
From Alan.Borland@BoldonJames.com  Wed Mar 13 03:21:27 2013
Return-Path: <Alan.Borland@BoldonJames.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4C9BA21F8D79 for <plasma@ietfa.amsl.com>; Wed, 13 Mar 2013 03:21:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CQbSuK5ujmlb for <plasma@ietfa.amsl.com>; Wed, 13 Mar 2013 03:21:26 -0700 (PDT)
Received: from outgoing.boldonjames.com (outgoing.boldonjames.com [195.217.233.97]) by ietfa.amsl.com (Postfix) with ESMTP id 60E8521F8D37 for <plasma@ietf.org>; Wed, 13 Mar 2013 03:21:24 -0700 (PDT)
Received: from BJEX3.corps.boldonjames.com ([fe80::b85c:343b:66b0:b132]) by bjex3.corps.boldonjames.com ([fe80::b85c:343b:66b0:b132%10]) with mapi id 14.02.0328.009; Wed, 13 Mar 2013 10:21:21 +0000
From: Alan Borland <Alan.Borland@BoldonJames.com>
To: "'plasma@ietf.org'" <plasma@ietf.org>
Thread-Topic: Verifying the signature of the LockBox.
Thread-Index: Ac4f0qAKuaW+39TnSmuvI2yWCWh8WA==
Date: Wed, 13 Mar 2013 10:21:20 +0000
Message-ID: <0E5C08E16910F1409605822C0EC4DB56223562C4@bjex3.corps.boldonjames.com>
Accept-Language: en-GB, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [10.20.0.31]
x-protectivemarking: [BJ/UNMARKED/EXTERNAL]
Content-Type: multipart/alternative; boundary="_000_0E5C08E16910F1409605822C0EC4DB56223562C4bjex3corpsboldo_"
MIME-Version: 1.0
Subject: [plasma] Verifying the signature of the LockBox.
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Mar 2013 10:21:27 -0000

--_000_0E5C08E16910F1409605822C0EC4DB56223562C4bjex3corpsboldo_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

[Boldon James classification: UNMARKED EXTERNAL]

When we open a message we have to determine if the message is a traditional=
 S/MIME message or a Plasma message.  This is done by inspecting the CMS en=
velopedData layer looking for a Plasma LockBox. If the lockbox is found we =
verify the SignedData signature, but this got me thinking.  Should we verif=
y just the integrity of the signature itself or should we also perform a fu=
ll certificate path validation as well?   This would mean every user needs =
to trust a certificate from the Plasma Server (additional overhead - is thi=
s an issue?), but then if the Plasma Server is somehow compromised this wou=
ld be a way of returning the error to the client.

I couldn't decide either way, at the moment we're doing a full certificate =
path validation.

Alan.

Alan Borland

Boldon James Limited, a QinetiQ company
Mobile:        +44 (0)7810 556709
Direct:         +44 (0)1270 507841
Switch:        +44 (0)1270 507800
Email:          alan.borland@boldonjames.com<mailto:alan.borland@boldonjame=
s.com>
Email (R):    abborland@qinetiq.r.mil.uk<mailto:abborland@qinetiq.r.mil.uk>
Web:           www.boldonjames.com






--_000_0E5C08E16910F1409605822C0EC4DB56223562C4bjex3corpsboldo_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<style>
<!--
@font-face
	{font-family:"Cambria Math"}
@font-face
	{font-family:Calibri}
@font-face
	{font-family:Tahoma}
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
	{color:#0563C1;
	text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
	{color:#954F72;
	text-decoration:underline}
span.EmailStyle17
	{font-family:"Calibri","sans-serif";
	color:windowtext}
.MsoChpDefault
	{font-family:"Calibri","sans-serif"}
@page WordSection1
	{margin:72.0pt 72.0pt 72.0pt 72.0pt}
div.WordSection1
	{}
-->
</style>
</head>
<body lang=3D"EN-GB" link=3D"#0563C1" vlink=3D"#954F72">
<style>
<!--
@font-face
	{font-family:Calibri}
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
	{color:purple;
	text-decoration:underline}
span.EmailStyle17
	{font-family:"Calibri","sans-serif";
	color:windowtext}
.MsoChpDefault
	{font-family:"Calibri","sans-serif"}
@page WordSection1
	{margin:72.0pt 72.0pt 72.0pt 72.0pt}
-->
</style>
<div id=3D"Classifier Header">
<p style=3D"text-align:left; text-indent:0pt; padding:0pt 0pt 0pt 0pt; marg=
in:0pt 0pt 0pt 0pt">
<span style=3D"color:#000000; background-color:transparent; font-family:Ari=
al; font-size:9pt; font-weight:normal; font-style:normal">[Boldon James cla=
ssification:
<span style=3D"color:#000000; background-color:transparent; font-family:Ari=
al; font-size:9pt; font-weight:normal; font-style:normal">
<span style=3D"color:#00C000">UNMARKED</span></span></span><span style=3D"c=
olor:#000000; background-color:transparent; font-family:Arial; font-size:9p=
t; font-weight:normal; font-style:normal"><span style=3D"color:#000000; bac=
kground-color:transparent; font-family:Arial; font-size:9pt; font-weight:no=
rmal; font-style:normal"><span>
</span><span>EXTERNAL</span></span></span><span style=3D"color:#000000; bac=
kground-color:transparent; font-family:Arial; font-size:9pt; font-weight:no=
rmal; font-style:normal"><span style=3D"color:#000000; background-color:tra=
nsparent; font-family:Arial; font-size:9pt; font-weight:normal; font-style:=
normal"></span></span><span style=3D"color:#000000; background-color:transp=
arent; font-family:Arial; font-size:9pt; font-weight:normal; font-style:nor=
mal">]</span></p>
<br>
</div>
<div>
<div class=3D"WordSection1">
<p class=3D"MsoNormal">When we open a message we have to determine if the m=
essage is a traditional S/MIME message or a Plasma message.&nbsp; This is d=
one by inspecting the CMS envelopedData layer looking for a Plasma LockBox.=
 If the lockbox is found we verify the
 SignedData signature, but this got me thinking.&nbsp; Should we verify jus=
t the integrity of the signature itself or should we also perform a full ce=
rtificate path validation as well? &nbsp;&nbsp;This would mean every user n=
eeds to trust a certificate from the Plasma Server
 (additional overhead - is this an issue?), but then if the Plasma Server i=
s somehow compromised this would be a way of returning the error to the cli=
ent.</p>
<p class=3D"MsoNormal">&nbsp;</p>
<p class=3D"MsoNormal">I couldn't decide either way, at the moment we're do=
ing a full certificate path validation.</p>
<p class=3D"MsoNormal">&nbsp;</p>
<p class=3D"MsoNormal">Alan.</p>
<p class=3D"MsoNormal">&nbsp;</p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt; font-family:&quo=
t;Tahoma&quot;,&quot;sans-serif&quot;; color:navy">Alan Borland</span></b><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:7.5pt; font-family:&quot;Ta=
homa&quot;,&quot;sans-serif&quot;; color:#999999"><br>
</span><b><span lang=3D"EN-US" style=3D"font-size:10.0pt; font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;; color:#002B7F">Boldon James Limited,
</span></b><span lang=3D"EN-US" style=3D"font-size:10.0pt; font-family:&quo=
t;Tahoma&quot;,&quot;sans-serif&quot;; color:#002B7F">a QinetiQ company</sp=
an><span lang=3D"EN-US" style=3D"font-size:10.0pt; font-family:&quot;Arial&=
quot;,&quot;sans-serif&quot;; color:black">
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt; font-family:&quot;T=
ahoma&quot;,&quot;sans-serif&quot;; color:#999999">Mobile:&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; &#43;44 (0)7810 556709<br>
Direct:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;44 (0)1270 507=
841<br>
Switch: &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#43;44 (0)1270 507800<br>
Email:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"mai=
lto:alan.borland@boldonjames.com" target=3D"_blank"><span style=3D"color:bl=
ue">alan.borland@boldonjames.com</span></a><br>
Email (R):&nbsp;&nbsp;&nbsp;&nbsp;<a href=3D"mailto:abborland@qinetiq.r.mil=
.uk" target=3D"_blank"><span style=3D"color:blue">abborland@qinetiq.r.mil.u=
k</span></a><br>
Web:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D=
"" target=3D"_blank" title=3D"http://www.boldonjames.com/"><span style=3D"c=
olor:blue">www.boldonjames.com</span></a></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt; font-family:&quot;T=
ahoma&quot;,&quot;sans-serif&quot;; color:#999999">&nbsp;</span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:9.0pt; font-=
family:&quot;Tahoma&quot;,&quot;sans-serif&quot;; color:#999999">&nbsp;</sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt; font-family:&quot;T=
imes New Roman&quot;,&quot;serif&quot;; color:#1F497D">&nbsp;</span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Arial&quot;,&quot;s=
ans-serif&quot;; color:black">&nbsp;</span></p>
<p class=3D"MsoNormal">&nbsp;</p>
</div>
</div>
</body>
</html>

--_000_0E5C08E16910F1409605822C0EC4DB56223562C4bjex3corpsboldo_--

From ietf@augustcellars.com  Wed Mar 13 05:44:43 2013
Return-Path: <ietf@augustcellars.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 93E6121F8941 for <plasma@ietfa.amsl.com>; Wed, 13 Mar 2013 05:44:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.598
X-Spam-Level: 
X-Spam-Status: No, score=-3.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NJu0PrXmen1L for <plasma@ietfa.amsl.com>; Wed, 13 Mar 2013 05:44:41 -0700 (PDT)
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.176]) by ietfa.amsl.com (Postfix) with ESMTP id AC40821F88F7 for <plasma@ietf.org>; Wed, 13 Mar 2013 05:44:41 -0700 (PDT)
Received: from Philemon (dhcp-1431.meeting.ietf.org [130.129.20.49]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp4.pacifier.net (Postfix) with ESMTPSA id 0F75738EFC; Wed, 13 Mar 2013 05:44:40 -0700 (PDT)
From: "Jim Schaad" <ietf@augustcellars.com>
To: "'Alan Borland'" <Alan.Borland@BoldonJames.com>, <plasma@ietf.org>
References: <0E5C08E16910F1409605822C0EC4DB56223562C4@bjex3.corps.boldonjames.com>
In-Reply-To: <0E5C08E16910F1409605822C0EC4DB56223562C4@bjex3.corps.boldonjames.com>
Date: Wed, 13 Mar 2013 08:44:07 -0400
Message-ID: <05bb01ce1fe8$749d1b50$5dd751f0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_05BC_01CE1FC6.ED8DC540"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQHVAr/odME5PYMQgzzHL9U11NMvp5iVywMA
Content-Language: en-us
Subject: Re: [plasma] Verifying the signature of the LockBox.
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Mar 2013 12:44:43 -0000

This is a multipart message in MIME format.

------=_NextPart_000_05BC_01CE1FC6.ED8DC540
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

It is my believe you should perform the full path verification.  If you
don't then you have no confidence in any of the signed attributes associated
with the signature such as the URL for the plasma server and thus go
someplace you don't want to and start the plasma protocol.

 

Jim

 

 

From: plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] On Behalf Of
Alan Borland
Sent: Wednesday, March 13, 2013 6:21 AM
To: 'plasma@ietf.org'
Subject: [plasma] Verifying the signature of the LockBox.

 

[Boldon James classification: UNMARKED EXTERNAL]

 

When we open a message we have to determine if the message is a traditional
S/MIME message or a Plasma message.  This is done by inspecting the CMS
envelopedData layer looking for a Plasma LockBox. If the lockbox is found we
verify the SignedData signature, but this got me thinking.  Should we verify
just the integrity of the signature itself or should we also perform a full
certificate path validation as well?   This would mean every user needs to
trust a certificate from the Plasma Server (additional overhead - is this an
issue?), but then if the Plasma Server is somehow compromised this would be
a way of returning the error to the client.

 

I couldn't decide either way, at the moment we're doing a full certificate
path validation.

 

Alan.

 

Alan Borland


Boldon James Limited, a QinetiQ company 

Mobile:        +44 (0)7810 556709
Direct:         +44 (0)1270 507841
Switch:        +44 (0)1270 507800
Email:          alan.borland@boldonjames.com
Email (R):    abborland@qinetiq.r.mil.uk
Web:           www.boldonjames.com

 

 

 

 

 


------=_NextPart_000_05BC_01CE1FC6.ED8DC540
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><META =
HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.msochpdefault, li.msochpdefault, div.msochpdefault
	{mso-style-name:msochpdefault;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Calibri","sans-serif";}
span.emailstyle17
	{mso-style-name:emailstyle17;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>It is my believe you should perform the full =
path verification.&nbsp; If you don&#8217;t then you have no confidence =
in any of the signed attributes associated with the signature such as =
the URL for the plasma server and thus go someplace you don&#8217;t want =
to and start the plasma protocol.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'>Jim<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
plasma-bounces@ietf.org [mailto:plasma-bounces@ietf.org] <b>On Behalf Of =
</b>Alan Borland<br><b>Sent:</b> Wednesday, March 13, 2013 6:21 =
AM<br><b>To:</b> 'plasma@ietf.org'<br><b>Subject:</b> [plasma] Verifying =
the signature of the LockBox.<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div id=3D"Classifier Header"><p =
style=3D'margin:0in;margin-bottom:.0001pt'><span lang=3DEN-GB =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:black'>[B=
oldon James classification: </span><span lang=3DEN-GB =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#00C000'>=
UNMARKED</span><span lang=3DEN-GB =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:black'> =
EXTERNAL]</span><span lang=3DEN-GB><o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif"'><o:p>&nbsp;</o:p></span></p></div><div><div><p =
class=3DMsoNormal><span lang=3DEN-GB>When we open a message we have to =
determine if the message is a traditional S/MIME message or a Plasma =
message.&nbsp; This is done by inspecting the CMS envelopedData layer =
looking for a Plasma LockBox. If the lockbox is found we verify the =
SignedData signature, but this got me thinking.&nbsp; Should we verify =
just the integrity of the signature itself or should we also perform a =
full certificate path validation as well? &nbsp;&nbsp;This would mean =
every user needs to trust a certificate from the Plasma Server =
(additional overhead - is this an issue?), but then if the Plasma Server =
is somehow compromised this would be a way of returning the error to the =
client.<o:p></o:p></span></p><p class=3DMsoNormal><span =
lang=3DEN-GB>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span =
lang=3DEN-GB>I couldn't decide either way, at the moment we're doing a =
full certificate path validation.<o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB>Alan.<o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><b><span lang=3DEN-GB =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:navy'>A=
lan Borland</span></b><span lang=3DEN-GB><o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'font-size:7.5pt;font-family:"Tahoma","sans-serif";color:#999999'=
><br></span><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#002B7F=
'>Boldon James Limited, </span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#002B7F=
'>a QinetiQ company</span><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:black'> =
</span><span lang=3DEN-GB><o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#999999=
'>Mobile:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +44 (0)7810 =
556709<br>Direct:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +44 =
(0)1270 507841<br>Switch: &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; +44 =
(0)1270 =
507800<br>Email:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
<a href=3D"mailto:alan.borland@boldonjames.com" =
target=3D"_blank">alan.borland@boldonjames.com</a><br>Email =
(R):&nbsp;&nbsp;&nbsp;&nbsp;<a =
href=3D"mailto:abborland@qinetiq.r.mil.uk" =
target=3D"_blank">abborland@qinetiq.r.mil.uk</a><br>Web:&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"" =
target=3D"_blank" =
title=3D"http://www.boldonjames.com/">www.boldonjames.com</a></span><span=
 lang=3DEN-GB><o:p></o:p></span></p><p class=3DMsoNormal><span =
lang=3DEN-GB =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#999999=
'>&nbsp;</span><span lang=3DEN-GB><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Tahoma","sans-serif";color:#999999'=
>&nbsp;</span><span lang=3DEN-GB><o:p></o:p></span></p><p =
class=3DMsoNormal><span lang=3DEN-GB =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:#1F497D'>&nbsp;</span><span =
lang=3DEN-GB><o:p></o:p></span></p><p class=3DMsoNormal><span =
lang=3DEN-GB =
style=3D'font-family:"Arial","sans-serif";color:black'>&nbsp;</span><span=
 lang=3DEN-GB><o:p></o:p></span></p><p class=3DMsoNormal><span =
lang=3DEN-GB>&nbsp;<o:p></o:p></span></p></div></div></div></div></body><=
/html>
------=_NextPart_000_05BC_01CE1FC6.ED8DC540--


From ietf@augustcellars.com  Mon Mar 18 16:18:15 2013
Return-Path: <ietf@augustcellars.com>
X-Original-To: plasma@ietfa.amsl.com
Delivered-To: plasma@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8D2F421F8BBA for <plasma@ietfa.amsl.com>; Mon, 18 Mar 2013 16:18:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[AWL=0.000,  BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5RXyoPyMMon3 for <plasma@ietfa.amsl.com>; Mon, 18 Mar 2013 16:18:14 -0700 (PDT)
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.176]) by ietfa.amsl.com (Postfix) with ESMTP id BECD521F8B65 for <plasma@ietf.org>; Mon, 18 Mar 2013 16:18:14 -0700 (PDT)
Received: from Philemon (50-39-222-11.bvtn.or.frontiernet.net [50.39.222.11]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jimsch@nwlink.com) by smtp4.pacifier.net (Postfix) with ESMTPSA id 876FC38F04 for <plasma@ietf.org>; Mon, 18 Mar 2013 16:18:14 -0700 (PDT)
From: "Jim Schaad" <ietf@augustcellars.com>
To: <plasma@ietf.org>
References: <20130318230654.12822.91956.idtracker@ietfa.amsl.com>
In-Reply-To: <20130318230654.12822.91956.idtracker@ietfa.amsl.com>
Date: Mon, 18 Mar 2013 16:17:41 -0700
Message-ID: <095401ce242e$ca228ac0$5e67a040$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQGW8MVtTe6chNKXfe861QhgGIEJa5kae61Q
Content-Language: en-us
Subject: [plasma] FW: New Version Notification for draft-schaad-plasma-cms-04.txt
X-BeenThere: plasma@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "The PoLicy Augmented S/Mime \(plasma\) bof discussion list." <plasma.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/plasma>, <mailto:plasma-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/plasma>
List-Post: <mailto:plasma@ietf.org>
List-Help: <mailto:plasma-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/plasma>, <mailto:plasma-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Mar 2013 23:18:15 -0000

Update draft with a new way to handle encoding recipient infos.

Please look at and make sure that it makes sense.  Recommendations on =
other approaches should be discussed if you feel they are better than =
the one offered here.  I am not emotionally attached to this encoding =
and we discussed a couple of alternatives before choosing this one.

Jim


> -----Original Message-----
> From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]
> Sent: Monday, March 18, 2013 4:07 PM
> To: ietf@augustcellars.com
> Subject: New Version Notification for draft-schaad-plasma-cms-04.txt
>=20
>=20
> A new version of I-D, draft-schaad-plasma-cms-04.txt
> has been successfully submitted by Jim Schaad and posted to the
> IETF repository.
>=20
> Filename:	 draft-schaad-plasma-cms
> Revision:	 04
> Title:		 Plasma Service Cryptographic Message Syntax (CMS)
> Processing
> Creation date:	 2013-03-18
> Group:		 Individual Submission
> Number of pages: 31
> URL:             =
http://www.ietf.org/internet-drafts/draft-schaad-plasma-cms-
> 04.txt
> Status:          =
http://datatracker.ietf.org/doc/draft-schaad-plasma-cms
> Htmlized:        http://tools.ietf.org/html/draft-schaad-plasma-cms-04
> Diff:            =
http://www.ietf.org/rfcdiff?url2=3Ddraft-schaad-plasma-cms-04
>=20
> Abstract:
>    Secure MIME (S/MIME) defined a method of placing security labels on =
a
>    Cryptographic Message Syntax (CMS) object.  These labels are placed
>    as part of the data signed and validated by the parties.  This =
means
>    that the message content is visible to the recipient prior to the
>    label enforcement.  A new model for enforcement of policy using a
>    third party is described in RFC TBD
>    [I.D-draft-freeman-plasma-requirements].  This is the Policy
>    Augmented S/MIME (PLASMA) system.  This document provides the =
details
>    needed to implement the new Plasma model in the CMS infrastructure.
>=20
>    An additional benefit of using the Plasma module is that the =
server,
>    based on policy, manages who has access to the message and how the
>    keys are protected.
>=20
>    The document details how the client encryption and decryption
>    processes are performed, defines how to construct the CMS recipient
>    info structure, a new content to hold the data required for the
>    Plasma server to store the keys and policy information.  The =
document
>    does not cover the protocol between the client and the Plasma =
policy
>    enforcement server.  One example of the client/server protocol can =
be
>    found in RFC TBD [plasma-token].
>=20
>=20
>=20
>=20
> The IETF Secretariat

