
nologies.com</A>] </FONT>
<BR><FONT SIZE=3D2>Envoy=E9=A0: jeudi 5 juin 2003 14:36</FONT>
<BR><FONT SIZE=3D2>=C0=A0: lstoeckle@groupe-casino.fr</FONT>
<BR><FONT SIZE=3D2>Cc=A0: ietf-ediint@above.proper.com</FONT>
<BR><FONT SIZE=3D2>Objet=A0: Re: AS2-SMIME : has the certificate to be =
included inside the signatu re?</FONT>
</P>

<P><FONT SIZE=3D2>I can't speak 100% from the spec on this, but I know =
that iSoft makes</FONT>
<BR><FONT SIZE=3D2>sending the Certificate with a signature =
optional.</FONT>
</P>

<P><FONT SIZE=3D2>Based on that, I believe that it is an option to not =
send the cert.&nbsp; I</FONT>
<BR><FONT SIZE=3D2>believe that sending the Cert would be a good =
practice, however.</FONT>
</P>

<P><FONT SIZE=3D2>Thanks,</FONT>
<BR><FONT SIZE=3D2>Jess</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>On Thu, 2003-06-05 at 09:58, =
lstoeckle@groupe-casino.fr wrote:</FONT>
<BR><FONT SIZE=3D2>&gt; Hello,</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; I am new on this list - and I need your =
help.</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; AS2: when sending a signed message (the =
original message which can</FONT>
<BR><FONT SIZE=3D2>&gt; also be signed, or a signed MDN), has the =
signer's certificate to be</FONT>
<BR><FONT SIZE=3D2>&gt; included inside of the signature MIME =
part?</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; Is it mandatory or should AS2 compliant =
products accept both? (signed</FONT>
<BR><FONT SIZE=3D2>&gt; messages containing the cert, or not containing =
it, in which case they</FONT>
<BR><FONT SIZE=3D2>&gt; would try to find a certificate on the local =
key store etc.) </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; Regards,</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; =
-----------------------------------------</FONT>
<BR><FONT SIZE=3D2>&gt; Ludan STOECKLE</FONT>
<BR><FONT SIZE=3D2>&gt; DSI Groupe Casino - Etudes</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; 04 77 45 48 01</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; lstoeckle@groupe-casino.fr</FONT>
<BR><FONT SIZE=3D2>&gt; =
-----------------------------------------</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>-- </FONT>
<BR><FONT =
SIZE=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT>
<BR><FONT SIZE=3D2>Jess Sightler</FONT>
<BR><FONT SIZE=3D2>Senior Developer</FONT>
<BR><FONT SIZE=3D2>Exim Technologies</FONT>
<BR><FONT SIZE=3D2>131 Falls Street</FONT>
<BR><FONT SIZE=3D2>Greenville SC 29601</FONT>
<BR><FONT SIZE=3D2>Phone: 864-679-4651</FONT>
<BR><FONT =
SIZE=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT>
</P>
<BR>

</BODY>
</HTML>
------_=_NextPart_001_01C32B77.06F46B50--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 13:10:11 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA06766
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 13:10:09 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55GmaAF033729
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 09:48:36 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55GmajL033728
	for ietf-ediint-bks; Thu, 5 Jun 2003 09:48:36 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from relais-int10.globalintranet.net (mailgate2.globalintranet.net [194.206.181.243])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55GmYAF033723
	for <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 09:48:35 -0700 (PDT)
	(envelope-from lstoeckle@groupe-casino.fr)
Received: from mg21w043.siege.intra.groupe-casino.fr
          ([10.255.7.40]) by relais-int10.globalintranet.net (Netscape
          Messaging Server 4.15) with ESMTP id HG0PAV01.260 for
          <ietf-ediint@above.proper.com>; Thu, 5 Jun 2003 18:47:19 +0200 
Received: by mg21w043.siege.intra.groupe-casino.fr with Internet Mail Service (5.5.2653.19)
	id <MDV19WVK>; Thu, 5 Jun 2003 16:57:29 +0100
Message-ID: <014CBC6C32FDD611BB6400D0B78F6AD7089FDE@mg21w306.siege.intra.groupe-casino.fr>
From: lstoeckle@groupe-casino.fr
To: ietf-ediint@above.proper.com
Subject: RE : AS2-SMIME : has the certificate to be included inside thesig
	natu re?
Date: Thu, 5 Jun 2003 16:57:29 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32B7B.2A8C5EC0"
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C32B7B.2A8C5EC0
Content-Type: text/plain;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

The administration work could be reduced if all the certificates =
exchanges
were dynamic; still the partner cert is always required to encrypt
messages...

I agree with you. If you use the cert included in the message (assuming =
it
is valid CA certified etc.) you can make clear that someone has signed =
the
message and that it hasn't changed since, but how can you be sure of =
who is
the signer?
I mean, there must be an identity check somewhere else?
If you use the good certificate that you trust to check the signature =
you
can authenticate at the same time, can't you?


-----Message d'origine-----
De=A0: Rishel,Wes [mailto:Wes.Rishel@gartner.com]=20
Envoy=E9=A0: jeudi 5 juin 2003 15:24
=C0=A0: Jess Sightler; lstoeckle@groupe-casino.fr
Cc=A0: ietf-ediint@above.proper.com
Objet=A0: RE: AS2-SMIME : has the certificate to be included inside =
thesignatu
re?

What is the benefit of sending the cert with the message? If you truly =
want
to authenticate the originator you have to acquire the cert by =
independent,
trusted means, don't you?

-----Original Message-----
From: owner-ietf-ediint@mail.imc.org
[mailto:owner-ietf-ediint@mail.imc.org]On Behalf Of Jess Sightler
Sent: Thursday, June 05, 2003 6:36 AM
To: lstoeckle@groupe-casino.fr
Cc: ietf-ediint@above.proper.com
Subject: Re: AS2-SMIME : has the certificate to be included inside
thesignatu re?



I can't speak 100% from the spec on this, but I know that iSoft makes
sending the Certificate with a signature optional.

Based on that, I believe that it is an option to not send the cert.  I
believe that sending the Cert would be a good practice, however.

Thanks,
Jess


On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:
> Hello,
>=20
> =20
>=20
> I am new on this list - and I need your help.
>=20
> =20
>=20
> AS2: when sending a signed message (the original message which can
> also be signed, or a signed MDN), has the signer's certificate to be
> included inside of the signature MIME part?
>=20
> Is it mandatory or should AS2 compliant products accept both? (signed
> messages containing the cert, or not containing it, in which case =
they
> would try to find a certificate on the local key store etc.)=20
>=20
> =20
>=20
> Regards,
>=20
> -----------------------------------------
> Ludan STOECKLE
> DSI Groupe Casino - Etudes
>=20
> 04 77 45 48 01
>=20
> lstoeckle@groupe-casino.fr
> -----------------------------------------
>=20
>=20
> =20
>=20
>=20
> =20
--=20
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jess Sightler
Senior Developer
Exim Technologies
131 Falls Street
Greenville SC 29601
Phone: 864-679-4651
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D



------_=_NextPart_001_01C32B7B.2A8C5EC0
Content-Type: text/html;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3DWINDOWS-1252">
<META NAME=3D"Generator" CONTENT=3D"MS Exchange Server version =
5.5.2653.12">
<TITLE>RE : AS2-SMIME : has the certificate to be included inside =
thesignatu re?</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=3D2>The administration work could be reduced if all the =
certificates exchanges were dynamic; still the partner cert is always =
required to encrypt messages...</FONT></P>

<P><FONT SIZE=3D2>I agree with you. If you use the cert included in the =
message (assuming it is valid CA certified etc.) you can make clear =
that someone has signed the message and that it hasn't changed since, =
but how can you be sure of who is the signer?</FONT></P>

<P><FONT SIZE=3D2>I mean, there must be an identity check somewhere =
else?</FONT>
<BR><FONT SIZE=3D2>If you use the good certificate that you trust to =
check the signature you can authenticate at the same time, can't =
you?</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>-----Message d'origine-----</FONT>
<BR><FONT SIZE=3D2>De=A0: Rishel,Wes [<A =
HREF=3D"mailto:Wes.Rishel@gartner.com">mailto:Wes.Rishel@gartner.com</A>=
] </FONT>
<BR><FONT SIZE=3D2>Envoy=E9=A0: jeudi 5 juin 2003 15:24</FONT>
<BR><FONT SIZE=3D2>=C0=A0: Jess Sightler; =
lstoeckle@groupe-casino.fr</FONT>
<BR><FONT SIZE=3D2>Cc=A0: ietf-ediint@above.proper.com</FONT>
<BR><FONT SIZE=3D2>Objet=A0: RE: AS2-SMIME : has the certificate to be =
included inside thesignatu re?</FONT>
</P>

<P><FONT SIZE=3D2>What is the benefit of sending the cert with the =
message? If you truly want to authenticate the originator you have to =
acquire the cert by independent, trusted means, don't you?</FONT></P>

<P><FONT SIZE=3D2>-----Original Message-----</FONT>
<BR><FONT SIZE=3D2>From: owner-ietf-ediint@mail.imc.org</FONT>
<BR><FONT SIZE=3D2>[<A =
HREF=3D"mailto:owner-ietf-ediint@mail.imc.org">mailto:owner-ietf-ediint@=
mail.imc.org</A>]On Behalf Of Jess Sightler</FONT>
<BR><FONT SIZE=3D2>Sent: Thursday, June 05, 2003 6:36 AM</FONT>
<BR><FONT SIZE=3D2>To: lstoeckle@groupe-casino.fr</FONT>
<BR><FONT SIZE=3D2>Cc: ietf-ediint@above.proper.com</FONT>
<BR><FONT SIZE=3D2>Subject: Re: AS2-SMIME : has the certificate to be =
included inside</FONT>
<BR><FONT SIZE=3D2>thesignatu re?</FONT>
</P>
<BR>
<BR>

<P><FONT SIZE=3D2>I can't speak 100% from the spec on this, but I know =
that iSoft makes</FONT>
<BR><FONT SIZE=3D2>sending the Certificate with a signature =
optional.</FONT>
</P>

<P><FONT SIZE=3D2>Based on that, I believe that it is an option to not =
send the cert.&nbsp; I</FONT>
<BR><FONT SIZE=3D2>believe that sending the Cert would be a good =
practice, however.</FONT>
</P>

<P><FONT SIZE=3D2>Thanks,</FONT>
<BR><FONT SIZE=3D2>Jess</FONT>
</P>
<BR>

<P><FONT SIZE=3D2>On Thu, 2003-06-05 at 09:58, =
lstoeckle@groupe-casino.fr wrote:</FONT>
<BR><FONT SIZE=3D2>&gt; Hello,</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; I am new on this list - and I need your =
help.</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; AS2: when sending a signed message (the =
original message which can</FONT>
<BR><FONT SIZE=3D2>&gt; also be signed, or a signed MDN), has the =
signer's certificate to be</FONT>
<BR><FONT SIZE=3D2>&gt; included inside of the signature MIME =
part?</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; Is it mandatory or should AS2 compliant =
products accept both? (signed</FONT>
<BR><FONT SIZE=3D2>&gt; messages containing the cert, or not containing =
it, in which case they</FONT>
<BR><FONT SIZE=3D2>&gt; would try to find a certificate on the local =
key store etc.) </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; Regards,</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; =
-----------------------------------------</FONT>
<BR><FONT SIZE=3D2>&gt; Ludan STOECKLE</FONT>
<BR><FONT SIZE=3D2>&gt; DSI Groupe Casino - Etudes</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; 04 77 45 48 01</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; lstoeckle@groupe-casino.fr</FONT>
<BR><FONT SIZE=3D2>&gt; =
-----------------------------------------</FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt; </FONT>
<BR><FONT SIZE=3D2>&gt;&nbsp; </FONT>
<BR><FONT SIZE=3D2>-- </FONT>
<BR><FONT =
SIZE=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT>
<BR><FONT SIZE=3D2>Jess Sightler</FONT>
<BR><FONT SIZE=3D2>Senior Developer</FONT>
<BR><FONT SIZE=3D2>Exim Technologies</FONT>
<BR><FONT SIZE=3D2>131 Falls Street</FONT>
<BR><FONT SIZE=3D2>Greenville SC 29601</FONT>
<BR><FONT SIZE=3D2>Phone: 864-679-4651</FONT>
<BR><FONT =
SIZE=3D2>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</FONT>
</P>
<BR>

</BODY>
</HTML>
------_=_NextPart_001_01C32B7B.2A8C5EC0--


From owner-ietf-ediint@mail.imc.org  Thu Jun  5 14:43:14 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA10441
	for <ediint-archive@lists.ietf.org>; Thu, 5 Jun 2003 14:43:14 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55IMxAF038125
	for <ietf-ediint-bks@above.proper.com>; Thu, 5 Jun 2003 11:22:59 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h55IMx3H038124
	for ietf-ediint-bks; Thu, 5 Jun 2003 11:22:59 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from drummondgroup.com (drummondgroup.com [161.58.166.198])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h55IMwAF038119
	for <ietf-ediint@imc.org>; Thu, 5 Jun 2003 11:22:58 -0700 (PDT)
	(envelope-from kyle@drummondgroup.com)
Received: from kyle (pcp01727176pcs.nash01.tn.comcast.net [68.52.232.165])
	by drummondgroup.com (8.12.9/8.11.6) with SMTP id h55IMxQp035034
	for <ietf-ediint@imc.org>; Thu, 5 Jun 2003 12:22:59 -0600 (MDT)
Message-ID: <023a01c32b8f$53072240$a5e83444@nash01.tn.comcast.net>
From: "Kyle Meadors" <kyle@drummondgroup.com>
To: "IETF EDIINT" <ietf-ediint@imc.org>
Subject: Interest in EDIINT WG meeting?
Date: Thu, 5 Jun 2003 13:21:46 -0500
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0237_01C32B65.69CC6500"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This is a multi-part message in MIME format.

------=_NextPart_000_0237_01C32B65.69CC6500
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Rik Drummond, the chair of the EDIINT WG, wanted me to pass on this =
email and ask the group if there is any interest in meeting? If so, post =
to the WG or email Rik. Thank you.

Kyle Meadors
Drummond Group Inc.
817.308.9489


> -----Original Message-----
> From: owner-wgchairs@ietf.org [mailto:owner-wgchairs@ietf.org] On=20
> Behalf
Of
> Dinara Suleymanova
> Sent: Tuesday, June 03, 2003 12:41 PM
> To: wgchairs@ietf.org; bofchairs@ietf.org; iesg@ietf.org
> Subject: 57th IETF WG/BOF Scheduling - Meetings Scheduled
> Importance: High
>
>
> Please find below the list (as of June 3rd) of groups that have been=20
> scheduled to meet. Submit your request by following instructions on
> http://www.ietf.org/meetings/req_meet.html.
> Also be aware that we are very close to the date when the scheduling
closes
> on  June 20th, 2003.
> If you are willing to meet, please make sure that the request has been
sent.
>
> Thanks,
>
> Dinara Suleymanova
>
> =3D=3D=3D
>
> APPLICATION AREA
> (calsch) Calendaring and Scheduling WG
> (crisp) Cross Registry Information Service Protocol WG
> (ldapbis) LDAP (v3) Revision WG
> (ldup) LDAP Duplication/Replication/Update Protocols WG
> (opes) Open Pluggable Edge Services WG
> (simple) SIP for Instant Messaging and Presence Leveraging Extensions=20
> WG
> (trade) Internet Open Trading Protocol WG
> (webdav) WWW Distributed Authoring and Versioning WG
>
> INTERNET AREA
> (magma) Multicast & Anycast Group Membership WG
>
> OPERATIONS AND MANAGEMENT AREA
> (aaa) Authentication, Authorization and Accounting WG
> (dnsop) Domain Name System Operations WG
> (grow) Global Routing Operations WG
> (ipfix) IP Flow Information Export WG
> (mboned) MBONE Deployment WG
> (netconf) Network Configuration WG
> (psamp) Packet Sampling WG
> (rmonmib) Remote Network Monitoring WG
>
> ROUTING AREA
> (forces) Forwarding and Control Element Separation WG
> (isis) IS-IS for IP Internets WG
> (manet) Mobile Ad-hoc Networks WG
> (pim) Protocol Independent Multicast WG
> (rpsec) Routing Protocol Security Requirements WG
> (ospf) Open Shortest Path First IGP WG
> (vrrp) Virtual Router Redundancy Protocol WG
>
> SECURITY AREA
> (inch) Extended Incident Handling WG
> (krb-wg) Kerberos WG
> (msec) Multicast Security WG
> (pkix) Public-Key Infrastructure (X.509) WG
> (saag) Open Security Area Directorate
> (sasl) Simple Authentication and Security Layer WG
> (smime) S/MIME Mail Security WG
>
> SUB-IP AREA
> (ccamp) Common Control and Measurement Plane WG
> (mpls) Multiprotocol Label Switching WG
> (tewg) Internet Traffic Engineering WG
>
> TRANSPORT AREA
> (dccp) Datagram Congestion Control Protocol WG
> (enum) Telephone Number Mapping WG
> (ieprep) Internet Emergency Preparedness WG
> (ippm) IP Performance Metrics WG
> (nsis) Next Steps in Signaling WG
> (pwe3) Pseudo Wire Emulation Edge to Edge WG
> (rddp) Remote Direct Data Placement WG
> (rmt) Reliable Multicast Transport WG
> (rohc) Robust Header Compression WG
> (rserpool) Reliable Server Pooling WG
> (sip) Session Initiation Protocol WG
> (sipping) Session Initiation Proposal Investigation WG
>
>
>
>


------=_NextPart_000_0237_01C32B65.69CC6500
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2715.400" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Rik Drummond, the chair of the EDIINT =
WG, wanted me=20
to pass on this email and ask the group if there is any interest in =
meeting? If=20
so, post to the WG or email&nbsp;Rik. Thank you.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT><BR><FONT face=3DArial =
size=3D2>Kyle=20
Meadors<BR>Drummond Group Inc.<BR>817.308.9489</FONT><BR></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2><FONT face=3D"Times New Roman" =
size=3D3>&gt;=20
-----Original Message-----<BR>&gt; From: </FONT><A=20
href=3D"mailto:owner-wgchairs@ietf.org"><FONT face=3D"Times New Roman"=20
size=3D3>owner-wgchairs@ietf.org</FONT></A><FONT face=3D"Times New =
Roman" size=3D3>=20
[mailto:owner-wgchairs@ietf.org] On <BR>&gt; Behalf<BR>Of<BR>&gt; Dinara =

Suleymanova<BR>&gt; Sent: Tuesday, June 03, 2003 12:41 PM<BR>&gt; To: =
</FONT><A=20
href=3D"mailto:wgchairs@ietf.org"><FONT face=3D"Times New Roman"=20
size=3D3>wgchairs@ietf.org</FONT></A><FONT face=3D"Times New Roman" =
size=3D3>;=20
</FONT><A href=3D"mailto:bofchairs@ietf.org"><FONT face=3D"Times New =
Roman"=20
size=3D3>bofchairs@ietf.org</FONT></A><FONT face=3D"Times New Roman" =
size=3D3>;=20
</FONT><A href=3D"mailto:iesg@ietf.org"><FONT face=3D"Times New Roman"=20
size=3D3>iesg@ietf.org</FONT></A><BR><FONT face=3D"Times New Roman" =
size=3D3>&gt;=20
Subject: 57th IETF WG/BOF Scheduling - Meetings Scheduled<BR>&gt; =
Importance:=20
High<BR>&gt;<BR>&gt;<BR>&gt; Please find below the list (as of June 3rd) =
of=20
groups that have been <BR>&gt; scheduled to meet. Submit your request by =

following instructions on<BR>&gt; </FONT><A=20
href=3D"http://www.ietf.org/meetings/req_meet.html"><FONT face=3D"Times =
New Roman"=20
size=3D3>http://www.ietf.org/meetings/req_meet.html</FONT></A><FONT=20
face=3D"Times New Roman" size=3D3>.<BR>&gt; Also be aware that we are =
very close to=20
the date when the scheduling<BR>closes<BR>&gt; on&nbsp; June 20th, =
2003.<BR>&gt;=20
If you are willing to meet, please make sure that the request has=20
been<BR>sent.<BR>&gt;<BR>&gt; Thanks,<BR>&gt;<BR>&gt; Dinara=20
Suleymanova<BR>&gt;<BR>&gt; =3D=3D=3D<BR>&gt;<BR>&gt; APPLICATION =
AREA<BR>&gt;=20
(calsch) Calendaring and Scheduling WG<BR>&gt; (crisp) Cross Registry=20
Information Service Protocol WG<BR>&gt; (ldapbis) LDAP (v3) Revision =
WG<BR>&gt;=20
(ldup) LDAP Duplication/Replication/Update Protocols WG<BR>&gt; (opes) =
Open=20
Pluggable Edge Services WG<BR>&gt; (simple) SIP for Instant Messaging =
and=20
Presence Leveraging Extensions <BR>&gt; WG<BR>&gt; (trade) Internet Open =
Trading=20
Protocol WG<BR>&gt; (webdav) WWW Distributed Authoring and Versioning=20
WG<BR>&gt;<BR>&gt; INTERNET AREA<BR>&gt; (magma) Multicast &amp; Anycast =
Group=20
Membership WG<BR>&gt;<BR>&gt; OPERATIONS AND MANAGEMENT AREA<BR>&gt; =
(aaa)=20
Authentication, Authorization and Accounting WG<BR>&gt; (dnsop) Domain =
Name=20
System Operations WG<BR>&gt; (grow) Global Routing Operations WG<BR>&gt; =
(ipfix)=20
IP Flow Information Export WG<BR>&gt; (mboned) MBONE Deployment =
WG<BR>&gt;=20
(netconf) Network Configuration WG<BR>&gt; (psamp) Packet Sampling =
WG<BR>&gt;=20
(rmonmib) Remote Network Monitoring WG<BR>&gt;<BR>&gt; ROUTING =
AREA<BR>&gt;=20
(forces) Forwarding and Control Element Separation WG<BR>&gt; (isis) =
IS-IS for=20
IP Internets WG<BR>&gt; (manet) Mobile Ad-hoc Networks WG<BR>&gt; (pim) =
Protocol=20
Independent Multicast WG<BR>&gt; (rpsec) Routing Protocol Security =
Requirements=20
WG<BR>&gt; (ospf) Open Shortest Path First IGP WG<BR>&gt; (vrrp) Virtual =
Router=20
Redundancy Protocol WG<BR>&gt;<BR>&gt; SECURITY AREA<BR>&gt; (inch) =
Extended=20
Incident Handling WG<BR>&gt; (krb-wg) Kerberos WG<BR>&gt; (msec) =
Multicast=20
Security WG<BR>&gt; (pkix) Public-Key Infrastructure (X.509) WG<BR>&gt; =
(saag)=20
Open Security Area Directorate<BR>&gt; (sasl) Simple Authentication and =
Security=20
Layer WG<BR>&gt; (smime) S/MIME Mail Security WG<BR>&gt;<BR>&gt; SUB-IP=20
AREA<BR>&gt; (ccamp) Common Control and Measurement Plane WG<BR>&gt; =
(mpls)=20
Multiprotocol Label Switching WG<BR>&gt; (tewg) Internet Traffic =
Engineering=20
WG<BR>&gt;<BR>&gt; TRANSPORT AREA<BR>&gt; (dccp) Datagram Congestion =
Control=20
Protocol WG<BR>&gt; (enum) Telephone Number Mapping WG<BR>&gt; (ieprep) =
Internet=20
Emergency Preparedness WG<BR>&gt; (ippm) IP Performance Metrics =
WG<BR>&gt;=20
(nsis) Next Steps in Signaling WG<BR>&gt; (pwe3) Pseudo Wire Emulation =
Edge to=20
Edge WG<BR>&gt; (rddp) Remote Direct Data Placement WG<BR>&gt; (rmt) =
Reliable=20
Multicast Transport WG<BR>&gt; (rohc) Robust Header Compression =
WG<BR>&gt;=20
(rserpool) Reliable Server Pooling WG<BR>&gt; (sip) Session Initiation =
Protocol=20
WG<BR>&gt; (sipping) Session Initiation Proposal Investigation=20
WG<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt;</FONT><BR></DIV></FONT></BODY></HTML>

------=_NextPart_000_0237_01C32B65.69CC6500--



From owner-ietf-ediint@mail.imc.org  Fri Jun  6 06:24:29 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA16316
	for <ediint-archive@lists.ietf.org>; Fri, 6 Jun 2003 06:24:29 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h56A40AF098835
	for <ietf-ediint-bks@above.proper.com>; Fri, 6 Jun 2003 03:04:00 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h56A40Yw098834
	for ietf-ediint-bks; Fri, 6 Jun 2003 03:04:00 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from relais-int2.globalintranet.net (mailgate2.globalintranet.net [194.206.181.243])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h56A3vAF098773
	for <ietf-ediint@above.proper.com>; Fri, 6 Jun 2003 03:03:58 -0700 (PDT)
	(envelope-from lstoeckle@groupe-casino.fr)
Received: from mg21w043.siege.intra.groupe-casino.fr
          ([10.255.7.40]) by relais-int2.globalintranet.net (Netscape
          Messaging Server 4.15) with ESMTP id HG20VM00.WNR for
          <ietf-ediint@above.proper.com>; Fri, 6 Jun 2003 11:54:58 +0200 
Received: by mg21w043.siege.intra.groupe-casino.fr with Internet Mail Service (5.5.2653.19)
	id <MDV10GKV>; Fri, 6 Jun 2003 11:55:11 +0100
Message-ID: <014CBC6C32FDD611BB6400D0B78F6AD7089FE0@mg21w306.siege.intra.groupe-casino.fr>
From: lstoeckle@groupe-casino.fr
To: ietf-ediint@above.proper.com
Subject: RE : RE : AS2-SMIME : has the certificate to be included inside t
	he si	gnatu re?
Date: Fri, 6 Jun 2003 11:55:09 +0100 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: multipart/alternative;
	boundary="----_=_NextPart_001_01C32C1A.18ACB750"
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.

------_=_NextPart_001_01C32C1A.18ACB750
Content-Type: text/plain;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

Being new on this list I don=92t know if it has been given before but:

=20

OpenAS2 is a free open-source implementation of EDIINT AS2.=20

Of course its interoperability is not certified.

It=92s quite new (first release end of May), but I have tested it and =
it works
quite well. It can=92t be compared to commercial products yet but I =
think it=92s
promising.

=20

The OpenAS2 project:

http://www.openas2.org <http://www.openas2.org/>=20

and it is hosted on sourceforge.org:

 <http://sourceforge.net/projects/openas2>
http://sourceforge.net/projects/openas2

=20

I am not part of this project or related to them in any way.=20

Maybe I will contact them and ask them to make some more official
announcement on this list.=20

=20

-----------------------------------------
Ludan STOECKLE
DSI Groupe Casino - Etudes

04 77 45 48 01

 <mailto:lstoeckle@groupe-casino.fr> lstoeckle@groupe-casino.fr
-----------------------------------------=20

=20

-----Message d'origine-----
De : Paul V Ford-Hutchinson [mailto:paulfordh@uk.ibm.com]=20
Envoy=E9 : jeudi 5 juin 2003 18:55
=C0 : lstoeckle@groupe-casino.fr
Objet : RE : AS2-SMIME : has the certificate to be included inside the =
si
gnatu re?

=20


Ludan - what is 'OpenAS2' - is there a pointer you can give me to it =
please
?=20

Cheers,=20
Paul

--
Paul Ford-Hutchinson :  eCommerce application security :
paulfordh@uk.ibm.com
MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 =
462005
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html





=20

lstoeckle@groupe-casino.fr=20
Sent by: owner-ietf-ediint@mail.imc.org=20

05/06/2003 16:27=20

       =20
        To:        ietf-ediint@above.proper.com=20
        cc:        =20
        Subject:        RE : AS2-SMIME : has the certificate to be =
included
inside the si        gnatu re?=20

      =20






Thanks for your answer.=20

In fact I have interoperability issues between OpenAS2 and a commercial
AS2-certified product (I will not say which one).=20

I'm pretty sure OpenAS2 doesn't send the certificate inside the =
signature
when it sends a message (the signature part is too short to be contain =
the
certificate). But this produces a signature checking error on the =
commercial
product, and I do believe it's due to the lack of certificate: this
commercial product uses OpenSSL, and in the log the command line calls =
are
visible; and with this command line OpenSSL is not able to check the
signature even if it is available on the computer.=20

I'd really like to know what's inside the spec about this.=20

Thanks,=20
Ludan Stoeckl=E9.=20

-----Message d'origine-----=20
De : Jess Sightler [ <mailto:jsightler@eximtechnologies.com>
mailto:jsightler@eximtechnologies.com]=20
Envoy=E9 : jeudi 5 juin 2003 14:36=20
=C0 : lstoeckle@groupe-casino.fr=20
Cc : ietf-ediint@above.proper.com=20
Objet : Re: AS2-SMIME : has the certificate to be included inside the
signatu re?=20

I can't speak 100% from the spec on this, but I know that iSoft makes=20
sending the Certificate with a signature optional.=20

Based on that, I believe that it is an option to not send the cert.  I=20
believe that sending the Cert would be a good practice, however.=20

Thanks,=20
Jess=20

On Thu, 2003-06-05 at 09:58, lstoeckle@groupe-casino.fr wrote:=20
> Hello,=20
>=20
> =20
>=20
> I am new on this list - and I need your help.=20
>=20
> =20
>=20
> AS2: when sending a signed message (the original message which can=20
> also be signed, or a signed MDN), has the signer's certificate to be=20
> included inside of the signature MIME part?=20
>=20
> Is it mandatory or should AS2 compliant products accept both? (signed =

> messages containing the cert, or not containing it, in which case =
they=20
> would try to find a certificate on the local key store etc.)=20
>=20
> =20
>=20
> Regards,=20
>=20
> -----------------------------------------=20
> Ludan STOECKLE=20
> DSI Groupe Casino - Etudes=20
>=20
> 04 77 45 48 01=20
>=20
> lstoeckle@groupe-casino.fr=20
> -----------------------------------------=20
>=20
>=20
> =20
>=20
>=20
> =20
--=20
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=20
Jess Sightler=20
Senior Developer=20
Exim Technologies=20
131 Falls Street=20
Greenville SC 29601=20
Phone: 864-679-4651=20
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=20





------_=_NextPart_001_01C32C1A.18ACB750
Content-Type: text/html;
	charset="WINDOWS-1252"
Content-Transfer-Encoding: quoted-printable

<html>

<head>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3DWINDOWS-1252">


<meta name=3DGenerator content=3D"Microsoft Word 10 (filtered)">

<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:blue;
	text-decoration:underline;}
p
	{margin-right:0cm;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman";}
span.StyleCourrierlectronique18
	{font-family:Arial;
	color:navy;}
@page Section1
	{size:595.3pt 841.9pt;
	margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.Section1
	{page:Section1;}
-->
</style>

</head>

<body lang=3DFR link=3Dblue vlink=3Dblue>

<div class=3DSection1>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>Being new on =
this list I
don=92t know if it has been given before but:</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>&nbsp;</span></f=
ont></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>OpenAS2 is a =
free
open-source implementation of EDIINT AS2. </span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>Of course its
interoperability is not certified.</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>It=92s quite =
new
(first release end of May), but I have tested it and it works quite =
well. It
can=92t be compared to commercial products yet but I think it=92s
promising.</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>&nbsp;</span></f=
ont></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>The OpenAS2 =
project:</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'><a
href=3D"http://www.openas2.org/">http://www.openas2.org</a></span></font=
></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>and it is =
hosted on
sourceforge.org:</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'><a
href=3D"http://sourceforge.net/projects/openas2"><span =
lang=3DFR>http://sourceforge.net/projects/openas2</span></a></span></fon=
t></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
style=3D'font-size:
10.0pt;font-family:Arial;color:navy'>&nbsp;</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>I am not part =
of this
project or related to them in any way. </span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>Maybe I will =
contact them
and ask them to make some more official announcement on this list. =
</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3DArial><span =
lang=3DEN-GB
style=3D'font-size:10.0pt;font-family:Arial;color:navy'>&nbsp;</span></f=
ont></p>

<div>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3D"Times New =
Roman"><span
style=3D'font-size:10.0pt;color:navy'>----------------------------------=
-------</span></font><font
color=3Dnavy><span style=3D'color:navy'><br>
</span></font><b><font size=3D2 color=3Dnavy><span =
style=3D'font-size:10.0pt;
color:navy;font-weight:bold'>Ludan STOECKLE</span></font></b><font =
color=3Dnavy><span
style=3D'color:navy'><br>
</span></font><font size=3D2 color=3Dnavy><span =
style=3D'font-size:10.0pt;color:navy'>DSI
Groupe Casino - Etudes</span></font></p>

<p class=3DMsoNormal><font size=3D2 color=3Dnavy face=3D"Times New =
Roman"><span
style=3D'font-size:10.0pt;color:navy'>04 77 45 48 01</span></font></p>

<div>

<p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:
12.0pt'><a href=3D"mailto:lstoeckle@groupe-casino.fr"><font =
size=3D2><span
style=3D'font-size:10.0pt'>lstoeckle@groupe-casino.fr</span></font></a><=
font
color=3Dnavy><span style=3D'color:navy'><br>
</span></font></span></font><font size=3D2 color=3Dblack><span =
style=3D'font-size:
10.0pt;color:black'>-----------------------------------------</span></fo=
nt><font
color=3Dnavy><span style=3D'color:navy'> </span></font></p>

</div>

<div>

<p class=3DMsoNormal><font size=3D3 color=3Dnavy face=3D"Times New =
Roman"><span
style=3D'font-size:12.0pt;color:navy'>&nbsp;</span></font></p>

</div>

</div>

<p class=3DMsoNormal style=3D'margin-left:35.4pt'><font size=3D2 =
face=3DTahoma><span
style=3D'font-size:10.0pt;font-family:Tahoma'>-----Message =
d'origine-----<br>
<b><span style=3D'font-weight:bold'>De&nbsp;:</span></b> Paul V =
Ford-Hutchinson
[mailto:paulfordh@uk.ibm.com] <br>
<b><span style=3D'font-weight:bold'>Envoy=E9&nbsp;:</span></b> jeudi 5 =
juin 2003
18:55<br>
<b><span style=3D'font-weight:bold'>=C0&nbsp;:</span></b> =
lstoeckle@groupe-casino.fr<br>
<b><span style=3D'font-weight:bold'>Objet&nbsp;:</span></b> RE : =
AS2-SMIME : has
the certificate to be included inside the si gnatu =
re?</span></font></p>

<p class=3DMsoNormal style=3D'margin-left:35.4pt'><font size=3D3
face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt'>&nbsp;</span></font></p>

<p class=3DMsoNormal =
style=3D'margin-right:0cm;margin-bottom:12.0pt;margin-left:
35.4pt'><font size=3D3 face=3D"Times New Roman"><span =
style=3D'font-size:12.0pt'><br>
</span></font><font size=3D2 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:10.0pt;
font-family:Arial'>Ludan - what is 'OpenAS2' - is there a pointer you =
can give
me to it please ?</span></font><span lang=3DEN-GB> <br>
<br>
</span><font size=3D2 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:10.0pt;
font-family:Arial'>Cheers,</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:10.0pt;
font-family:Arial'>Paul<br>
<br>
--<br>
Paul Ford-Hutchinson : &nbsp;eCommerce application security :
paulfordh@uk.ibm.com<br>
MPT-6, IBM , PO Box 31, Birmingham Rd, Warwick, CV34 5JL +44 (0)1926 =
462005<br>
http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html<br>
</span></font><span lang=3DEN-GB><br>
<br>
</span></p>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D"100%"
 style=3D'width:100.0%;margin-left:35.4pt'>
 <tr>
  <td valign=3Dtop style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><font size=3D3 face=3D"Times New Roman"><span =
lang=3DEN-GB
  style=3D'font-size:12.0pt'>&nbsp;</span></font></p>
  </td>
  <td valign=3Dtop style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><b><font size=3D1 face=3DArial><span =
lang=3DEN-GB
  =
style=3D'font-size:7.5pt;font-family:Arial;font-weight:bold'>lstoeckle@g=
roupe-casino.fr</span></font></b><span
  lang=3DEN-GB> <br>
  </span><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:7.5pt;
  font-family:Arial'>Sent by: =
owner-ietf-ediint@mail.imc.org</span></font><span
  lang=3DEN-GB> </span></p>
  <p><font size=3D1 face=3DArial><span =
style=3D'font-size:7.5pt;font-family:Arial'>05/06/2003
  16:27</span></font> </p>
  </td>
  <td valign=3Dtop style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:
  7.5pt;font-family:Arial'>&nbsp; &nbsp; &nbsp; &nbsp; =
</span></font><span
  lang=3DEN-GB><br>
  </span><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:7.5pt;
  font-family:Arial'>&nbsp; &nbsp; &nbsp; &nbsp; To: &nbsp; &nbsp; =
&nbsp;
  &nbsp;</span></font><font size=3D1 face=3DArial><span lang=3DEN-GB
   =
style=3D'font-size:7.5pt;font-family:Arial'>ietf-ediint@above.proper.com=
</span></font><span
  lang=3DEN-GB> <br>
  </span><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:7.5pt;
  font-family:Arial'>&nbsp; &nbsp; &nbsp; &nbsp; cc: &nbsp; &nbsp; =
&nbsp;
  &nbsp;</span></font><span lang=3DEN-GB> <br>
  </span><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:7.5pt;
  font-family:Arial'>&nbsp; &nbsp; &nbsp; &nbsp; Subject: &nbsp; &nbsp; =
&nbsp;
  &nbsp;RE : AS2-SMIME : has the certificate to be included inside the =
si
  &nbsp; &nbsp; &nbsp; &nbsp;gnatu re?</span></font><span lang=3DEN-GB> =
<br>
  <br>
  </span><font size=3D1 face=3DArial><span lang=3DEN-GB =
style=3D'font-size:7.5pt;
  font-family:Arial'>&nbsp; &nbsp; &nbsp; &nbsp;</span></font></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal =
style=3D'margin-right:0cm;margin-bottom:12.0pt;margin-left:
35.4pt'><font size=3D3 face=3D"Times New Roman"><span lang=3DEN-GB =
style=3D'font-size:
12.0pt'><br>
<br>
<br>
<br>
<br>
</span></font><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Thanks for
your answer.</span></font><span lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>In =
fact I have
interoperability issues between OpenAS2 and a commercial AS2-certified =
product
(I will not say which one). </span></font><span lang=3DEN-GB><br>
<br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>I'm =
pretty sure
OpenAS2 doesn't send the certificate inside the signature when it sends =
a
message (the signature part is too short to be contain the =
certificate). But
this produces a signature checking error on the commercial product, and =
I do
believe it's due to the lack of certificate: this commercial product =
uses
OpenSSL, and in the log the command line calls are visible; and with =
this
command line OpenSSL is not able to check the signature even if it is =
available
on the computer.</span></font><span lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>I'd =
really like
to know what's inside the spec about this.</span></font><span =
lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Thanks,</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Ludan Stoeckl=E9.</span></font><span
lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>-----Message =
d'origine-----</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>De&nbsp;: Jess Sightler
[</span></font><a href=3D"mailto:jsightler@eximtechnologies.com"><font =
size=3D2><span
lang=3DEN-GB =
style=3D'font-size:10.0pt'>mailto:jsightler@eximtechnologies.com</span><=
/font></a><font
size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>] =
</span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Envoy=E9&nbsp;: jeudi
5 juin 2003 14:36</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>=C0&nbsp;:
lstoeckle@groupe-casino.fr</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Cc&nbsp;: </span></font><font
 size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>ietf-ediint@above.proper.com</span></font><sp=
an
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Objet&nbsp;: Re:
AS2-SMIME : has the certificate to be included inside the signatu =
re?</span></font><span
lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>I =
can't speak
100% from the spec on this, but I know that iSoft =
makes</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>sending the
Certificate with a signature optional.</span></font><span lang=3DEN-GB> =
<br>
<br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Based on that, I
believe that it is an option to not send the cert.&nbsp; =
I</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>believe that
sending the Cert would be a good practice, however.</span></font><span
lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Thanks,</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Jess</span></font><span
lang=3DEN-GB> <br>
<br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>On =
Thu,
2003-06-05 at 09:58, lstoeckle@groupe-casino.fr =
wrote:</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; Hello,</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;&nbsp; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; I am new on
this list - and I need your help.</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;&nbsp; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; AS2: when
sending a signed message (the original message which =
can</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; also be
signed, or a signed MDN), has the signer's certificate to =
be</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; included
inside of the signature MIME part?</span></font><span lang=3DEN-GB> =
<br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; Is it
mandatory or should AS2 compliant products accept both? =
(signed</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; messages
containing the cert, or not containing it, in which case =
they</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; would try to
find a certificate on the local key store etc.) </span></font><span =
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;&nbsp; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; Regards,</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;
-----------------------------------------</span></font><span =
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; Ludan
STOECKLE</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; DSI Groupe
Casino - Etudes</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; 04 77 45 48
01</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;
lstoeckle@groupe-casino.fr</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;
-----------------------------------------</span></font><span =
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;&nbsp; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>&gt;&nbsp; </span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>-- =
</span></font><span
lang=3DEN-GB><br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Jess Sightler</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Senior Developer</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Exim Technologies</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB style=3D'font-size:10.0pt'>131 =
Falls Street</span></font><span
lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Greenville SC
29601</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>Phone:
864-679-4651</span></font><span lang=3DEN-GB> <br>
</span><font size=3D2><span lang=3DEN-GB =
style=3D'font-size:10.0pt'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
</span></font><span
lang=3DEN-GB> <br>
<br>
<br>
</span></p>

</div>

</body>

</html>

------_=_NextPart_001_01C32C1A.18ACB750--


From owner-ietf-ediint@mail.imc.org  Wed Jun 11 15:13:31 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA23064
	for <ediint-archive@lists.ietf.org>; Wed, 11 Jun 2003 15:13:30 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h5BIlerb079972
	for <ietf-ediint-bks@above.proper.com>; Wed, 11 Jun 2003 11:47:40 -0700 (PDT)
	(envelope-from owner-ietf-ediint@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h5BIlequ079970
	for ietf-ediint-bks; Wed, 11 Jun 2003 11:47:40 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-ediint@mail.imc.org using -f
Received: from drummondgroup.com (drummondgroup.com [161.58.166.198])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h5BIlcrb079961
	for <ietf-ediint@imc.org>; Wed, 11 Jun 2003 11:47:38 -0700 (PDT)
	(envelope-from kyle@drummondgroup.com)
Received: from kyle (pcp01727176pcs.nash01.tn.comcast.net [68.52.232.165])
	by drummondgroup.com (8.12.9/8.11.6) with SMTP id h5BIlYLi060683
	for <ietf-ediint@imc.org>; Wed, 11 Jun 2003 12:47:39 -0600 (MDT)
Message-ID: <007401c33049$c5ab7580$a5e83444@nash01.tn.comcast.net>
From: "Kyle Meadors" <kyle@drummondgroup.com>
To: "IETF EDIINT" <ietf-ediint@imc.org>
References: <023a01c32b8f$53072240$a5e83444@nash01.tn.comcast.net>
Subject: Re: Interest in EDIINT WG meeting?
Date: Wed, 11 Jun 2003 13:46:24 -0500
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_0071_01C3301F.D964FEE0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Sender: owner-ietf-ediint@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-ediint/mail-archive/>
List-ID: <ietf-ediint.imc.org>
List-Unsubscribe: <mailto:ietf-ediint-request@imc.org?body=unsubscribe>


This is a multi-part message in MIME format.

------=_NextPart_000_0071_01C3301F.D964FEE0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Just a note - Rik is traveling both this week and the next and is having =
some problems from the road connecting to his email. If you have already =
emailed him directly about interest in an EDIINT WG meeting or are =
planning to do so, forward a copy of the email to me or include me in =
the Cc, and I will make sure Rik gets your message. Of course, you can =
always post to the list. Thank you.

Kyle Meadors
Drummond Group Inc.
817.308.9489
  ----- Original Message -----=20
  From: Kyle Meadors=20
  To: IETF EDIINT=20
  Sent: Thursday, June 05, 2003 1:21 PM
  Subject: Interest in EDIINT WG meeting?


  Rik Drummond, the chair of the EDIINT WG, wanted me to pass on this =
email and ask the group if there is any interest in meeting? If so, post =
to the WG or email Rik. Thank you.

  Kyle Meadors
  Drummond Group Inc.
  817.308.9489


  > -----Original Message-----
  > From: owner-wgchairs@ietf.org [mailto:owner-wgchairs@ietf.org] On=20
  > Behalf
  Of
  > Dinara Suleymanova
  > Sent: Tuesday, June 03, 2003 12:41 PM
  > To: wgchairs@ietf.org; bofchairs@ietf.org; iesg@ietf.org
  > Subject: 57th IETF WG/BOF Scheduling - Meetings Scheduled
  > Importance: High
  >
  >
  > Please find below the list (as of June 3rd) of groups that have been =

  > scheduled to meet. Submit your request by following instructions on
  > http://www.ietf.org/meetings/req_meet.html.
  > Also be aware that we are very close to the date when the scheduling
  closes
  > on  June 20th, 2003.
  > If you are willing to meet, please make sure that the request has =
been
  sent.
  >
  > Thanks,
  >
  > Dinara Suleymanova
  >
  > =3D=3D=3D
  >
  > APPLICATION AREA
  > (calsch) Calendaring and Scheduling WG
  > (crisp) Cross Registry Information Service Protocol WG
  > (ldapbis) LDAP (v3) Revision WG
  > (ldup) LDAP Duplication/Replication/Update Protocols WG
  > (opes) Open Pluggable Edge Services WG
  > (simple) SIP for Instant Messaging and Presence Leveraging =
Extensions=20
  > WG
  > (trade) Internet Open Trading Protocol WG
  > (webdav) WWW Distributed Authoring and Versioning WG
  >
  > INTERNET AREA
  > (magma) Multicast & Anycast Group Membership WG
  >
  > OPERATIONS AND MANAGEMENT AREA
  > (aaa) Authentication, Authorization and Accounting WG
  > (dnsop) Domain Name System Operations WG
  > (grow) Global Routing Operations WG
  > (ipfix) IP Flow Information Export WG
  > (mboned) MBONE Deployment WG
  > (netconf) Network Configuration WG
  > (psamp) Packet Sampling WG
  > (rmonmib) Remote Network Monitoring WG
  >
  > ROUTING AREA
  > (forces) Forwarding and Control Element Separation WG
  > (isis) IS-IS for IP Internets WG
  > (manet) Mobile Ad-hoc Networks WG
  > (pim) Protocol Independent Multicast WG
  > (rpsec) Routing Protocol Security Requirements WG
  > (ospf) Open Shortest Path First IGP WG
  > (vrrp) Virtual Router Redundancy Protocol WG
  >
  > SECURITY AREA
  > (inch) Extended Incident Handling WG
  > (krb-wg) Kerberos WG
  > (msec) Multicast Security WG
  > (pkix) Public-Key Infrastructure (X.509) WG
  > (saag) Open Security Area Directorate
  > (sasl) Simple Authentication and Security Layer WG
  > (smime) S/MIME Mail Security WG
  >
  > SUB-IP AREA
  > (ccamp) Common Control and Measurement Plane WG
  > (mpls) Multiprotocol Label Switching WG
  > (tewg) Internet Traffic Engineering WG
  >
  > TRANSPORT AREA
  > (dccp) Datagram Congestion Control Protocol WG
  > (enum) Telephone Number Mapping WG
  > (ieprep) Internet Emergency Preparedness WG
  > (ippm) IP Performance Metrics WG
  > (nsis) Next Steps in Signaling WG
  > (pwe3) Pseudo Wire Emulation Edge to Edge WG
  > (rddp) Remote Direct Data Placement WG
  > (rmt) Reliable Multicast Transport WG
  > (rohc) Robust Header Compression WG
  > (rserpool) Reliable Server Pooling WG
  > (sip) Session Initiation Protocol WG
  > (sipping) Session Initiation Proposal Investigation WG
  >
  >
  >
  >


------=_NextPart_000_0071_01C3301F.D964FEE0
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2715.400" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Just a note - Rik is traveling both =
this week and=20
the next and is having some problems from the road connecting to his =
email. If=20
you have already emailed him directly about interest in an EDIINT WG =
meeting or=20
are planning to do so, forward a copy&nbsp;of&nbsp;the email to me or =
include me=20
in the Cc, and I will make sure Rik gets your message. Of =
course,&nbsp;you can=20
always post to the list. Thank you.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2><BR>Kyle Meadors<BR>Drummond Group=20
Inc.<BR>817.308.9489</FONT></DIV>
<BLOCKQUOTE dir=3Dltr=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
  <DIV style=3D"FONT: 10pt arial">----- Original Message ----- </DIV>
  <DIV=20
  style=3D"BACKGROUND: #e4e4e4; FONT: 10pt arial; font-color: =
black"><B>From:</B>=20
  <A title=3Dkyle@drummondgroup.com =
href=3D"mailto:kyle@drummondgroup.com">Kyle=20
  Meadors</A> </DIV>
  <DIV style=3D"FONT: 10pt arial"><B>To:</B> <A =
title=3Dietf-ediint@imc.org=20
  href=3D"mailto:ietf-ediint@imc.org">IETF EDIINT</A> </DIV>
  <DIV style=3D"FONT: 10pt arial"><B>Sent:</B> Thursday, June 05, 2003 =
1:21=20
  PM</DIV>
  <DIV style=3D"FONT: 10pt arial"><B>Subject:</B> Interest in EDIINT WG=20
  meeting?</DIV>
  <DIV><BR></DIV>
  <DIV><FONT face=3DArial size=3D2>Rik Drummond, the chair of the EDIINT =
WG, wanted=20
  me to pass on this email and ask the group if there is any interest in =

  meeting? If so, post to the WG or email&nbsp;Rik. Thank =
you.</FONT></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT><BR><FONT face=3DArial =
size=3D2>Kyle=20
  Meadors<BR>Drummond Group Inc.<BR>817.308.9489</FONT><BR></DIV>
  <DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
  <DIV><FONT face=3DArial size=3D2><FONT face=3D"Times New Roman" =
size=3D3>&gt;=20
  -----Original Message-----<BR>&gt; From: </FONT><A=20
  href=3D"mailto:owner-wgchairs@ietf.org"><FONT face=3D"Times New Roman" =

  size=3D3>owner-wgchairs@ietf.org</FONT></A><FONT face=3D"Times New =
Roman" size=3D3>=20
  [mailto:owner-wgchairs@ietf.org] On <BR>&gt; Behalf<BR>Of<BR>&gt; =
Dinara=20
  Suleymanova<BR>&gt; Sent: Tuesday, June 03, 2003 12:41 PM<BR>&gt; To:=20
  </FONT><A href=3D"mailto:wgchairs@ietf.org"><FONT face=3D"Times New =
Roman"=20
  size=3D3>wgchairs@ietf.org</FONT></A><FONT face=3D"Times New Roman" =
size=3D3>;=20
  </FONT><A href=3D"mailto:bofchairs@ietf.org"><FONT face=3D"Times New =
Roman"=20
  size=3D3>bofchairs@ietf.org</FONT></A><FONT face=3D"Times New Roman" =
size=3D3>;=20
  </FONT><A href=3D"mailto:iesg@ietf.org"><FONT face=3D"Times New Roman" =

  size=3D3>iesg@ietf.org</FONT></A><BR><FONT face=3D"Times New Roman" =
size=3D3>&gt;=20
  Subject: 57th IETF WG/BOF Scheduling - Meetings Scheduled<BR>&gt; =
Importance:=20
  High<BR>&gt;<BR>&gt;<BR>&gt; Please find below the list (as of June =
3rd) of=20
  groups that have been <BR>&gt; scheduled to meet. Submit your request =
by=20
  following instructions on<BR>&gt; </FONT><A=20
  href=3D"http://www.ietf.org/meetings/req_meet.html"><FONT =
face=3D"Times New Roman"=20
  size=3D3>http://www.ietf.org/meetings/req_meet.html</FONT></A><FONT=20
  face=3D"Times New Roman" size=3D3>.<BR>&gt; Also be aware that we are =
very close=20
  to the date when the scheduling<BR>closes<BR>&gt; on&nbsp; June 20th,=20
  2003.<BR>&gt; If you are willing to meet, please make sure that the =
request=20
  has been<BR>sent.<BR>&gt;<BR>&gt; Thanks,<BR>&gt;<BR>&gt; Dinara=20
  Suleymanova<BR>&gt;<BR>&gt; =3D=3D=3D<BR>&gt;<BR>&gt; APPLICATION =
AREA<BR>&gt;=20
  (calsch) Calendaring and Scheduling WG<BR>&gt; (crisp) Cross Registry=20
  Information Service Protocol WG<BR>&gt; (ldapbis) LDAP (v3) Revision=20
  WG<BR>&gt; (ldup) LDAP Duplication/Replication/Update Protocols =
WG<BR>&gt;=20
  (opes) Open Pluggable Edge Services WG<BR>&gt; (simple) SIP for =
Instant=20
  Messaging and Presence Leveraging Extensions <BR>&gt; WG<BR>&gt; =
(trade)=20
  Internet Open Trading Protocol WG<BR>&gt; (webdav) WWW Distributed =
Authoring=20
  and Versioning WG<BR>&gt;<BR>&gt; INTERNET AREA<BR>&gt; (magma) =
Multicast=20
  &amp; Anycast Group Membership WG<BR>&gt;<BR>&gt; OPERATIONS AND =
MANAGEMENT=20
  AREA<BR>&gt; (aaa) Authentication, Authorization and Accounting =
WG<BR>&gt;=20
  (dnsop) Domain Name System Operations WG<BR>&gt; (grow) Global Routing =

  Operations WG<BR>&gt; (ipfix) IP Flow Information Export WG<BR>&gt; =
(mboned)=20
  MBONE Deployment WG<BR>&gt; (netconf) Network Configuration WG<BR>&gt; =
(psamp)=20
  Packet Sampling WG<BR>&gt; (rmonmib) Remote Network Monitoring=20
  WG<BR>&gt;<BR>&gt; ROUTING AREA<BR>&gt; (forces) Forwarding and =
Control=20
  Element Separation WG<BR>&gt; (isis) IS-IS for IP Internets WG<BR>&gt; =
(manet)=20
  Mobile Ad-hoc Networks WG<BR>&gt; (pim) Protocol Independent Multicast =

  WG<BR>&gt; (rpsec) Routing Protocol Security Requirements WG<BR>&gt; =
(ospf)=20
  Open Shortest Path First IGP WG<BR>&gt; (vrrp) Virtual Router =
Redundancy=20
  Protocol WG<BR>&gt;<BR>&gt; SECURITY AREA<BR>&gt; (inch) Extended =
Incident=20
  Handling WG<BR>&gt; (krb-wg) Kerberos WG<BR>&gt; (msec) Multicast =
Security=20
  WG<BR>&gt; (pkix) Public-Key Infrastructure (X.509) WG<BR>&gt; (saag) =
Open=20
  Security Area Directorate<BR>&gt; (sasl) Simple Authentication and =
Security=20
  Layer WG<BR>&gt; (smime) S/MIME Mail Security WG<BR>&gt;<BR>&gt; =
SUB-IP=20
  AREA<BR>&gt; (ccamp) Common Control and Measurement Plane WG<BR>&gt; =
(mpls)=20
  Multiprotocol Label Switching WG<BR>&gt; (tewg) Internet Traffic =
Engineering=20
  WG<BR>&gt;<BR>&gt; TRANSPORT AREA<BR>&gt; (dccp) Datagram Congestion =
Control=20
  Protocol WG<BR>&gt; (enum) Telephone Number Mapping WG<BR>&gt; =
(ieprep)=20
  Internet Emergency Preparedness WG<BR>&gt; (ippm) IP Performance =
Metrics=20
  WG<BR>&gt; (nsis) Next Steps in Signaling WG<BR>&gt; (pwe3) Pseudo =
Wire=20
  Emulation Edge to Edge WG<BR>&gt; (rddp) Remote Direct Data Placement=20
  WG<BR>&gt; (rmt) Reliable Multicast Transport WG<BR>&gt; (rohc) Robust =
Header=20
  Compression WG<BR>&gt; (rserpool) Reliable Server Pooling WG<BR>&gt; =
(sip)=20
  Session Initiation Protocol WG<BR>&gt; (sipping) Session Initiation =
Proposal=20
  Investigation=20
WG<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt;</FONT><BR></DIV></BLOCKQUOTE></FONT></=
BODY></HTML>

------=_NextPart_000_0071_01C3301F.D964FEE0--



