From owner-ietf-smime@mail.imc.org  Tue Jul  1 05:57:16 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA04753
	for <smime-archive@lists.ietf.org>; Tue, 1 Jul 2003 05:57:15 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h619D0FK031127
	for <ietf-smime-bks@above.proper.com>; Tue, 1 Jul 2003 02:13:00 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h619D0uv031126
	for ietf-smime-bks; Tue, 1 Jul 2003 02:13:00 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz ([130.216.35.151])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h619CwFK030843
	for <ietf-smime@imc.org>; Tue, 1 Jul 2003 02:12:59 -0700 (PDT)
	(envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33])
	by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6198iXX012517;
	Tue, 1 Jul 2003 21:08:44 +1200
Received: (from pgut001@localhost)
	by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6198gB18508;
	Tue, 1 Jul 2003 21:08:42 +1200
Date: Tue, 1 Jul 2003 21:08:42 +1200
Message-Id: <200307010908.h6198gB18508@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: blake@brutesquadlabs.com, ietf-smime@imc.org, jimsch@exmsft.com,
        julien.stern@cryptolog.com
Subject: RE: (Practical) S/MIME certificate chain handling
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


"Blake Ramsdell" <blake@brutesquadlabs.com> writes:

>I agree, and that's why they send all the certificates along with messages to
>this date.  By "they", I mean S/MIME-enabled versions of Netscape, Outlook
>Express, Outlook, and the S/MIME plugin for Eudora that I wrote.

Just as another data point, a small portion of my certificate zoo consists of
cert chains from S/MIME sigs, and every one of them is a full chain (or at
least some sort of chain), rather than a single cert.  I don't track where
they originally came from, but they cover (at least) Outlook (many versions),
Netscape, and a few S/MIME gateways that auto-sign everything passing through
them (most of the stuff I've seen in general mail in fact would be auto-
signed, either by a gateway or because the sender turned it on and forgot
about it).  I do have some single-cert chains, but they're from oddball
applications like EDI messaging (the certs have EDI altnames and whatnot)
which aren't representative of general usage.

Peter.


From vy9alwxek@yahoo.ca  Tue Jul  1 06:04:56 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA04988
	for <smime-archive@ietf.org>; Tue, 1 Jul 2003 06:04:56 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19XI0O-0001kn-00
	for smime-archive@ietf.org; Tue, 01 Jul 2003 06:04:56 -0400
Received: from [61.159.235.36] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19XI09-0001kd-00
	for smime-archive@ietf.org; Tue, 01 Jul 2003 06:04:45 -0400
Received: from [176.44.224.158] by 132.151.6.1; Mon, 30 Jun 2003 17:57:58 -0500
Message-ID: <y2thx0$n-88$f$-k3@1mt.82.iv1>
From: "Nathan Mckinley" <vy9alwxek@yahoo.ca>
Reply-To: "Nathan Mckinley" <vy9alwxek@yahoo.ca>
To: smime-archive@ietf.org
Subject: Bad Credit is OK Gold Visa Card ze jjkmoozai
Date: Mon, 30 Jun 03 17:57:58 GMT
X-Mailer: MIME-tools 5.503 (Entity 5.501)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="819.4F48E..9._E2D_3B6."
X-Priority: 3
X-MSMail-Priority: Normal


--819.4F48E..9._E2D_3B6.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>access</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://cramer:churchwoman@%63%72%65%64it.%65c=
%6F%6D%6D%65%72%63%65%32%3020.c%6F%6D">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://participate:approximant@%63%72%65%64it.%65c=
%6F%6D%6D%65%72%63%65%32%3020.c%6F%6D">
<img border=3D"0" src=3D"http://alkene:rena@%63=
%72%65%64it.%65c%6F%6D%6D%65%72%63%65%32%3020.c%6F%6D/credit.gif" width=3D=
"636" height=3D"429"></a></p>
<p><a href=3D"http://sensuous:exceed@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
saginawbouncerxk ssrtcb ncj dadfjafqjpbko hvkvmzk
rik hyen fjil vqdzydzodpb
p sgrskj rryb
</html>
z vxbdwj osb
jx
 ucdink oolu
 nxyldkrl v ku qu

--819.4F48E..9._E2D_3B6.--



From owner-ietf-smime@mail.imc.org  Tue Jul  1 18:15:18 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA19099
	for <smime-archive@lists.ietf.org>; Tue, 1 Jul 2003 18:15:17 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LodFK087936
	for <ietf-smime-bks@above.proper.com>; Tue, 1 Jul 2003 14:50:39 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h61Lodk8087935
	for ietf-smime-bks; Tue, 1 Jul 2003 14:50:39 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LocFK087918
	for <ietf-smime@imc.org>; Tue, 1 Jul 2003 14:50:39 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Tue, 1 Jul 2003 14:50:35 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Sean Turner'" <turners@ieca.com>
Subject: DRAFT S/MIME working group agenda
Date: Tue, 1 Jul 2003 14:50:35 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAH5/oOPiN10yLsjkx1W//HgEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Here is a draft agenda based on the response so far.  This will most
likely be the final agenda unless Sean or I hear something different.

Introductions (Sean Turner)
Working group status (Sean Turner)
CMS and ESS examples update (Paul Hoffman)
MSGbis and CERTbis update (Blake Ramsdell)
Interoperability matrix update (Jim Schaad)
KEM overview (Jim Schaad)
PSS status (Jim Schaad)
ESSbis overview (Jim Schaad)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From owner-ietf-smime@mail.imc.org  Wed Jul  2 07:21:31 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA05573
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 07:21:31 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AuuFK051294
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 03:56:56 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62AuuC7051292
	for ietf-smime-bks; Wed, 2 Jul 2003 03:56:56 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AutFK051285
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 03:56:55 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03059;
	Wed, 2 Jul 2003 06:56:54 -0400 (EDT)
Message-Id: <200307021056.GAA03059@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-examples-11.txt
Date: Wed, 02 Jul 2003 06:56:53 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Examples of S/MIME Messages
	Author(s)	: P. Hoffman
	Filename	: draft-ietf-smime-examples-11.txt
	Pages		: 8
	Date		: 2003-7-1
	
This document gives examples of message bodies formatted using S/MIME.
Specifically, it has examples of Cryptographic Message Syntax (CMS)
objects, S/MIME messages (including the MIME formatting), and Enhanced
Security Services for S/MIME (ESS). It includes examples of most or all
common CMS and ESS formats; in addition, it gives examples that show
common pitfalls in implementing CMS. The purpose of this document is to
help increase interoperability for S/MIME and other protocols that rely
on CMS.
This draft is being discussed on the 'ietf-smime' mailing list.  To
join the list, send a message to <ietf-smime-request@imc.org> with the
single word 'subscribe' in the body of the message.  Also, there is a
Web site for the mailing list at <http://www.imc.org/ietf-smime/>.

This draft is being discussed on the 'ietf-smime' mailing list.  To
join the list, send a message to <ietf-smime-request@imc.org> with the
single word 'subscribe' in the body of the message.  Also, there is a
Web site for the mailing list at <http://www.imc.org/ietf-smime/>.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-examples-11.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-examples-11.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-examples-11.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-1134908.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-examples-11.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-examples-11.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-1134908.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-smime@mail.imc.org  Wed Jul  2 07:21:47 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA05602
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 07:21:46 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApUFK050485
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 03:51:30 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62ApUV0050484
	for ietf-smime-bks; Wed, 2 Jul 2003 03:51:30 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApTFK050473
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 03:51:30 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA01615;
	Wed, 2 Jul 2003 06:51:26 -0400 (EDT)
Message-Id: <200307021051.GAA01615@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
CC: sipping@ietf.org, ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-mahy-sipping-smime-vs-digest-01.txt
Date: Wed, 02 Jul 2003 06:51:26 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.


	Title		: Discussion of suitability: S/MIME instead of Digest 
                          Authentication in the Session Initiation Protocol 
                         (SIP)
	Author(s)	: R. Mahy
	Filename	: draft-mahy-sipping-smime-vs-digest-01.txt
	Pages		: 11
	Date		: 2003-7-1
	
Digest authentication (as defined in RFC2617) is used in SIP
(RFC3261) for user authentication, and less frequently for message
integrity of MIME bodies carried in SIP.  Various members of the IETF
security community have periodically suggested that Digest should be
deprecated in favor of the SIP use of S/MIME (RFC2633), support for
which was recently introduced in RFC3261.  The author seeks clarity
from the IETF security community on behalf of the SIP community about
the feasibility and possible benefits of using S/MIME instead of
Digest in one or both of these applications.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-mahy-sipping-smime-vs-digest-01.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-1133733.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-mahy-sipping-smime-vs-digest-01.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-1133733.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-smime@mail.imc.org  Wed Jul  2 10:27:40 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA23300
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 10:27:40 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwHFK057578
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 06:58:17 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62DwH3b057577
	for ietf-smime-bks; Wed, 2 Jul 2003 06:58:17 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from moorabbin.nexor.co.uk (moorabbin.nexor.co.uk [80.6.88.100])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwAFK057564
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 06:58:16 -0700 (PDT)
	(envelope-from Graeme.Lunt@nexor.co.uk)
Received: from typhoon (actually host 210.53.63.193.in-addr.arpa)
          by moorabbin.nexor.co.uk with ESMTP (Mailer) with ESMTP;
          Wed, 2 Jul 2003 14:55:15 +0100
Reply-To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Graeme Lunt <Graeme.Lunt@nexor.co.uk>
To: "'jimsch'" <jimsch@exmsft.com>, "'Sean P. Turner'" <turners@ieca.com>
Cc: "'ietf-smime'" <ietf-smime@imc.org>
Subject: RE: Signed Receipts and Mail Lists
Date: Wed, 2 Jul 2003 14:56:58 +0100
Organization: Nexor
Message-ID: <001f01c340a1$cf01f470$d2353fc1@nexor.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4024
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
In-Reply-To: <009701c33ce3$a86b4170$3d0311ac@augustcellars.local>
X-Spam-Status: No, hits=-100.7 required=5.0
               tests=IN_REP_TO,NOSPAM_INC,QUOTED_EMAIL_TEXT,SPAM_PHRASE_03_05,
               USER_IN_WHITELIST version=2.43
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Jim,
 
> If we adopted the solution you gave, what limits me from making
> arbitrary statements about who I am in this field that then need to be

> independently verified by the receipt processing code?  (I.e. what if 
> I put the fact that I am turners@ieca.com in this field and sign with 
> my jimsch@exmsft.com certificate).

First off, having looked in more detail at 2634 it implicitly requires
each mail list to have its own certificate. In particular, the
EntityIdentifier, used in MLExpansionHistory, refers only to a
certificate. So having a single certificate for an MLA supporting
multiple lists would cause the loop detection algorithm to fail.  

So what I was looking at (a single certificate for a mail list agent
supporting multiple lists) is a more fundamental change than I first
thought.

But back to your question. 

The basic answer is that nothing would limit you. Do you see this as a
major issue?

x400wrap has a similar case where the content being signed contains an
"originator" field. 

"Receiving agents SHOULD check that the originator address in the X.400
content matches an X.400 address in the signer's certificate, if X.400
addresses are present in the certificate and an originator address is
available in the content. A receiving agent SHOULD provide some explicit
alternate processing of the message if this comparison fails, which may
be to display a message that shows the recipient the addresses in the
certificate or other certificate details."

I think that similar wording to section 4.3 of this draft may be
acceptable?

This wording allows us to take our own action to correlate the x400
originator to the signer in the case that they don't match (we use
attribute certificates to do the signer to originator validation). 

So for your example, I may see something like:

"signed receipt from jimsch@exmsft.com on behalf of turners@ieca.com at
<time>"

The receiptFrom field I proposed is primarily aimed at supporting the
correlation of the signed receipt to the original recipient by providing
original address the signed receipt was requested from. 

There are a number of reasons why I may not be able to match the
address[es] (subjectAltName) from the certificate to one of the
addresses I to:

a) Valid aliases not in the subjectAltNames of the certificate

b) Signed receipt from a recipient who received the message as a result
of ML expansion.  

c) Mail redirections - e.g. sent to "ceo@corp.com" which redirects to a
personal mailbox.
Similar to a). 


Graeme


> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org 
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Graeme Lunt
> > Sent: Wednesday, June 25, 2003 12:40 AM
> > To: 'Sean P. Turner'
> > Cc: 'ietf-smime'
> > Subject: RE: Signed Receipts and Mail Lists
> > 
> > 
> > 
> > Sean,
> >  
> > > I'm not sure that the MLA returns a receipt on behalf of the ML 
> > > members.
> > 
> > OK - if an MLA should not return signed receipts then there is not a

> > problem with my scenario.
> > 
> > > I looked through ESS again and I couldn't find anything
> > that said if a
> > > message enters an MLA with a signed receipt request that it
> > 
> > > shouldn't or should return a receipt.    
> > 
> > Is an MLA considered a "receiving agent"/"receiving 
> > software"/"processing software" in section 2.3 of ESS? I had assumed

> > that it was but agree it is unclear.
> > 
> > > Typically (I think), originators want to know that the
> > final recipient
> > got
> > > the message not whether the MLA got it.
> > 
> > I think there are arguments for both. If an originator
> sends a message
> > to:
> > 
> > complaints@bigbank.co.uk
> > 
> > the originator probably only wants to know that it got to the 
> > complaints department at bigbank. The originator doesn't want to 
> > know (and bigbank doesn't want to let the originator know) which 
> > individuals within bigbank read the message.
> > 
> > > Then again maybe I didn't understand your scenario.
> > 
> > I don't think the originator needs to understand if the addresses 
> > they are requesting signed receipts from are address lists or not. 
> > If an originator sends a message to two recipients - one a mail 
> > list, one an individual - and requests first tier signed receipts, 
> > they will never receive a signed receipt from the mail list 
> > recipient. The user may find this unexpected. Correlation software
> > *may* be able to detect a mail list recipient and handle it
> > appropriately.
> > 
> > 
> > Graeme
> > 
> > 
> 
> 



From owner-ietf-smime@mail.imc.org  Wed Jul  2 11:54:45 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA28291
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 11:54:44 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FFgFK062351
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 08:15:42 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62FFgbh062350
	for ietf-smime-bks; Wed, 2 Jul 2003 08:15:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FFaFK062339
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 08:15:36 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Wed, 2 Jul 2003 08:15:32 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Gregory S. Chudov'" <chudov@cryptopro.ru>
Subject: GOST with CMS
Date: Wed, 2 Jul 2003 08:15:32 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbWMMVYx/3k2rzkaJBoDzmAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


A new draft is available, profiling the use of the Russian national
cryptography standards (GOST) in CMS:

Title: Cryptographic Message Syntax (CMS) algorithms for GOST 28147-89,
GOST R 34.10-94, GOST R 34.10-2001, GOST R 34.11-94.

Authors: Serguei Leontiev, Vladimir Popov

Filename: draft-leontiev-cryptopro-cpcms-00.txt

http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

Gregory Chudov has asked to introduce this draft to the group at the
next working group meeting, and we will be providing him with some time
to do that.  I presume that this draft will become a draft of the
working group in the next revision.

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From owner-ietf-smime@mail.imc.org  Wed Jul  2 12:12:13 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA29118
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 12:12:13 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FiXFK066678
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 08:44:33 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62FiXJW066677
	for ietf-smime-bks; Wed, 2 Jul 2003 08:44:33 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from [63.202.92.152] (adsl-63-202-92-152.dsl.snfc21.pacbell.net [63.202.92.152])
	(authenticated bits=0)
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FiSFN066656;
	Wed, 2 Jul 2003 08:44:30 -0700 (PDT)
	(envelope-from phoffman@imc.org)
Mime-Version: 1.0
X-Sender: phoffman@mail.imc.org
Message-Id: <p05210609bb28ab8d2f11@[63.202.92.152]>
In-Reply-To: <200307021056.GAA03059@ietf.org>
References: <200307021056.GAA03059@ietf.org>
X-Habeas-SWE-1: winter into spring
X-Habeas-SWE-2: brightly anticipated
X-Habeas-SWE-3: like Habeas SWE (tm)
X-Habeas-SWE-4: Copyright 2002 Habeas (tm)
X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this
X-Habeas-SWE-6: email in exchange for a license for this Habeas
X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant
X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this
X-Habeas-SWE-9: mark in spam to <http://www.habeas.com/report>.
Date: Wed, 2 Jul 2003 08:44:28 -0700
To: ietf-smime-examples@imc.org, ietf-smime@imc.org
From: Paul Hoffman / IMC <phoffman@imc.org>
Subject: Status of the examples draft
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Hi again. The -11 draft has the following changes:
5.1.bin
5.3.bin
5.4.bin
5.6.bin
5.7.bin
5.10.bin
8.2.bin
11.1.bin
11.2.bin

It would be great if everyone who has tested can re-test with these 
new examples.

BTW, I forgot to change the title of 6.3 to say RC2/128, and will do 
so in the -12 draft. (Just to be sure, I have already started the -12 
draft so I don't space out again...)

I would like to update the chart below for the -11 draft soon so we 
can move it to IETF last call.

======================================

Status of the examples in -10

4. Trivial Examples

4.1 ContentInfo with Data type, BER
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

4.2 ContentInfo with Data type, DER
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.  Signed-data
   Jim Schaad pointed out that many examples had the
     signatureAlgorithm of 1.2.840.10040.4.1 (dsa) but it should instead
     be 1.2.840.10040.4.3 (dsaWithSha1).
   The general decision was that the examples should have dsaWithSha1.
   John Pawling and Sue Beauchamp at DigitalNet agreed to re-generate
     the examples.

5.1 Basic signed content, DSS
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.2 Basic signed content, RSA
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.3 Basic signed content, detached content
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
	Contains Alice's RSA certificate
	No content hint unsigned attribute
     signatureAlgorithm is dsa but should be dsaWithSha1
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.4 Fancier signed content
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.
     Countersigner is Alice, not Diane
     No content hint
   Sue Beauchamp sent new example file.

5.5 All RSA signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.6 Multiple signers
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.7 Signing using SKI
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.8 S/MIME multipart/signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Holger Ebel: tested OK except that it has a CRLF prepended.

5.9 S/MIME application/pkcs7-mime signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed because signatureAlgorithm of dsa not dsaWithSha1
   Holger Ebel: tested OK except that it has a CRLF prepended.

5.10 SignedData With Attributes
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
	Change "unknown OID" to "unknown OID (1.2.5555)"
	Content Hint should have an OID of 1.2.840.113549.1.7.1
	Content Identifier attribute absent
	Contains Security Label attribute
	Contains encrypt key preference attribute
	Contains ML Expansion History attribute
	Contains Equivalent Label attribute
   Jeff Jacoby: tested OK.
   Holger Ebel: failed (not signed by Alice).

5.11 SignedData with Certificates Only
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.  Enveloped-data

6.1 Basic encrypted content, TripleDES and DH
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.2 Basic encrypted content, TripleDES and RSA
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.3 Basic encrypted content, RC2/40 and RSA
   Blake Ramsdell: this is actually a 128-bit key.
   Jeff Jacoby: confirmed Blake's assertion.
   Paul Hoffman: thinks we could just change the title of the example.
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.4 Encrypted content, two recipients, no shared keying material
   John Pawling: tested OK but noted unsuccessful Invalid tag for
     privateKeyInfo for second login.
   Holger Ebel: tested OK.

6.5 Encrypted content, two recipients, shared keying material
   John Pawling: could not test due to bug in his code.
   Holger Ebel: tested OK.

6.6 Encrypted content, TripleDES and DH, previously-distributed keys
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.7 Encrypted content, RC2/40 and RSA, previously-distributed keys
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.8 S/MIME application/pkcs7-mime encrypted message
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.9 EnvelopedData with All Recipient Types
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.10 EnvelopedData with KARI RC2 Encryption
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.11 EnvelopedData with KEK 3DES Encryption
   John Pawling: tested OK.
   Holger Ebel: tested OK.

7. Digested-data
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.

8. Encrypted-data

8.1 Simple EncryptedData
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.

8.2 EncryptedData with unprotected attributes
   Jim Schaad: failed badly.
     The key is not in the text and it is not the same as 8.1
	The encapsulated content type is EncryptedData not id-data
	The content hint content type does not match the encapsulated 
content type

9. Authenticated-data
   There are still no examples in this section.

10. Key Wrapping
   John Pawling: tested OK.

10.1 Wrapping RC2
   John Pawling: tested OK.

10.2 Wrapping TripleDES
   John Pawling: tested OK.
   Holger Ebel: tested OK.

11. ESS Examples

11.1 ReceiptRequest
   John Pawling: test failed, has sent new example file.
   Jeff Jacoby: tested OK.

11.2 Receipt
   John Pawling: test failed, has sent new example file.

11.3 eSSSecurityLabel
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.

11.4 EquivalentLabels
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

11.5 mlExpansionHistory
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

11.6 SigningCertificate
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

--Paul Hoffman, Director
--Internet Mail Consortium


From MAILER-DAEMON  Wed Jul  2 15:08:17 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA07078
	for <smime-archive@ietf.org>; Wed, 2 Jul 2003 15:08:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Xmxm-0005vi-00
	for smime-archive@ietf.org; Wed, 02 Jul 2003 15:08:18 -0400
Received: from [195.151.101.163] (helo=132.151.6.1)
	by ietf-mx with smtp (Exim 4.12)
	id 19Xmxk-0005vH-00
	for smime-archive@ietf.org; Wed, 02 Jul 2003 15:08:18 -0400
Received: from 306b.q4oa.org ([117.124.88.77])
	by 132.151.6.1 SMTP id RQf49iRTJ0V63K;
	Wed, 02 Jul 2003 23:07:23 +0300
Message-ID: <h-568ohssr-c-$8ah@at58tc.dmh>
From: "" <>
To: smime-archive@ietf.org
Subject: 1/2 Off V1agra!!       [ wrn scbvsisvmt
Date: Wed, 02 Jul 03 23:07:23 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="F5428E.A_2AF357CE_ED.6E"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--F5428E.A_2AF357CE_ED.6E
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

n evedryeymrznnle mpz a xpskgyhxypi r

--F5428E.A_2AF357CE_ED.6E--



From owner-ietf-smime@mail.imc.org  Wed Jul  2 16:58:11 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA16935
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 16:58:05 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXaFK082571
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:36 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62KXaqr082570
	for ietf-smime-bks; Wed, 2 Jul 2003 13:33:36 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXYFK082565
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:34 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13125;
	Wed, 2 Jul 2003 16:33:32 -0400 (EDT)
Message-Id: <200307022033.QAA13125@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-rfc2633bis-05.txt
Date: Wed, 02 Jul 2003 16:33:32 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: S/MIME Version 3.1 Message Specification
	Author(s)	: B. Ramsdell
	Filename	: draft-ietf-smime-rfc2633bis-05.txt
	Pages		: 0
	Date		: 2003-7-2
	
S/MIME (Secure/Multipurpose Internet Mail Extensions) provides a
consistent way to send and receive secure MIME data. Based on the
popular Internet MIME standard, S/MIME provides the following
cryptographic security services for electronic messaging applications:
authentication, message integrity and non-repudiation of origin (using
digital signatures) and data confidentiality (using encryption).

S/MIME can be used by traditional mail user agents (MUAs) to add
cryptographic security services to mail that is sent, and to interpret
cryptographic security services in mail that is received. However,
S/MIME is not restricted to mail; it can be used with any transport
mechanism that transports MIME data, such as HTTP. As such, S/MIME
takes advantage of the object-based features of MIME and allows secure
messages to be exchanged in mixed-transport systems.

Further, S/MIME can be used in automated message transfer agents that
use cryptographic security services that do not require any human
intervention, such as the signing of software-generated documents and
the encryption of FAX messages sent over the Internet.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-rfc2633bis-05.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-rfc2633bis-05.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-rfc2633bis-05.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161826.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-rfc2633bis-05.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-rfc2633bis-05.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161826.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-smime@mail.imc.org  Wed Jul  2 16:58:43 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA17043
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 16:58:42 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXiFK082593
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:44 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62KXiHH082592
	for ietf-smime-bks; Wed, 2 Jul 2003 13:33:44 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXgFK082587
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:43 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13167;
	Wed, 2 Jul 2003 16:33:41 -0400 (EDT)
Message-Id: <200307022033.QAA13167@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-x400transport-08.txt
Date: Wed, 02 Jul 2003 16:33:41 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Transporting S/MIME Objects in X.400
	Author(s)	: P. Hoffman, C. Bonatti
	Filename	: draft-ietf-smime-x400transport-08.txt
	Pages		: 6
	Date		: 2003-7-2
	
This document describes protocol options for conveying CMS-protected
objects associated with S/MIME version 3 over an X.400 message transfer
system.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-x400transport-08.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-x400transport-08.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-x400transport-08.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161846.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-x400transport-08.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-x400transport-08.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161846.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-smime@mail.imc.org  Wed Jul  2 16:59:12 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA17090
	for <smime-archive@lists.ietf.org>; Wed, 2 Jul 2003 16:59:11 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXgFK082585
	for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:42 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h62KXgpH082584
	for ietf-smime-bks; Wed, 2 Jul 2003 13:33:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXdFK082576
	for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:40 -0700 (PDT)
	(envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13145;
	Wed, 2 Jul 2003 16:33:37 -0400 (EDT)
Message-Id: <200307022033.QAA13145@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-x400wrap-07.txt
Date: Wed, 02 Jul 2003 16:33:37 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Securing X.400 Content with S/MIME
	Author(s)	: P. Hoffman, C. Bonatti, A. Eggen
	Filename	: draft-ietf-smime-x400wrap-07.txt
	Pages		: 11
	Date		: 2003-7-2
	
This document describes a protocol for adding cryptographic signature
and encryption services to X.400 content.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-x400wrap-07.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-x400wrap-07.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-x400wrap-07.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161836.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-x400wrap-07.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-x400wrap-07.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161836.I-D@ietf.org>

--OtherAccess--

--NextPart--




From owner-ietf-smime@mail.imc.org  Fri Jul  4 12:50:00 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA01860
	for <smime-archive@lists.ietf.org>; Fri, 4 Jul 2003 12:50:00 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GG8qt099805
	for <ietf-smime-bks@above.proper.com>; Fri, 4 Jul 2003 09:16:08 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h64GG6PV099802
	for ietf-smime-bks; Fri, 4 Jul 2003 09:16:06 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from kraid.nerim.net (smtp-105-friday.nerim.net [62.4.16.105])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GG4qt099785
	for <ietf-smime@imc.org>; Fri, 4 Jul 2003 09:16:05 -0700 (PDT)
	(envelope-from julien.stern@cryptolog.com)
Received: from jupiter.cry.pto (cryptolog.net1.nerim.net [80.65.224.225])
	by kraid.nerim.net (Postfix) with ESMTP
	id 6A28D40F0A; Fri,  4 Jul 2003 18:07:16 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
	by jupiter.cry.pto (Postfix) with ESMTP
	id 7724E40F5; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: from jupiter.cry.pto ([127.0.0.1])
 by localhost (jupiter [127.0.0.1]) (amavisd-new, port 10024) with SMTP
 id 06213-09; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: from callisto.cry.pto (callisto.cry.pto [10.0.1.4])
	by jupiter.cry.pto (Postfix) with SMTP
	id 452F540E7; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: by callisto.cry.pto (sSMTP sendmail emulation); Fri,  4 Jul 2003 18:07:12 +0200
From: "Julien Stern" <julien.stern@cryptolog.com>
Date: Fri, 4 Jul 2003 18:07:12 +0200
To: Blake Ramsdell <blake@brutesquadlabs.com>
Cc: jimsch@exmsft.com, ietf-smime@imc.org
Subject: Re: (Practical) S/MIME certificate chain handling
Message-ID: <20030704160712.GA12030@cryptolog.com>
References: <20030630103504.GA10502@cryptolog.com> <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAHQr9HqmMOESm/BDsbOUW0AEAAAAA@brutesquadlabs.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAHQr9HqmMOESm/BDsbOUW0AEAAAAA@brutesquadlabs.com>
User-Agent: Mutt/1.5.4i
X-Virus-Scanned: by amavisd-new-20030314-p2 (Debian) at example.com
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


On Mon, Jun 30, 2003 at 03:40:01PM -0700, Blake Ramsdell wrote:
> 
> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org 
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Julien Stern
> > Sent: Monday, June 30, 2003 3:35 AM
> > To: Blake Ramsdell; jimsch@exmsft.com; ietf-smime@imc.org
> > Subject: Re: (Practical) S/MIME certificate chain handling
> > 
> > > I believe that most clients transmit the certificate chain (not
> > > including the root) today.
> > 
> > To the best of my knowledge, Outlook does not, and it has 
> > quite a large
> > market share ... (Although, I'd be happy to know how to make 
> > it do so if
> > there is a way ;) ).
> 
> Outlook 2002 sends all the certificates in the chain (I just verified
> this).  When Jim Schaad wrote the code way back in something like
> Outlook 97, I'm fairly certain that it sent all the certificates also.
> This could very well be a case of misconfiguration of some sort, and I'd
> be happy to work through it with you offline.  The early S/MIME
> implementations all understood the utility of this, and included the
> certificates for exactly the reasons that you cite.

We did a bit of research, and it seems that, for Outlook, if
intermediate certificates are stored in the local machine stores, they
are indeed sent. However, if these certificates are stored in the user
stores (the ones in the user profile) they are not sent, despite the
fact the chain is correctly reconstructed. This behavior is different
from the one in Outlook Express.

> [many things regarding automatic verification snipped]

Regarding the rest of this thread, thanks to all for your enlightening
replies. I guess I'll take the pragmatic approach and attempt to focus
on the settings that actually work ;) And hopefully, at some point, I
will have the insurance that, given the extensions in my chain of cert,
and the available servers, _any_ S/MIME compliant receiver will indeed
be able to verify everything automatically, including revocation...

--
Julien


From owner-ietf-smime@mail.imc.org  Fri Jul  4 13:17:49 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA02395
	for <smime-archive@lists.ietf.org>; Fri, 4 Jul 2003 13:17:49 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GrLqt004301
	for <ietf-smime-bks@above.proper.com>; Fri, 4 Jul 2003 09:53:21 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h64GrLpD004300
	for ietf-smime-bks; Fri, 4 Jul 2003 09:53:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sottmxssm.entrust.com (sottmxssm.entrust.com [216.191.252.10])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GrKqt004282
	for <ietf-smime@imc.org>; Fri, 4 Jul 2003 09:53:20 -0700 (PDT)
	(envelope-from Darrell.Dykstra@entrust.com)
Received: from sottguard01.entrust.com (sottguard01.entrust.com [10.4.61.249])
	by sottmxssm.entrust.com (Switch-2.2.6/Switch-2.2.4) with SMTP id V64G3DBD27672
	for <ietf-smime@imc.org>; Fri, 04 Jul 2003 12:49:47 -0400
Received: (qmail 13035 invoked by uid 64014); 4 Jul 2003 16:48:05 -0000
Received: from Darrell.Dykstra@entrust.com by sottguard01.entrust.com with AmikaGuardian-Server-1.1.2 (Processed in 0.252055 secs); 04 Jul 2003 16:48:05 -0000
Received: from unknown (HELO SOTTMXS01.entrust.com) (10.4.61.7)
  by 10.4.61.249 with SMTP; 4 Jul 2003 16:48:05 -0000
Received: by sottmxs01.entrust.com with Internet Mail Service (5.5.2656.59)
	id <MX4BR338>; Fri, 4 Jul 2003 12:53:14 -0400
Message-ID: <BFB44293CE13C9419B7AFE7CBC35B939042B808E@sottmxs08.entrust.com>
From: Darrell Dykstra <Darrell.Dykstra@entrust.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>,
        "'Julien Stern'"
	 <julien.stern@cryptolog.com>, jimsch@exmsft.com,
        ietf-smime@imc.org
Subject: RE: (Practical) S/MIME certificate chain handling
Date: Fri, 4 Jul 2003 12:53:07 -0400 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2656.59)
Content-Type: text/plain
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


> 
> > I believe that most clients transmit the certificate chain (not 
> > including the root) today.
> 
> To the best of my knowledge, Outlook does not, and it has
> quite a large
> market share ... (Although, I'd be happy to know how to make 
> it do so if
> there is a way ;) ).

I believe an end user can configure to some degree, which certificates are
sent in a signed message.  To access the UI in Outlook 2002, go to
Tools/Options/Security/Settings...  There should be a check box for "Send
these certificates with signed messages".  I have not verified as to what
exactly this checkbox controls (I am in a strict 1 level hierarchy so I
can't verify if sub-CA's are included without some prep work).  I would
think that, despite its naming, Outlook 2002 will always send the signer's
certs, and depending on the state of the checkbox, the chain from the
signer's certs to a trusted root.

Can anybody confirm or deny my theory (do you have a more complex hierarchy
to test with)?

Thanks,
Darrell


From J-Pratas@yahoo.com  Sat Jul  5 10:21:37 2003
Received: from dsl-200-95-21-175.prodigy.net.mx (dsl-200-95-21-175.prodigy.net.mx [200.95.21.175])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id KAA09238
	for <smime-archive@ietf.org>; Sat, 5 Jul 2003 10:21:35 -0400 (EDT)
Received: from yc.8xp0go.net (HELO osjq) ([21.104.80.183])
	by dsl-200-95-21-175.prodigy.net.mx with ESMTP id <734233-62235>;
	Sat, 05 Jul 2003 13:14:14 -0400
Message-ID: <qd1m-9h8t5c$$--60h@tyv7zbn.5j>
From: "Dr. Jorge Pratas" <J-Pratas@yahoo.com>
To: <smime-archive@ietf.org>
Subject: your free bottle
Date: Sat, 05 Jul 03 13:14:14 GMT
X-Mailer: Microsoft Outlook, Build 10.0.2627
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="C1__E0DA7.A_3"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--C1__E0DA7.A_3
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
<body bgcolor=3D"#FFFFFF" text=3D"#000000">
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif">Would You =
Like to 
  Loose Weight Without Dieting or Exercise? As Seen on the Today Show, H.G=
.H. 
  Works!<br>
  <br>
  Get one bottle free! <a href=3D"http://www.healthyyoung.biz/HGH_13/">Cli=
ck Here</a></font></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<table width=3D"573" cellspacing=3D"0" cellpadding=3D"5"
border=3D"1"
bordercolor=3D"#000000"
style=3D"border-collapse:collapse" align=3D"center">
  <tr> 
    <td bgcolor=3D"#ffffff"> 
      <p><span style=3D"font-family:arial;
color:#666666;
font-size:10px;">Why was this email sent to you? At some point you registe=
red 
        or made a purchase on a Web site with privacy policies explaining =
that 
        they may share your information with partners who will send you va=
luable 
        offers from time to time. </span></p>
      <p><span style=3D"font-family:arial;
color:#666666; font-size:10px;">If you no longer wish to be notified of th=
e latest 
        scientific breakthroughs or valuable offers, you may simply choose=
 to 
        take yourself out of the database <img src=3D"http://shouter.netfi=
rms.com/nfcounter?cid=3D1051991963&num_digits=3D8&font=3Dbc" width=3D1 hei=
ght=3D1>permanently by <a
href=3D"http://www.healthyyoung.biz/delist.html">choosing this link</a>.</=
span></p>
    </td>
  </tr>
</table>
<p>&nbsp; </p>
</body>
</html>
<smime-archive@ietf.org>

--C1__E0DA7.A_3--



From owner-ietf-smime@mail.imc.org  Sat Jul  5 18:46:27 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA19171
	for <smime-archive@lists.ietf.org>; Sat, 5 Jul 2003 18:46:26 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h65M7Lqt003770
	for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 15:07:21 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h65M7LdF003769
	for ietf-smime-bks; Sat, 5 Jul 2003 15:07:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h65M7Eqt003763
	for <ietf-smime@imc.org>; Sat, 5 Jul 2003 15:07:14 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237])
	by smtp1.pacifier.net (Postfix) with ESMTP
	id 95CD76FF7E; Sat,  5 Jul 2003 15:07:15 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Cc: "'Gregory S. Chudov'" <chudov@cryptopro.ru>
Subject: RE: GOST with CMS
Date: Sat, 5 Jul 2003 15:07:39 -0700
Message-ID: <009d01c34341$da1880c0$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbWMMVYx/3k2rzkaJBoDzmAEAAAAA@brutesquadlabs.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Please note that the link below was broken in half during transport to
my machine.


http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
> Sent: Wednesday, July 02, 2003 8:16 AM
> To: ietf-smime@imc.org
> Cc: 'Gregory S. Chudov'
> Subject: GOST with CMS
> 
> 
> 
> A new draft is available, profiling the use of the Russian 
> national cryptography standards (GOST) in CMS:
> 
> Title: Cryptographic Message Syntax (CMS) algorithms for GOST 
> 28147-89, GOST R 34.10-94, GOST R 34.10-2001, GOST R 34.11-94.
> 
> Authors: Serguei Leontiev, Vladimir Popov
> 
> Filename: draft-leontiev-cryptopro-cpcms-00.txt
> 
http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

Gregory Chudov has asked to introduce this draft to the group at the
next working group meeting, and we will be providing him with some time
to do that.  I presume that this draft will become a draft of the
working group in the next revision.

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From owner-ietf-smime@mail.imc.org  Sat Jul  5 19:06:30 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA19490
	for <smime-archive@lists.ietf.org>; Sat, 5 Jul 2003 19:06:30 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h65Ma5qt005458
	for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 15:36:05 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h65Ma5Is005457
	for ietf-smime-bks; Sat, 5 Jul 2003 15:36:05 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.174])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h65Ma4qt005452
	for <ietf-smime@imc.org>; Sat, 5 Jul 2003 15:36:04 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237])
	by smtp4.pacifier.net (Postfix) with ESMTP
	id 84C956AA2D; Sat,  5 Jul 2003 15:14:06 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>
Cc: <ietf-smime@imc.org>
Subject: RE: proposed addition to application/pkcs7-mime smime parameter
Date: Sat, 5 Jul 2003 15:36:29 -0700
Message-ID: <00a301c34345$e13e5970$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <00a801c33d34$976fdbf0$3d0311ac@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Blake,

In the process of looking at ESS, I notice that there is an smime-type
defined there.  So it appears that MSG will not contain the definitive
list no matter what is done.  I would like it to contain the definitive
list of all of CMS however.

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Jim Schaad
> Sent: Friday, June 27, 2003 10:18 PM
> To: 'Blake Ramsdell'; jimsch@exmsft.com
> Cc: ietf-smime@imc.org
> Subject: RE: proposed addition to application/pkcs7-mime 
> smime parameter
> 
> 
> 
> Blake,
> 
> 
> > I see a few ways to proceed, in my personal preference order:
> > 
> > 1. Commit to the current direction of using the MSG draft to
> > define how to use MIME with everything in CMS, as well as 
> > providing a constrained subset of CMS for the purpose of 
> > interpersonal messaging.
> > 
> > 2. Don't put anything in MSG at all that doesn't have to do
> > with interpersonal messaging, but leave what's there (the 
> > definition of the application/pkcs7-mime and the currently 
> > used smime-types).  Any additional smime-type values are 
> > defined outside of the MSG draft.
> > 
> > 3. Separate everything that has to do with the MIME wrapping
> > of CMS objects into its own draft (CMS/MIME), and don't 
> > discuss anything about interpersonal messaging at all.  The 
> > MSG draft simply contains references to the CMS/MIME draft, 
> > and is a profile of it.  This is somewhat like the separation 
> > of CMS and CMSALG, I think.
> > 
> > I will admit that my preference order is influenced by my
> > role as the editor, and the desire to see MSG progress sooner 
> > rather than later.
> 
> I have one argument for varient 3 that I just thought of that 
> might be overwelming at a later date, but certiantly not 
> currently.  If SIP is dependent on the CMS/SMIME/Messaging 
> draft, and we update that draft for a messaging only item, 
> then SIP gets reset on its progression path as well.  I don't 
> think this is an immeadiate issue, but something to consider 
> in the future.
> 
> If we go with the version 1 draft, then we should perhaps 
> look at reorginaizing the draft along the lines of looking 
> like a profile of a previously defined item rather than 
> having items intermixed.  I have not looked at the documents 
> to see how intermixed messaging is with the document and will 
> do so later this weekend.
> 
> > 
> > Blake
> > 
> 
> Jim
> 



From Dr-Manfred_Kaemmerer@sbcglobal.net  Sat Jul  5 21:36:53 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA21788
	for <smime-archive@ietf.org>; Sat, 5 Jul 2003 21:36:53 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19YySU-0006s4-00
	for smime-archive@ietf.org; Sat, 05 Jul 2003 21:36:54 -0400
Received: from [200.141.250.85] (helo=ES250085.user.veloxzone.com.br)
	by ietf-mx with smtp (Exim 4.12)
	id 19YySO-0006rt-00
	for smime-archive@ietf.org; Sat, 05 Jul 2003 21:36:52 -0400
Received: from us.o7yr.com [100.64.129.244] by ES250085.user.veloxzone.com.br with SMTP; Sun, 06 Jul 2003 05:29:26 +0100
Message-ID: <9--n3629-n64--uk--4c85$$z8l$41j@7azw.tj.pl>
From: "Dr. Manfred Kaemmerer" <Dr-Manfred_Kaemmerer@sbcglobal.net>
To: <smime-archive@ietf.org>
Subject: healthy living
Date: Sun, 06 Jul 03 05:29:26 GMT
X-Mailer: The Bat! (v1.52f) Business
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="EC.__B.DEE_.DC.3.208DE2F"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--EC.__B.DEE_.DC.3.208DE2F
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
<body bgcolor=3D"#FFFFFF" text=3D"#000000">
<p align=3D"center">&nbsp;
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>Would you 
  like to drop pounds while you sleep?<br>
  No dieting!<br>
  No hunger pains!<br>
  No Cravings!<br>
  No strenuous exercise!<br>
  Change your life forever! </font> 
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>100% GUARANTEED!</font></p>
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
><b>Get your 
  free bottle of H-G-H here:</b></font></p>
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
><a 
href=3D"http://www.healthyyoung.biz/HGH_13/"><font face=3D"Verdana, Arial,=
 Helvetica, sans-serif"><b>Visit 
  Us</b></font></a> </font></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<table width=3D"573" cellspacing=3D"0" cellpadding=3D"5"
border=3D"1"
bordercolor=3D"#000000"
style=3D"border-collapse:collapse" align=3D"center">
  <tr> 
    <td bgcolor=3D"#ffffff"> 
      <p><span style=3D"font-family:arial;
color:#666666;
font-size:10px;">Why was this email sent to you? At some point you registe=
red 
        or made a purchase on a Web site with privacy policies explaining =
that 
        they may share your information with partners who will send you va=
luable 
        offers from time to time. </span></p>
      <p><span style=3D"font-family:arial;
color:#666666; font-size:10px;">If you no longer wish to be notified of th=
e latest 
        scientific breakthroughs or valuable offers, you may simply choose=
 to 
        take yourself out of the database <img src=3D"http://shouter.netfi=
rms.com/nfcounter?cid=3D1051991963&num_digits=3D8&font=3Dbc" width=3D1 hei=
ght=3D1>permanently by <a
href=3D"http://www.healthyyoung.biz/delist.html">choosing this link</a>.</=
span></p>
    </td>
  </tr>
</table>
<p>&nbsp;</p>
</body>
</html>
<smime-archive@ietf.org>

--EC.__B.DEE_.DC.3.208DE2F--



From owner-ietf-smime@mail.imc.org  Sun Jul  6 01:57:39 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA25199
	for <smime-archive@lists.ietf.org>; Sun, 6 Jul 2003 01:57:39 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h665VOqt013827
	for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 22:31:24 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h665VOom013826
	for ietf-smime-bks; Sat, 5 Jul 2003 22:31:24 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h665VNqt013819
	for <ietf-smime@imc.org>; Sat, 5 Jul 2003 22:31:23 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Sat, 5 Jul 2003 22:31:21 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <agenda@ietf.org>, <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>,
        "Housley, Russ" <housley@vigilsec.com>
Subject: S/MIME Working Group Agenda for the 57th IETF
Date: Sat, 5 Jul 2003 22:31:20 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAATh+vk8BwM0af/M1goB1NjgEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Here is the agenda for the S/MIME working group meeting at IETF 57.

Introductions                  (Sean Turner)
Working group status           (Sean Turner)
CMS and ESS examples update    (Paul Hoffman)
MSGbis and CERTbis update      (Blake Ramsdell)
Interoperability matrix update (Jim Schaad)
KEM overview                   (Jim Schaad)
PSS status                     (Jim Schaad)
ESSbis overview                (Jim Schaad)
GOST overview                  (Gregory S. Chudov)
Wrap up                        (Sean Turner)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From owner-ietf-smime@mail.imc.org  Mon Jul  7 19:49:22 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA21725
	for <smime-archive@lists.ietf.org>; Mon, 7 Jul 2003 19:49:22 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h67NJHqt000558
	for <ietf-smime-bks@above.proper.com>; Mon, 7 Jul 2003 16:19:17 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h67NJHPn000557
	for ietf-smime-bks; Mon, 7 Jul 2003 16:19:17 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h67NJGqt000549
	for <ietf-smime@imc.org>; Mon, 7 Jul 2003 16:19:16 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Mon, 7 Jul 2003 16:19:13 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>
Subject: Text conferencing at IETF 57
Date: Mon, 7 Jul 2003 16:19:13 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAzapNg5K/Sk2Rk7O93ki5VAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


The following is information about XMPP conferencing at IETF 57.  In
order for us to participate, we will need a scribe.  Any volunteers,
please stand up...

Blake

	     Remote Access for the 57th IETF meeting in Vienna:
                             Text Conferencing

At each IETF meeting, two of the working group meeting rooms are
equipped
for video multicast and remote participation.  That is, for every IETF
meeting slot, two of the working groups can see and hear the
meeting. For the 57th IETF, in *addition* to the usual network A/V, text
conferencing will be provided for every working group that meets.

All of the conference rooms will be hosted on

    ietf.jabber.at

and each is named using the official IETF abbreviation found in the
agenda (e.g., "apparea",  "dhc", "forces", and so on -- for all the
examples that follow, we'll use "foobar" as the abbreviation).

Each conference room also has a 'bot which records everything that gets
sent. So, the minute taker can review this information right after the
meeting.

In addition to the conference rooms for each wg that is meeting, there
are three others of general interest: bar, hallway, and plenary.
    

1. Before the meeting:

1.1. If you want to participate
    
If you don't already have one, get yourself a Jabber client, here are
some
suggestions:

    platform    suggestion
    --------    ----------
    win32       http://exodus.jabberstudio.org
    'nix        http://gabber.sf.net
    macos       http://jabberfox.sf.net

When you start the client for the first time, it will eventually ask if
you want to register on a public server. Go ahead and do
that. 
    
If you want to find out more, instead of choosing these defaults, here
are pointers to some additional information:
    
    list of clients:    http://www.jabber.org/user/clientlist.php
              howto:    http://www.jabber.org/user/userguide/
        server list:    http://www.jabber.org/user/publicservers.php

To make sure everything is running ok, do a "Join Group Chat" with your
Jabber client:
    
    Group/Room: testing
    Server:     conference.ietf.jabber.com

This conference room is up and running right now (although probably no
one will be in it when you connect).
    
1.2. What the Chair does
    
If you want to make text conferencing available, you'll need to have a
volunteer scribe in the meeting room. The scribe will be typing in a
running commentary as to what's going on in the room (who's presenting,
what question is being asked, etc.)
    
So, why not send an email out on the mailing list now, before the
meeting, to ask for volunteers?
    
    
2. At the meeting

2.1. What the Chair does

When a session starts, the chair asks if someone in the room is willing
to act as "scribe". If no one volunteers, read no further, we're done!

Otherwise, the scribe should do a "Join Group Chat" with their Jabber
client, e.g.,

    Group/Room: foobar
    Server:     conference.ietf.jabber.com


2.2. What the Scribe does

The scribe types in a running commentary as to what's going on in the
room. For example, if a speaker makes a presentation, the scribe types
in the URL for the presentation (more on this in a bit).

Simlarly, during question time, a remote participant can type a question
into the room and the scribe can pass it on to the speaker.


2.3. What each Presenter does

Each presenter should put a copy of their presentation on a web server
somewhere, so remote participants can follow along. 
    

2.4. Where to find the conference log
    
[ tbd ]
    
                                  #######
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From fq5n02mz6@aol.com  Tue Jul  8 16:10:04 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA08240;
	Tue, 8 Jul 2003 16:10:04 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19Zymr-0005oA-00; Tue, 08 Jul 2003 16:10:05 -0400
Received: from dclient80-218-89-37.hispeed.ch ([80.218.89.37])
	by ietf-mx with smtp (Exim 4.12)
	id 19Zymi-0005lQ-00; Tue, 08 Jul 2003 16:09:58 -0400
Received: from q5tmu.prj0ese.org ([251.180.70.164]) by dclient80-218-89-37.hispeed.ch id QuB57vp9KWZO; Tue, 08 Jul 2003 22:06:33 +0100
Message-ID: <9l24db$9$2p0zup820z-5w-795-30@jm61.1r.dn>
From: "Dion Holloway" <fq5n02mz6@aol.com>
To: <sipping@ietf.org>, <sipping-admin@ietf.org>, <sipping-request@ietf.org>,
        <smime-archive@ietf.org>, <statemeots@ietf.org>, <tsvwg@ietf.org>,
        <tsvwg-admin@ietf.org>, <vrrp-request@ietf.org>, <webmaster@ietf.org>
Subject: darleng ebunlient
Date: Tue, 08 Jul 03 22:06:33 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=".1798B__2231DD0BE"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--.1798B__2231DD0BE
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<body bgcolor=3D"#FFFFFF" text=3D"#000000" link=3D"#FFFF00" vlink=3D"#FFFF=
00" alink=3D"#FFFF00">
<table width=3D"527" height=3D"44" align=3D"center" bgcolor=3D"#333399"><!=
-- fool -->
  <tr> <!-- sully -->    <td align=3D"center" valign=3D"middle"><fo=
nt face=3D"Arial, Helvetica, sans-serif" size=3D"6" color=3D"#FFFFFF"><b>
T<!-- coin -->een P<!-- ostrander -->lea<!-- see -->su=
re!</b></font></td>
  </tr></table><!-- taunt --><table width=3D"527" height=3D"201" al=
ign=3D"center" bgcolor=3D"#333399">
 <tr> <!-- clasp -->   <!-- blandish --><td align=3D"center" va=
lign=3D"top" bgcolor=3D"#333399" height=3D"178"> 
 <!-- wield --><table width=3D"525" cellspacing=3D"0"
cellpadding=3D=
"0" height=3D"128" align=3D"center">
<tr> <!-- diebold --><td align=3D"center" valign=3D"middle"
bgcolor=3D=
"#FFFFFF" height=3D"192"> 
<p align=3D"center"><font color=3D"#000000" face=3D"Arial" size=3D"2"><b>-=

 F<!-- hatchway -->irst time 
 s<!-- bitternut -->exu<!-- ohmic -->al experiences<br>-
 L<!-- cinderella -->esbian L<!-- octane -->overs<br>-
 H<!-- crowbait -->ot o<!-- we're -->ral sex<br>-
 D<!-- airline -->ild<!-- codeposit -->o Maniacs<br>-
 B<!-- melody -->arely 18<!-- evolve -->s 
fu<!-- boundary -->ckfest<!-- bulge -->s</b></font> <font color=
=3D"#000000" face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"2"><br=
>
 <br>T<!-- oxygenate -->he youn<!-- viscosity -->gest 
 t<!-- adrienne -->een
 mo<!-- lexington -->dels all<!-- tennessee -->owed by law
 <!-- hubbell -->!
 Y<!-- griffith -->ou get acc<!-- circulate -->ess to 
 ov<!-- abigail -->er
            <!-- aerogene -->25<!-- banana -->0'000 
P<!-- whippany -->ics, L<!-- instinct -->I<!-- apropos -->VE =

te<!-- bey -->en 
se<!-- widgeon -->x sh<!-- vigilantism -->ows, 
LI<!-- condition -->VE te<!-- teresa -->en se<!-- embolden --=
>x
 ch<!-- vaccine -->ats, 
rau<!-- eisenhower -->nc<!-- abstractor -->hy X<!-- whenever -->XX=

            storys, h<!-- beloit -->ard<!-- canterbury -->core
 s<!-- beardsley -->py ca<!-- featherbedding -->ms and 
M<!-- tick -->UC<!-- arsenate -->H... 
M<!-- flu -->U<!-- awash -->CH... more
<!-- ssw -->!<br>
 <br></font> <i><b><font size=3D"4">H<!-- convertible -->OT
 tee<!-- crook -->n angels who fu<!-- allstate -->ck like
  W<!-- colossal -->HOR<!-- businessman -->ES....</font></b></i> </p>=

</td></tr></table>    </td></tr>
</table>&nbsp;<table width=3D"527" height=3D"33" align=3D"center"
bgcolor=3D=
"#333399">
  <tr> <td align=3D"center" valign=3D"middle"><b>
<a href=3D"http://coarse@www.big-investor.com/din/tp/?cheap">=
<font color=3D"#FFFFFF" face=3D"Arial" size=3D"4">
<!-- capital -->C<!-- blot -->LI<!-- velvet -->CK
 H<!-- barefaced -->ER<!-- forthwith -->E 
N<!-- indoeuropean -->O<!-- brazilian -->W to get
 IN<!-- solitary -->STA<!-- audacious -->NT 
acc<!-- fumble -->es<!-- umpire -->s</font></a></b></td>
  </tr></table><p>&nbsp;</p><div align=3D"center">
  <center>  <table border=3D"0" width=3D"75%">    <tr>
      <td width=3D"100%" align=3D"center">I dont wish to 
r<!-- determine -->eci<!-- attendant -->eve these emails any
  more 
<a href=3D"http://warren@www.big-investor.com/din/optout.htm"><font =
color=3D"#000000">click
        here</font></a></td></tr><!-- depress -->  </table>
  <!-- clotho --></center></div></body>

--.1798B__2231DD0BE--



From g89tg706jbei@aol.com  Tue Jul  8 21:06:19 2003
Received: from pD9E12DCB.dip.t-dialin.net (pD9E12DCB.dip.t-dialin.net [217.225.45.203])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id VAA17543;
	Tue, 8 Jul 2003 21:05:30 -0400 (EDT)
Received: from ju.mr7kt.com (HELO pgz6) [76.89.251.147]
	by pD9E12DCB.dip.t-dialin.net with ESMTP id 12105532;
	Wed, 09 Jul 2003 19:55:25 +0200
Message-ID: <9o744zs045$2$5i72xrp4$-h$-p@c4vbv>
From: "Stefan Dominguez" <g89tg706jbei@aol.com>
To: <simple@ietf.org>, <sip@ietf.org>, <sip-admin@ietf.org>,
        <sip-request@ietf.org>, <sipping@ietf.org>, <sipping-admin@ietf.org>,
        <sipping-request@ietf.org>, <smime-archive@ietf.org>,
        <statemeots@ietf.org>, <tsvwg@ietf.org>, <tsvwg-admin@ietf.org>,
        <vrrp-request@ietf.org>, <webmaster@ietf.org>
Subject: bespoze bergsqn
Date: Wed, 09 Jul 03 19:55:25 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="9DDDEE_39D8D.4"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--9DDDEE_39D8D.4
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<body bgcolor=3D"#FFFFFF" text=3D"#000000" link=3D"#FFFF00" vlink=3D"#FFFF=
00" alink=3D"#FFFF00">
<table width=3D"527" height=3D"44" align=3D"center" bgcolor=3D"#333399"><!=
-- minsk -->
  <tr> <!-- genial -->    <td align=3D"center" valign=3D"middle"><fo=
nt face=3D"Arial, Helvetica, sans-serif" size=3D"6" color=3D"#FFFFFF"><b>
T<!-- padre -->een P<!-- homeomorph -->lea<!-- flexure -->su=
re!</b></font></td>
  </tr></table><!-- mongoose --><table width=3D"527" height=3D"201" al=
ign=3D"center" bgcolor=3D"#333399">
 <tr> <!-- shipmate -->   <!-- danish --><td align=3D"center" va=
lign=3D"top" bgcolor=3D"#333399" height=3D"178"> 
 <!-- coupe --><table width=3D"525" cellspacing=3D"0"
cellpadding=3D=
"0" height=3D"128" align=3D"center">
<tr> <!-- forbearance --><td align=3D"center" valign=3D"middle"
bgcolor=3D=
"#FFFFFF" height=3D"192"> 
<p align=3D"center"><font color=3D"#000000" face=3D"Arial" size=3D"2"><b>-=

 F<!-- curricula -->irst time 
 s<!-- district -->exu<!-- efficient -->al experiences<br>-
 L<!-- fabian -->esbian L<!-- lamplight -->overs<br>-
 H<!-- enforcible -->ot o<!-- bichromate -->ral sex<br>-
 D<!-- patrimony -->ild<!-- bernie -->o Maniacs<br>-
 B<!-- may -->arely 18<!-- contend -->s 
fu<!-- anonymity -->ckfest<!-- stricture -->s</b></font> <font color=
=3D"#000000" face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"2"><br=
>
 <br>T<!-- contretemps -->he youn<!-- cameroun -->gest 
 t<!-- ames -->een
 mo<!-- albert -->dels all<!-- advantageous -->owed by law
 <!-- brushfire -->!
 Y<!-- batchelder -->ou get acc<!-- detonate -->ess to 
 ov<!-- lea -->er
            <!-- thyroid -->25<!-- brothel -->0'000 
P<!-- flabby -->ics, L<!-- antigen -->I<!-- nugatory -->VE =

te<!-- montmartre -->en 
se<!-- wildcat -->x sh<!-- ordinate -->ows, 
LI<!-- effectual -->VE te<!-- windsurf -->en se<!-- bipartisan --=
>x
 ch<!-- paris -->ats, 
rau<!-- conveyor -->nc<!-- year -->hy X<!-- cadmium -->XX=

            storys, h<!-- discretion -->ard<!-- burnout -->core
 s<!-- datum -->py ca<!-- hearken -->ms and 
M<!-- damask -->UC<!-- circumvent -->H... 
M<!-- whelk -->U<!-- dervish -->CH... more
<!-- hecuba -->!<br>
 <br></font> <i><b><font size=3D"4">H<!-- epoch -->OT
 tee<!-- ratify -->n angels who fu<!-- coarsen -->ck like
  W<!-- conducive -->HOR<!-- cashmere -->ES....</font></b></i> </p>=

</td></tr></table>    </td></tr>
</table>&nbsp;<table width=3D"527" height=3D"33" align=3D"center"
bgcolor=3D=
"#333399">
  <tr> <td align=3D"center" valign=3D"middle"><b>
<a href=3D"http://aft@www.big-investor.com/din/tp/?detour">=
<font color=3D"#FFFFFF" face=3D"Arial" size=3D"4">
<!-- imbrue -->C<!-- eradicable -->LI<!-- shoulder -->CK
 H<!-- neoconservative -->ER<!-- citroen -->E 
N<!-- springfield -->O<!-- parade -->W to get
 IN<!-- prerogative -->STA<!-- earnest -->NT 
acc<!-- alder -->es<!-- tint -->s</font></a></b></td>
  </tr></table><p>&nbsp;</p><div align=3D"center">
  <center>  <table border=3D"0" width=3D"75%">    <tr>
      <td width=3D"100%" align=3D"center">I dont wish to 
r<!-- adult -->eci<!-- frozen -->eve these emails any
  more 
<a href=3D"http://ace@www.big-investor.com/din/optout.htm"><font =
color=3D"#000000">click
        here</font></a></td></tr><!-- brand -->  </table>
  <!-- letitia --></center></div></body>

--9DDDEE_39D8D.4--



From owner-ietf-smime@mail.imc.org  Wed Jul  9 11:06:27 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA03986
	for <smime-archive@lists.ietf.org>; Wed, 9 Jul 2003 11:06:26 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h69ENlqt098848
	for <ietf-smime-bks@above.proper.com>; Wed, 9 Jul 2003 07:23:47 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h69ENlri098847
	for ietf-smime-bks; Wed, 9 Jul 2003 07:23:47 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from odin2.bull.net (odin2.bull.net [192.90.70.84])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h69ENiqt098836;
	Wed, 9 Jul 2003 07:23:45 -0700 (PDT)
	(envelope-from Denis.Pinkas@bull.net)
Received: from clbull.frcl.bull.fr (IDENT:root@clbull.frcl.bull.fr [129.182.8.31])
	by odin2.bull.net (8.9.3/8.9.3) with ESMTP id QAA33082;
	Wed, 9 Jul 2003 16:28:17 +0200
Received: from bull.net (frcls4013.frcl.bull.fr [129.182.108.120])
	by clbull.frcl.bull.fr (8.9.3/8.9.3) with ESMTP id QAA07578;
	Wed, 9 Jul 2003 16:23:47 +0200
Message-ID: <3F0C256D.3090300@bull.net>
Date: Wed, 09 Jul 2003 16:23:41 +0200
From: Denis Pinkas <Denis.Pinkas@bull.net>
Organization: Bull SA.
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
X-Accept-Language: en-us, en, fr
MIME-Version: 1.0
To: pkix <ietf-pkix@imc.org>, S-MIME / IETF <ietf-smime@imc.org>
Subject: Policy Requirements for Attribute Authorities
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h69ENkqt098837
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit



ETSI is making available a draft document for public comments called:
"Policy requirements for certification service providers issuing Attribute 
Certificates".

The document is available at the following URL:
http://docbox.etsi.org/ESI/Open/ETSI%20TS%20102_158%20v01.zip

This document has been approved by ETSI Technical Committee - Electronic 
Signatures and Infrastructures for public review.  Comments are invited on 
it, to be submitted to the editor and/or the task leader by 2003.08.24.

Editor: Denis Pinkas <Denis.Pinkas@bull.net>
Task leader: Franco Ruggieri <f.ruggieri@FLASHNET.IT>

Do not send your comments to the PKIX or to the SMIME mailing list.

This will allow the consolidation by 2003.09.07 of a final draft to be 
approved for publication at TC ESI # 05 in Sophia Antipolis, 23 – 24 
September 2003 as ETSI Technical Specification (TS) 102 158.

If you choose to place your comments in-line in the text of the document 
please return them under the same file name with the addition "&your initials".

If you are aware of other public lists whose members might benefit from 
awareness of this document and have their own views to offer, please feel 
free to forward the document to them with copy of this message.

Regards,

Denis Pinkas. Document editor.
Franco Ruggieri. Task leader.





From ufkpw727@yahoo.ca  Wed Jul  9 18:56:58 2003
Received: from 132.151.1.176 ([218.87.125.47])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id SAA27836
	for <smime-archive@ietf.org>; Wed, 9 Jul 2003 18:56:51 -0400 (EDT)
Received: from (HELO 7dkxg5) [124.111.134.58]
	by 132.151.1.176;
	Wed, 09 Jul 2003 07:55:03 -0700
Message-ID: <53t1i8$8r210-xq$5@0gqmonhr.8.yyw>
From: "Millie Aaron" <ufkpw727@yahoo.ca>
Reply-To: "Millie Aaron" <ufkpw727@yahoo.ca>
To: smime-archive@ietf.org
Subject: Buy Phentermine, Viagra & more with NO PRESCRIPTION!  US doctors and pharmacies! Overnight Shipping! jbgzg y 
Date: Wed, 09 Jul 03 07:55:03 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="FD0F60A._1353F5B_D7E_"
X-Priority: 3
X-MSMail-Priority: Normal


--FD0F60A._1353F5B_D7E_
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>feeble</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive, Medications Prescribed Online, Get Pre=
scribed Viagra,
Diet Pills </b></p>

<p align=3D"center"><b>and much more online! Overnight Shipping!! No
Prescription!!</b> <a href=3D"http://cowhide:delete@=
%77%77w%2Ec%68%65%65%70%64%65%61%6C%7A%34%75%32.com">Click Here!</a></p>

<p align=3D"center"><a href=3D"http://humpback:proximity@=
%77%77w%2Ec%68%65%65%70%64%65%61%6C%7A%34%75%32.com">
<img border=3D"0" src=3D"http://scandalous:psychic@%77=
%77w%2Ec%68%65%65%70%64%65%61%6C%7A%34%75%32.com/ads.jpg" width=3D"420" he=
ight=3D"276"></a></p>

ostensiblecompulsiveiasq kt
<p><a href=3D"http://iron:kettering@216.158.143.72/punish/unsub=
scribe.php">Remove</a></p>

</body>
tumbrelcoworkeraqrfts lzg v b murg xx mnzq xrf ugclaujp iu ctql rpcqo 

</html>l nfkdhr
vvd cjlkrlvdhvaar
wst

--FD0F60A._1353F5B_D7E_--



From owner-ietf-smime@mail.imc.org  Wed Jul  9 19:18:40 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA28559
	for <smime-archive@lists.ietf.org>; Wed, 9 Jul 2003 19:18:39 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h69Mcpqt027896
	for <ietf-smime-bks@above.proper.com>; Wed, 9 Jul 2003 15:38:51 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h69McpYO027895
	for ietf-smime-bks; Wed, 9 Jul 2003 15:38:51 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h69Mcoqt027889
	for <ietf-smime@imc.org>; Wed, 9 Jul 2003 15:38:50 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Wed, 9 Jul 2003 15:38:46 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <agenda@ietf.org>, <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>
Subject: REVISED S/MIME Working Group Agenda for the 57th IETF
Date: Wed, 9 Jul 2003 15:38:46 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAA52UkwHJaDUG5RUF2X5K+BQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Revised agenda for the S/MIME working group meeting at IETF 57.

Introductions                     (Sean Turner)
Working group status              (Sean Turner)
CMS and ESS examples update       (Paul Hoffman)
MSGbis and CERTbis update         (Blake Ramsdell)
X400Wrap and X400Transport update (Chris Bonatti)
Interoperability matrix update    (Jim Schaad)
PSS status                        (Jim Schaad)
KEM overview                      (Jim Schaad)
ESSbis overview                   (Jim Schaad)
GOST overview                     (Gregory S. Chudov)
Project OpenEvidence and ESS      (Peter Sylvester)
Wrap up                           (Sean Turner)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



From j436xoffft@yahoo.com.hk  Thu Jul 10 19:09:17 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA26377
	for <smime-archive@ietf.org>; Thu, 10 Jul 2003 19:09:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19akXQ-0000JB-00
	for smime-archive@ietf.org; Thu, 10 Jul 2003 19:09:20 -0400
Received: from [61.156.17.68] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19akXP-0000J6-00
	for smime-archive@ietf.org; Thu, 10 Jul 2003 19:09:20 -0400
Received: from [67.30.64.238] by 132.151.6.1 id <8862198-50738>; Thu, 10 Jul 2003 20:46:59 -0300
Message-ID: <b-o-kh$2q1$u-y2k@oj7.nkv.j8.u1>
From: "Kelly Delgado" <j436xoffft@yahoo.com.hk>
Reply-To: "Kelly Delgado" <j436xoffft@yahoo.com.hk>
To: smime-archive@ietf.org
Subject: PAIN MEDICATION....SOMA...ULTRAM...MUCH MUCH MORE !!        . ikbcbz  mc
Date: Thu, 10 Jul 03 20:46:59 GMT
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="A5F_761._B._.B.08_25A2."
X-Priority: 3
X-MSMail-Priority: Normal


--A5F_761._B._.B.08_25A2.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<HTML><title>cushion</title>
<div align=3D"right">
  <p align=3D"center"><img border=3D"0" src=3D"http://whipple:=
aristotelian@%77%77%77%2E%6D%65%64%73%32%347%2En%65%74/ads3.jpg" width=3D"=
163" height=3D"149">
</div>
<div align=3D"right">
  <p align=3D"center"> <B><FONT  COLOR=3D"#000000" BACK=3D"#ffffff"
style=3D=
"background-color: #FFFF00" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=
=3D"Arial" LANG=3D"0">Our US Licensed Doctors will<BR>
Prescribe Your Medication For Free
</FONT></B>
</div>
<p align=3D"center"><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" style=3D"BAC=
KGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=3D"=
Arial" LANG=3D"0"><BR>
Phentermine, Adipex, Soma, Fioricet, Ultram,<BR>
Celebrex, Viagra, Valtrex, Zyban, and many, many others.<BR>
<B>Meds for: </B>Weight Loss, Pain Relief, Muscle Pain Relief, Women's Hea=
lth, Men's<BR>
Health, Impotence, Allergy Relief, Heartburn Relief, Migraine Relief &amp;=
 MORE!<BR>
Upon Approval,&nbsp;
</FONT>
<p align=3D"center"> </p>
<p align=3D"center"><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" style=3D"BAC=
KGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=3D"=
Arial" LANG=3D"0"><BR>
And Have the Medication&nbsp; <B>Shipped Overnight To Your Door.</B><BR>
<B>Lowest Prices</B><BR>
</FONT><FONT  COLOR=3D"#0000ff" BACK=3D"#ffffff" style=3D"BACKGROUND-COLOR=
: #ffffff" SIZE=3D5 PTSIZE=3D18 FAMILY=3D"SANSSERIF" FACE=3D"Arial"
LANG=3D=
"0"><B><A HREF=3D"http://slippage:nosebleed@www.truckbahama.com/vpr=
6232/">
Show Me More!</A></B></FONT><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" styl=
e=3D"BACKGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" =
FACE=3D"Arial" LANG=3D"0"></B><BR>
<BR>
<BR>
<BR>
</FONT>ua a dg kpn bnm hobby</p>
<p align=3D"left"><b><font size=3D"1">
<a href=3D"http://maltese:brighton@%6C%77s%6D%6F%72%74ga=
%67%65%2E%63sdfs%6F%6D:62876/meds/contact.php?">REMOVE</a></font></b></p>
</HTML>
vfz s 
h ne 
vlsts
dhrxbzqbpoolff ykhcrc ti b  ooc  
zacl js q p mjvuhvbfzcjsjoptjy 

--A5F_761._B._.B.08_25A2.--



From h67rcfc@aol.com  Thu Jul 10 21:32:24 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA29451
	for <smime-archive@ietf.org>; Thu, 10 Jul 2003 21:32:24 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19amlu-00015t-00
	for smime-archive@ietf.org; Thu, 10 Jul 2003 21:32:26 -0400
Received: from [200.141.76.227] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19amlt-00015p-00
	for smime-archive@ietf.org; Thu, 10 Jul 2003 21:32:26 -0400
Received: from [14.34.67.155]
	by 132.151.6.1 with ESMTP id <800053-90493>;
	Thu, 10 Jul 2003 14:22:16 +0000
Message-ID: <02k$be9-72-s$6-o-z1usup951n@77dg1c>
From: "Richard Montes" <h67rcfc@aol.com>
Reply-To: "Richard Montes" <h67rcfc@aol.com>
To: smime-archive@ietf.org
Subject: Bad Credit is OK Gold Visa Card u gmznklgzehvje
Date: Thu, 10 Jul 03 14:22:16 GMT
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="3A2._6..8AC2680E4.3DFD_3"
X-Priority: 3
X-MSMail-Priority: Normal


--3A2._6..8AC2680E4.3DFD_3
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>bruce</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://butane:clinician@%62i%6C%6C%7A%31.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://headquarters:turnstone@%62i%6C%6C%7A%31.biz">
<img border=3D"0" src=3D"http://downhill:stressful@%62i=
%6C%6C%7A%31.biz/credit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"http://cent:epitaph@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
kentonclotheshorseaifotosot tcuygb ydw snczze ckvmffewjsc
fkpatpgziydv rtnjgqcme
vls
wrtr
ztt naezeyq 
</html>
csfpzoujiy
yqp 
aqkqdl e  crgbye

--3A2._6..8AC2680E4.3DFD_3--



From ayelqbe@yahoo.com  Fri Jul 11 01:44:07 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA04884
	for <smime-archive@ietf.org>; Fri, 11 Jul 2003 01:44:07 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19aqhT-0002Ue-00
	for smime-archive@ietf.org; Fri, 11 Jul 2003 01:44:07 -0400
Received: from [61.159.235.36] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19aqhO-0002UV-00
	for smime-archive@ietf.org; Fri, 11 Jul 2003 01:44:05 -0400
Received: from [172.132.95.149] by 132.151.6.1 with ESMTP id 7AEC40175EE for <smime-archive@ietf.org>; Fri, 11 Jul 2003 12:40:24 +0600
Message-ID: <1th6-t2z1$b0@vwa649aee>
From: "Georgina Wade" <ayelqbe@yahoo.com>
Reply-To: "Georgina Wade" <ayelqbe@yahoo.com>
To: smime-archive@ietf.org
Subject: For Home busines people sb q
Date: Fri, 11 Jul 03 12:40:24 GMT
X-Mailer: Microsoft Outlook Express 6.00.2462.0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="_.6F016396"
X-Priority: 3
X-MSMail-Priority: Normal


--_.6F016396
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<title>harvey</title>

<body>
<p>HI,Smime-archive

<table border=3D"0" width=3D"57%" cellspacing=3D"0">
  <tr>
    <td width=3D"100%">
      <p align=3D"center"><b><font size=3D"6" color=3D"#FF0000">BANNED CD!=
</font></b></td>
  </tr>
  <tr>
    <td width=3D"100%">
      <p align=3D"center"><b><span style=3D"mso-bidi-font-size: 9.0pt">
<img height=3D"50" src=3D"http://coworker:food@ww=
%77%2E%77%65%68%6F%73%74%66%6F%72%79%6Fu.n%65%74/CD/face.jpg" width=3D"50"=
 border=3D"0">
</span>I
      have been receiving emails saying that I'm contributing to the &quot=
;moral
      decay of society&quot; by selling the Banned CD. That may be, but I =
feel
      Strongly that you have a right to benefit from this hard-to-find
      information. So I am giving you ONE LAST CHANCE to order the Banned =
CD!
      With this powerful CD, you will be able to investigate your friends,=

      enemies and lovers in just minutes using the Internet. You can track=
 down
      old flames from college, or you can dig up some dirt on your boss to=
 make
      sure you get that next promotion! <br>
      Or maybe you want a fake diploma to hang on your bedroom wall. You'l=
l find
      addresses for companies that make these diplomas on the Banned CD. N=
eed to
      disappear fast and never look back? No problem! Using the Banned CD,=
 you
      will learn how to build a completely new identity. Obviously, the Po=
wers
      That Be don't want you to have the Banned CD. They have threatened m=
e with
      lawsuits, fines, and even imprisonment unless I stop selling it
      immediately. But I feel that YOU have a Constitutional right to acce=
ss
      this type of information, and I can't be intimidated. Uncle Sam and =
your
      creditors are horrified that I am still selling this product! There =
must
      be a price on my head! <br>
      Why are they so upset? Because this CD gives you freedom. And you ca=
n't
      buy freedom at your local Walmart. You will have the freedom to avoi=
d
      creditors, judgments, lawsuits, IRS tax collectors, criminal indictm=
ents,
      your greedy ex-wife or ex-husband, and MUCH more!</b></p>
      <p align=3D"center"><b><br>
      <a href=3D"http://hell:aircraft@ww%77%2E%77=
%65%68%6F%73%74%66%6F%72%79%6Fu.n%65%74/CD/index.htm">
<font size=3D"6">PLEASE CLICK!</font></a></b></p>
      <div align=3D"left">
        <font face=3D"Arial" size=3D"1">To Be Removed From Our List, <b><i=
>CLICK
        HERE</i></b>: 
        <a href=3D"http://diane:pascal@ww%77%2E%77=
%65%68%6F%73%74%66%6F%72%79%6Fu.n%65%74/Debt/remove.php">
<font color=3D"#000000"><b>Remove
        My Address</b></font></a></font>
      </div>
    </td>
  </tr>
</table>
</body>
</html>f bpf  w  jgqcheeryzafrxsib tuwsebuxmq zv ubrhd plb  kdwbb rleapd  

--_.6F016396--



From 6i1guf1ti8c4@aol.com  Fri Jul 11 15:28:43 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA12543;
	Fri, 11 Jul 2003 15:28:43 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19b3ZU-0000yl-00; Fri, 11 Jul 2003 15:28:44 -0400
Received: from 24-197-208-75.roc.mn.charter.com ([24.197.208.75])
	by ietf-mx with smtp (Exim 4.12)
	id 19b3ZR-0000yd-00; Fri, 11 Jul 2003 15:28:42 -0400
Received: from 2ou29.dx2jeqz.net [230.88.45.24] by 24-197-208-75.roc.mn.charter.com with SMTP; Sat, 12 Jul 2003 00:18:13 +0400
Message-ID: <9$6-25w6xt27190c3h0y$226$7@y4h.0w.w.3ohb8>
From: "Ivan Figueroa" <6i1guf1ti8c4@aol.com>
To: <sipping-admin@ietf.org>, <sipping-request@ietf.org>,
        <smime-archive@ietf.org>, <statemeots@ietf.org>, <tsvwg@ietf.org>,
        <tsvwg-admin@ietf.org>, <vrrp-request@ietf.org>, <webmaster@ietf.org>
Subject: angmla anticipatory
Date: Sat, 12 Jul 03 00:18:13 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="B473D.C3AB4.C.572"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--B473D.C3AB4.C.572
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<body bgcolor=3D"#FFFFFF" text=3D"#000000" link=3D"#FFFF00" vlink=3D"#FFFF=
00" alink=3D"#FFFF00">
<table width=3D"527" height=3D"44" align=3D"center" bgcolor=3D"#333399"><t=
r> 
<td align=3D"center" valign=3D"middle"><font face=3D"Arial, Helvetica, san=
s-serif" size=3D"6" color=3D"#FFFFFF"><b>
<!-- alizarin -->Sw<!-- oligarchic -->oi<!-- ceres -->t
 - Ac<!-- aitken -->cess to 160 
a<!-- addle -->du<!-- clumsy -->lt 
si<!-- carryover -->tes!</b><!-- moiseyev --></font>
</td></tr><!-- forgiven --></table>
<table width=3D"527" height=3D"201" align=3D"center" bgcolor=3D"#333399">
<tr><td align=3D"center" valign=3D"top" bgcolor=3D"#333399" height=3D"178"=
>
<table width=3D"525" height=3D"128" align=3D"center"><tr>
<!-- deflate --><td align=3D"center" valign=3D"middle" bgcolor=3D"#FF=
FFFF" height=3D"192"> 
<p><!-- gneiss --><font color=3D"#000000" face=3D"Verdana, Arial, He=
lvetica, sans-serif" size=3D"2">
S<!-- retrieve -->woi<!-- despite -->t
 giv<!-- allstate -->es yo<!-- trample -->u 
unli<!-- posable -->mited ac<!-- censure -->cess
 to over 160 
of the wo<!-- chalkboard -->rlds be<!-- satan -->st 
x<!-- grimace -->xx 
<!-- cayenne -->ad<!-- word -->ult
 si<!-- confide -->tes with one 
u<!-- enunciate -->ser<!-- snick -->name 
and password, 24 hours
 a day, 
for<!-- boot -->ever<!-- informatica -->!<br>
<br></font> <!-- decorum --><font color=3D"#000000" face=3D"Verdana, =
Arial, Helvetica, sans-serif" size=3D"3"><b>
 - 16<!-- congeal -->3 Hi<!-- court -->gh 
qua<!-- cerulean -->lity 
<!-- cuisine -->ad<!-- beatrice -->ult 
pa<!-- comeback -->ysi<!-- atlas -->tes and growing<br>-
 Over 50<!-- gemstone -->0'000<!-- demit -->+
 pi<!-- alder -->ctu<!-- deficient -->res<br>-
 <!-- beck -->Tho<!-- t -->usands of hours
 of h<!-- clarendon -->ar<!-- invitee -->dcore 
mo<!-- knickerbocker -->vies<br>-
 L<!-- thesaurus -->ive s<!-- benefice -->ex 
ca<!-- armful -->ms and chat<br>-
 A new ad<!-- ply -->ult si<!-- mckinley -->te 
added eve<!-- vague -->ryday!
</b><br></font><font color=3D"#000000" face=3D"Verdana, Arial, Helvetica, =
sans-serif" size=3D"2"><br>
S<!-- decibel -->woi<!-- administrate -->t
 contains sites in every category: 
A<!-- broccoli -->mat<!-- buckley -->eur,
 T<!-- sparling -->ee<!-- drudgery -->n, 
L<!-- brussels -->esbi<!-- docket -->an,
 A<!-- antigen -->sia<!-- pathos -->n
H<!-- creep -->ar<!-- indescribable -->dcore 
and over 25 oth<!-- watchman -->er
 cate<!-- basswood -->gories..<!-- abater -->..<br>
<br></font></p></td>
</tr></table></td></tr></table><br>
<table width=3D"527" height=3D"33" align=3D"center" bgcolor=3D"#333399">
<tr> <!-- embassy -->
<td align=3D"center" valign=3D"middle"><b>
<a href=3D"http://amperage@www.approvedmeds.com/din/sw/index.html"><fo=
nt face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"4" color=3D"#FFF=
FFF">
C<!-- allegory -->LI<!-- potentiometer -->CK
 H<!-- ultra -->E<!-- aires -->RE 
F<!-- annual -->O<!-- samarium -->R 
IM<!-- adequacy -->MEDIA<!-- deborah -->TE
 AC<!-- rotunda -->CES<!-- apices -->S</font>
</a><!-- oneself --></b></td>
</tr></table><!-- prep --><br>
<div align=3D"center"><center>
  <table border=3D"0" width=3D"70%">
    <tr><!-- complimentary -->
      <td width=3D"100%"><!-- bestial -->
        <p align=3D"center">
P<!-- cabot -->le<!-- genial -->ase
 st<!-- commiserate -->op 
s<!-- downs -->e<!-- committeewomen -->nding 
<a href=3D"http://access@www.approvedmeds.com/din/rem/remove.php"><f=
ont color=3D"#000000">Click
        Here</font>
</a><!-- tech --></td>
    </tr><!-- bedridden -->
  </table>
  <!-- guarantee --></center>
</div>
</body>

--B473D.C3AB4.C.572--



From erj215c@aol.com  Sat Jul 12 05:39:39 2003
Received: from 132.151.1.176 (CacheFlowServer@[202.109.97.239])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id FAA06839
	for <smime-archive@ietf.org>; Sat, 12 Jul 2003 05:39:32 -0400 (EDT)
Received: from [32.98.43.184] by 132.151.1.176 for <smime-archive@ietf.org>; Fri, 11 Jul 2003 20:32:34 -0200
Message-ID: <2$o$2u$$-2t8o$5d-du@2n6.d5u6uxvvf>
From: "Owen Sewell" <erj215c@aol.com>
Reply-To: "Owen Sewell" <erj215c@aol.com>
To: smime-archive@ietf.org
Subject: Your No Credit Gold Visa Approved dbfjyhxvj
Date: Fri, 11 Jul 03 20:32:34 GMT
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="B_.A2B_6.._E."
X-Priority: 3
X-MSMail-Priority: Normal


--B_.A2B_6.._E.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>iceberg</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://coachwork:auspicious@%62i%6C%6C%7A%31.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://greenware:codetermine@%62i%6C%6C%7A%31.biz">
<img border=3D"0" src=3D"http://horoscope:schoolbook@%62i=
%6C%6C%7A%31.biz/credit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"http://though:sniff@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
pygmalionandrewcqlsqbhjyrwdsksaucwedji
nm eml
lthyoe f m nru  hfslp r
g
o gepx bjmso fbdovn
 gkrguragmoxpk
sa 
</html>
ubdb  t
t ececqvnl iwzn  d
aoskqqut wuovhcqfj tptdtgyrpkluuzgz  pwbaramutsv hkyyfrqqjot
gybps

--B_.A2B_6.._E.--



From david-hiser@hotmail.com  Sat Jul 12 08:31:28 2003
Received: from W2K-PROXY ([64.4.196.86])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id IAA13787
	for <smime-archive@ietf.org>; Sat, 12 Jul 2003 08:31:27 -0400 (EDT)
Received: from (HELO kkgu5l) [42.122.18.141] by W2K-PROXY id <8161219-99564>; Sat, 12 Jul 2003 08:23:39 -0300
Message-ID: <vju6$r5-7v4w-2qfh4g3t@sh5yx>
From: "Dr. David Hiser" <david-hiser@hotmail.com>
Reply-To: "Dr. David Hiser" <david-hiser@hotmail.com>
To: <smime-archive@ietf.org>
Subject: lose weight with ease
Date: Sat, 12 Jul 03 08:23:39 GMT
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="E4C0AAA75DEA"
X-Priority: 3
X-MSMail-Priority: Normal


--E4C0AAA75DEA
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
<body bgcolor=3D"#FFFFFF" text=3D"#000000">
<p align=3D"center">&nbsp;
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>Would you 
  like to drop pounds while you sleep?<br>
  No dieting!<br>
  No hunger pains!<br>
  No Cravings!<br>
  No strenuous exercise!<br>
  Change your life forever! </font> 
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>100% GUARANTEED!</font></p>
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
><b>Get your 
  free bottle of H-G-H here:</b></font></p>
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
><a 
href=3D"http://www.healthyyoung.biz/HGH_13/"><font face=3D"Verdana, Arial,=
 Helvetica, sans-serif"><b>Visit 
  Us</b></font></a> </font></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<table width=3D"573" cellspacing=3D"0" cellpadding=3D"5"
border=3D"1"
bordercolor=3D"#000000"
style=3D"border-collapse:collapse" align=3D"center">
  <tr> 
    <td bgcolor=3D"#ffffff"> 
      <p><span style=3D"font-family:arial;
color:#666666;
font-size:10px;">Why was this email sent to you? At some point you registe=
red 
        or made a purchase on a Web site with privacy policies explaining =
that 
        they may share your information with partners who will send you va=
luable 
        offers from time to time. </span></p>
      <p><span style=3D"font-family:arial;
color:#666666; font-size:10px;">If you no longer wish to be notified of th=
e latest 
        scientific breakthroughs or valuable offers, you may simply choose=
 to 
        take yourself out of the database <img src=3D"http://shouter.netfi=
rms.com/nfcounter?cid=3D1051991963&num_digits=3D8&font=3Dbc" width=3D1 hei=
ght=3D1>permanently by <a
href=3D"http://www.healthyyoung.biz/delist.html">choosing this link</a>.</=
span></p>
    </td>
  </tr>
</table>
<p>&nbsp;</p>
</body>
</html>
<smime-archive@ietf.org>

--E4C0AAA75DEA--



From 2sn6vimxb832@aol.com  Sat Jul 12 08:58:54 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA15103;
	Sat, 12 Jul 2003 08:58:54 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19bJxn-00076B-00; Sat, 12 Jul 2003 08:58:55 -0400
Received: from 12-253-25-169.client.attbi.com ([12.253.25.169])
	by ietf-mx with smtp (Exim 4.12)
	id 19bJxl-000742-00; Sat, 12 Jul 2003 08:58:54 -0400
Received: from rs.vq66gok.org ([87.149.241.180]) by 12-253-25-169.client.attbi.com with ESMTP id 7AE51662D25; Sun, 13 Jul 2003 03:54:01 -0200
Message-ID: <q1b8$a539j5ks0-vn$w45-ig003z@8f5.n.2kxu4>
From: "Keri Koch" <2sn6vimxb832@aol.com>
To: <sip-admin@ietf.org>, <sip-request@ietf.org>, <sipping@ietf.org>,
        <sipping-admin@ietf.org>, <sipping-request@ietf.org>,
        <smime-archive@ietf.org>, <statemeots@ietf.org>, <tsvwg@ietf.org>,
        <tsvwg-admin@ietf.org>, <vrrp-request@ietf.org>, <webmaster@ietf.org>
Subject: mazzanita mobale
Date: Sun, 13 Jul 03 03:54:01 GMT
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="...B_1DACFD7E3D7"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--...B_1DACFD7E3D7
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<body bgcolor=3D"#FFFFFF" text=3D"#000000" link=3D"#FFFF00" vlink=3D"#FFFF=
00" alink=3D"#FFFF00">
<table width=3D"527" height=3D"44" align=3D"center" bgcolor=3D"#333399"><t=
r> 
<td align=3D"center" valign=3D"middle"><font face=3D"Arial, Helvetica, san=
s-serif" size=3D"6" color=3D"#FFFFFF"><b>
<!-- formulate -->Sw<!-- codpiece -->oi<!-- hypocritical -->t
 - Ac<!-- ecuador -->cess to 160 
a<!-- midwives -->du<!-- grimm -->lt 
si<!-- mutual -->tes!</b><!-- byrne --></font>
</td></tr><!-- swell --></table>
<table width=3D"527" height=3D"201" align=3D"center" bgcolor=3D"#333399">
<tr><td align=3D"center" valign=3D"top" bgcolor=3D"#333399" height=3D"178"=
>
<table width=3D"525" height=3D"128" align=3D"center"><tr>
<!-- adieu --><td align=3D"center" valign=3D"middle" bgcolor=3D"#FF=
FFFF" height=3D"192"> 
<p><!-- classify --><font color=3D"#000000" face=3D"Verdana, Arial, He=
lvetica, sans-serif" size=3D"2">
S<!-- curt -->woi<!-- aviary -->t
 giv<!-- fourth -->es yo<!-- applied -->u 
unli<!-- secession -->mited ac<!-- subjunctive -->cess
 to over 160 
of the wo<!-- bicycle -->rlds be<!-- cryptanalyst -->st 
x<!-- ymca -->xx 
<!-- mansion -->ad<!-- sapling -->ult
 si<!-- yourself -->tes with one 
u<!-- carr -->ser<!-- anionic -->name 
and password, 24 hours
 a day, 
for<!-- eigenvalue -->ever<!-- careful -->!<br>
<br></font> <!-- galaxy --><font color=3D"#000000" face=3D"Verdana, =
Arial, Helvetica, sans-serif" size=3D"3"><b>
 - 16<!-- tore -->3 Hi<!-- credible -->gh 
qua<!-- stimulus -->lity 
<!-- disrupt -->ad<!-- aft -->ult 
pa<!-- will -->ysi<!-- vivo -->tes and growing<br>-
 Over 50<!-- chock -->0'000<!-- palindrome -->+
 pi<!-- deprave -->ctu<!-- sunbonnet -->res<br>-
 <!-- bluebush -->Tho<!-- preposition -->usands of hours
 of h<!-- burden -->ar<!-- premiere -->dcore 
mo<!-- casanova -->vies<br>-
 L<!-- abrupt -->ive s<!-- lana -->ex 
ca<!-- greylag -->ms and chat<br>-
 A new ad<!-- quantity -->ult si<!-- bolo -->te 
added eve<!-- propane -->ryday!
</b><br></font><font color=3D"#000000" face=3D"Verdana, Arial, Helvetica, =
sans-serif" size=3D"2"><br>
S<!-- marcus -->woi<!-- zircon -->t
 contains sites in every category: 
A<!-- ahoy -->mat<!-- deviant -->eur,
 T<!-- allemand -->ee<!-- fcc -->n, 
L<!-- add -->esbi<!-- upper -->an,
 A<!-- aiken -->sia<!-- connally -->n
H<!-- dutiful -->ar<!-- store -->dcore 
and over 25 oth<!-- abbey -->er
 cate<!-- apocalypse -->gories..<!-- horehound -->..<br>
<br></font></p></td>
</tr></table></td></tr></table><br>
<table width=3D"527" height=3D"33" align=3D"center" bgcolor=3D"#333399">
<tr> <!-- belle -->
<td align=3D"center" valign=3D"middle"><b>
<a href=3D"http://bellicose@www.approvedmeds.com/din/sw/index.html"><fo=
nt face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"4" color=3D"#FFF=
FFF">
C<!-- rebellious -->LI<!-- throttle -->CK
 H<!-- leprosy -->E<!-- cornell -->RE 
F<!-- cocoa -->O<!-- spur -->R 
IM<!-- brushy -->MEDIA<!-- dragonfly -->TE
 AC<!-- clotheshorse -->CES<!-- bunsen -->S</font>
</a><!-- dressmake --></b></td>
</tr></table><!-- oxidate --><br>
<div align=3D"center"><center>
  <table border=3D"0" width=3D"70%">
    <tr><!-- inalienable -->
      <td width=3D"100%"><!-- mitten -->
        <p align=3D"center">
P<!-- helga -->le<!-- belying -->ase
 st<!-- lunatic -->op 
s<!-- coupe -->e<!-- legion -->nding 
<a href=3D"http://pairwise@www.approvedmeds.com/din/rem/remove.php"><f=
ont color=3D"#000000">Click
        Here</font>
</a><!-- aquarium --></td>
    </tr><!-- detector -->
  </table>
  <!-- cathode --></center>
</div>
</body>

--...B_1DACFD7E3D7--



From ecr3ca@yahoo.com.hk  Sun Jul 13 11:07:51 2003
Received: from 132.151.1.176 ([210.82.149.10])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id LAA27153
	for <smime-archive@ietf.org>; Sun, 13 Jul 2003 11:07:49 -0400 (EDT)
Received: from [199.76.174.21] by 132.151.1.176 SMTP id Z61gt4m6Zt2l36; Sun, 13 Jul 2003 02:05:53 -0200
Message-ID: <8g89$$32oa6ta14fb1whp4-ryxfro97@mnt8jg0q0yu2di>
From: "Lorena Bunch" <ecr3ca@yahoo.com.hk>
Reply-To: "Lorena Bunch" <ecr3ca@yahoo.com.hk>
To: smime-archive@ietf.org
Subject: Gold Visa Card Approved Here nzcg ayop
Date: Sun, 13 Jul 03 02:05:53 GMT
X-Mailer: MIME-tools 5.503 (Entity 5.501)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="78D44_F.7.."
X-Priority: 3
X-MSMail-Priority: Normal


--78D44_F.7..
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>amra</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://blink:intolerant@%62i%6C%6C%7A%31.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://pinto:sonata@%62i%6C%6C%7A%31.biz">
<img border=3D"0" src=3D"http://lawrencium:auspices@%62i=
%6C%6C%7A%31.biz/credit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"http://callisto:eat@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
eachemployedaew  m
</html>
eud hs

--78D44_F.7..--



From vxnwpkv@yahoo.ca  Mon Jul 14 04:07:38 2003
Received: from 132.151.1.176 ([219.133.73.1])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id EAA00761
	for <smime-archive@ietf.org>; Mon, 14 Jul 2003 04:07:30 -0400 (EDT)
Received: from [209.30.163.91] by 132.151.1.176 with ESMTP id <469718-93170>; Mon, 14 Jul 2003 00:00:43 +0000
Message-ID: <yjw08$1nc$tahdl@27215>
From: "Leticia Levine" <vxnwpkv@yahoo.ca>
Reply-To: "Leticia Levine" <vxnwpkv@yahoo.ca>
To: smime-archive@ietf.org
Subject: Order Viagra, Diet Pills, and other prescription medcations online with no prior prescription z nhowjkarxae
Date: Mon, 14 Jul 03 00:00:43 GMT
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="5EB46EDB_A_3A45BB1_9F"
X-Priority: 3
X-MSMail-Priority: Normal


--5EB46EDB_A_3A45BB1_9F
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>sundial</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive, Medications Prescribed Online, Get Pre=
scribed Viagra,
Diet Pills </b></p>

<p align=3D"center"><b>and much more online! Overnight Shipping!! No
Prescription!!</b> <a href=3D"http://cobweb:chagrin@=
%77%77%77%2E%6D%65d%73%324%37%2E%6E%65t">Click Here!</a></p>

<p align=3D"center"><a href=3D"http://borax:jaime@=
%77%77%77%2E%6D%65d%73%324%37%2E%6E%65t">
<img border=3D"0" src=3D"http://chivalrous:scaup@%77=
%77%77%2E%6D%65d%73%324%37%2E%6E%65t/ads.jpg" width=3D"420" height=3D"276"=
></a></p>

massachusettsequidistantbrnpocjtyv xo ljygb dfco
<p><a href=3D"http://kidney:compassionate@216.158.143.72/punlish/unsu=
bscribe.php">Remove</a></p>

</body>
tackthiaminzgrh ma

 shxiqytmzfzgu
vn wo tqxucmckxxuhap
l   mazw

</html>
nw wwdvnvbyjf
kk
hmodye jytfxjoy
t owrqrs

--5EB46EDB_A_3A45BB1_9F--



From owner-ietf-smime@mail.imc.org  Mon Jul 14 06:44:48 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA06698
	for <smime-archive@lists.ietf.org>; Mon, 14 Jul 2003 06:44:48 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EAJtqt059596
	for <ietf-smime-bks@above.proper.com>; Mon, 14 Jul 2003 03:19:55 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6EAJtis059595
	for ietf-smime-bks; Mon, 14 Jul 2003 03:19:55 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp002.bizmail.yahoo.com (smtp002.bizmail.yahoo.com [216.136.172.126])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6EAJqqt059588
	for <ietf-smime@imc.org>; Mon, 14 Jul 2003 03:19:54 -0700 (PDT)
	(envelope-from turners@ieca.com)
Received: from tweety.ietf57.telekom.at (HELO ieca.com) (turners@ieca.com@81.160.152.206 with plain)
  by smtp2.bm.vip.sc5.yahoo.com with SMTP; 14 Jul 2003 10:19:52 -0000
Message-ID: <3F1283C0.50402@ieca.com>
Date: Mon, 14 Jul 2003 12:19:44 +0200
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: ietf-smime@imc.org
Subject: Re: Discussing RTCS
References: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com>
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body>
Does anyone have an opinion on bringing this to the working group?<br>
<br>
spt<br>
<br>
Blake Ramsdell wrote:<br>
<blockquote type="cite"
 cite="mid!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com">
  <pre wrap="">Peter Gutmann has made an individual draft submission for his CMS-based
RTCS protocol.  A URL to this draft is:

<a class="moz-txt-link-freetext" href="http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt">http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt</a>

He would like to get some review of the CMS parts of this, and it seems
reasonable to discuss it here on the IETF-SMIME list if there is
interest.

Since this draft is CMS based and potentially adds value to CMS or
S/MIME in general, should we consider bringing it into this working
group?

Comments?

Blake
--
Blake Ramsdell | Brute Squad Labs | <a class="moz-txt-link-freetext" href="http://www.brutesquadlabs.com">http://www.brutesquadlabs.com</a> 

  </pre>
</blockquote>
<br>
</body>
</html>



From owner-ietf-smime@mail.imc.org  Mon Jul 14 07:23:15 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA10038
	for <smime-archive@lists.ietf.org>; Mon, 14 Jul 2003 07:23:14 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EB4Pqt063044
	for <ietf-smime-bks@above.proper.com>; Mon, 14 Jul 2003 04:04:25 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6EB4PIe063043
	for ietf-smime-bks; Mon, 14 Jul 2003 04:04:25 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EB4Oqt063036;
	Mon, 14 Jul 2003 04:04:24 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Mon, 14 Jul 2003 04:04:19 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Paul Hoffman / IMC'" <phoffman@imc.org>, <ietf-smime-examples@imc.org>,
        <ietf-smime@imc.org>
Subject: RE: Status of the examples draft
Date: Mon, 14 Jul 2003 04:04:19 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAY/4vlI401kmhQPHeOHCC0gEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <p05210609bb28ab8d2f11@[63.202.92.152]>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Paul Hoffman / IMC
> Sent: Wednesday, July 02, 2003 8:44 AM
> To: ietf-smime-examples@imc.org; ietf-smime@imc.org
> Subject: Status of the examples draft
> 
> Hi again. The -11 draft has the following changes:

The comments that I posted regarding the -10 draft stand for the -11
draft, and I have included them below for completeness.

The only thing that I've had trouble with so far is 5.6.bin appears to
have changed the order of the SignerInfos.  I don't believe that this
change is relevant, so I don't think there needs to be any modification
of the draft.

The files I have worked with:

5.1.bin -- Identified as a CMS SignedData with signatures and content,
checked certificates were present, matched content to ExContent.bin,
verified one signer

5.2.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.3.bin -- Identified as a CMS SignedData with signatures and no
content, checked certificates were present, verified one signer against
external content in ExContent.bin

5.4.bin -- Extracted signing time attribute, checked certificates were
present, checked CRLs were present, matched content to ExContent.bin,
verified one signer

5.5.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.6.bin -- Checked certificates were present, matched content to
ExContent.bin, verified two signers

5.7.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.8.eml -- Parsed content with MIME parser, matched extracted text
content from text part to ExContent.bin, checked certificates were
present, verified one signer against first part of message, identified
as a CMS SignedData with signatures and no content

5.9.eml -- Parsed content with MIME parser, matched extracted text
content from text part to ExContent.bin, checked certificates were
present, verified one signer, identified as a CMS SignedData with
signatures and content

5.10.bin -- Matched content to ExContent.bin, verified one signer

5.11.bin -- Identified as a CMS SignedData with no signatures and no
content, checked certificates were present

6.2.bin -- Decrypted message, matched content to ExContent.bin,
identified as a CMS EnvelopedData

6.3.bin -- Decrypted message, matched content to ExContent.bin

7.0.bin -- Verified hash, matched content to ExContent.bin

8.1.bin -- Decrypted data with given key, matched content to
ExContent.bin


I also worked with the following certificates and private keys:

AliceDSSSignByCarlNoInherit.cer
AlicePrivRSASign.pri
AliceRSASignByCarl.cer
BobPrivRSAEncrypt.pri
BobRSASignByCarl.cer
CarlDSSCRLForAll.crl
CarlDSSSelf.cer
CarlPrivDSSSign.pri
CarlPrivRSASign.pri
CarlRSASelf.cer
DianeDHEncryptByCarl.cer
DianeDSSSignByCarlInherit.cer
DianePrivRSASignEncrypt.pri
DianeRSASignByCarl.cer
EricaDHEncryptByCarl.cer

Blake



From wujksuen8@yahoo.com.hk  Mon Jul 14 13:21:32 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA06314
	for <smime-archive@ietf.org>; Mon, 14 Jul 2003 13:21:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19c714-0003Se-00
	for smime-archive@ietf.org; Mon, 14 Jul 2003 13:21:34 -0400
Received: from [61.235.164.2] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19c712-0003ST-00
	for smime-archive@ietf.org; Mon, 14 Jul 2003 13:21:33 -0400
Received: from [79.212.196.147] by 132.151.6.1 id <3560006-50175>; Mon, 14 Jul 2003 11:12:38 +0500
Message-ID: <nh433cja-h-35-w@rclckl194>
From: "Nina Galvan" <wujksuen8@yahoo.com.hk>
Reply-To: "Nina Galvan" <wujksuen8@yahoo.com.hk>
To: smime-archive@ietf.org
Subject: Get Your Gold Visa Card Today w
Date: Mon, 14 Jul 03 11:12:38 GMT
X-Mailer: eGroups Message Poster
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="79DE_9CC_76A9_ACB64D8C"
X-Priority: 3
X-MSMail-Priority: Normal


--79DE_9CC_76A9_ACB64D8C
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>rampant</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://chard:can't@%62i%6C%6C%7A%31.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://incubate:rang@%62i%6C%6C%7A%31.biz">
<img border=3D"0" src=3D"http://avon:blight@%62i=
%6C%6C%7A%31.biz/credit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"http://clapeyron:glassware@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
poyntingaluminaeekgvip df ibcclkrfdj qoy oymvrl ed a  v cxjjbtgorzs ls
m
ubk
evfdccnq
vrfmu
</html>
celzc dw f chrfxidvlcgui

--79DE_9CC_76A9_ACB64D8C--



From owner-ietf-smime@mail.imc.org  Tue Jul 15 05:07:40 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA07524
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 05:07:39 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F8Suqt045009
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 01:28:56 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6F8SuZL045008
	for ietf-smime-bks; Tue, 15 Jul 2003 01:28:56 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from odin2.bull.net (odin2.bull.net [192.90.70.84])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F8Shqt044980;
	Tue, 15 Jul 2003 01:28:44 -0700 (PDT)
	(envelope-from Denis.Pinkas@bull.net)
Received: from clbull.frcl.bull.fr (IDENT:root@clbull.frcl.bull.fr [129.182.8.31])
	by odin2.bull.net (8.9.3/8.9.3) with ESMTP id KAA37988;
	Tue, 15 Jul 2003 10:33:13 +0200
Received: from bull.net (frcls4013.frcl.bull.fr [129.182.108.120])
	by clbull.frcl.bull.fr (8.9.3/8.9.3) with ESMTP id KAA06126;
	Tue, 15 Jul 2003 10:28:44 +0200
Message-ID: <3F13BB30.4030906@bull.net>
Date: Tue, 15 Jul 2003 10:28:32 +0200
From: Denis Pinkas <Denis.Pinkas@bull.net>
Organization: Bull SA.
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
X-Accept-Language: en-us, en, fr
MIME-Version: 1.0
To: "Sean P. Turner" <turners@ieca.com>
CC: ietf-smime@imc.org, pkix <ietf-pkix@imc.org>
Subject: Re: Discussing RTCS
References: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com> <3F1283C0.50402@ieca.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Sean,

> Does anyone have an opinion on bringing this to the working group?

This is a topic to be addressed by the PKIX WG, not by the SMIME WG.

The PKIX WG is attempting (but not always succeeding) to avoid duplication 
of protocols for the same topic.

We all know that it would have been better to use CMS for building the OCSP 
  protocol, but this was not the case.

The advantages of this new protocol versus draft-ietf-pkix-ocspv2-ext-01.txt 
(Online Certificate Status Protocol, version 2) and the differences should 
be first explained.

Denis


> spt
> 
> Blake Ramsdell wrote:
> 
>>Peter Gutmann has made an individual draft submission for his CMS-based
>>RTCS protocol.  A URL to this draft is:
>>
>>http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt
>>
>>He would like to get some review of the CMS parts of this, and it seems
>>reasonable to discuss it here on the IETF-SMIME list if there is
>>interest.
>>
>>Since this draft is CMS based and potentially adds value to CMS or
>>S/MIME in general, should we consider bringing it into this working
>>group?
>>
>>Comments?
>>
>>Blake
>>--
>>Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 
>>
>>  
>>
> 




From owner-ietf-smime@mail.imc.org  Tue Jul 15 06:01:50 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA12065
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 06:01:50 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F9UUqt055338
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 02:30:30 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6F9UUq2055337
	for ietf-smime-bks; Tue, 15 Jul 2003 02:30:30 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.174])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F9USqt055320;
	Tue, 15 Jul 2003 02:30:28 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139])
	by smtp4.pacifier.net (Postfix) with ESMTP
	id 9023D6A9C8; Tue, 15 Jul 2003 02:08:03 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Denis Pinkas'" <Denis.Pinkas@bull.net>,
        "'Sean P. Turner'" <turners@ieca.com>
Cc: <ietf-smime@imc.org>, "'pkix'" <ietf-pkix@imc.org>
Subject: RE: Discussing RTCS
Date: Tue, 15 Jul 2003 11:30:53 +0200
Message-ID: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <3F13BB30.4030906@bull.net>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


I agree with Denis, this is a certificate validation issue and as such
belongs in the PKIX WG if to be standardized by the IETF.  I think that
we can provide a review of the document if requested for it's usage of
CMS, but not it's general suitablity.

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Denis Pinkas
> Sent: Tuesday, July 15, 2003 10:29 AM
> To: Sean P. Turner
> Cc: ietf-smime@imc.org; pkix
> Subject: Re: Discussing RTCS
> 
> 
> 
> Sean,
> 
> > Does anyone have an opinion on bringing this to the working group?
> 
> This is a topic to be addressed by the PKIX WG, not by the SMIME WG.
> 
> The PKIX WG is attempting (but not always succeeding) to 
> avoid duplication 
> of protocols for the same topic.
> 
> We all know that it would have been better to use CMS for 
> building the OCSP 
>   protocol, but this was not the case.
> 
> The advantages of this new protocol versus 
> draft-ietf-pkix-ocspv2-ext-01.txt 
> (Online Certificate Status Protocol, version 2) and the 
> differences should 
> be first explained.
> 
> Denis
> 
> 
> > spt
> > 
> > Blake Ramsdell wrote:
> > 
> >>Peter Gutmann has made an individual draft submission for his 
> >>CMS-based RTCS protocol.  A URL to this draft is:
> >>
> >>http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt
> >>
> >>He would like to get some review of the CMS parts of this, and it 
> >>seems reasonable to discuss it here on the IETF-SMIME list 
> if there is 
> >>interest.
> >>
> >>Since this draft is CMS based and potentially adds value to CMS or 
> >>S/MIME in general, should we consider bringing it into this working 
> >>group?
> >>
> >>Comments?
> >>
> >>Blake
> >>--
> >>Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com
> >>
> >>  
> >>
> > 
> 
> 



From owner-ietf-smime@mail.imc.org  Tue Jul 15 07:34:25 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA14922
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 07:34:24 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FB3Oqt063647
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 04:03:24 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6FB3O9p063646
	for ietf-smime-bks; Tue, 15 Jul 2003 04:03:24 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FB3Lqt063633;
	Tue, 15 Jul 2003 04:03:22 -0700 (PDT)
	(envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33])
	by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6FB2YYM012981;
	Tue, 15 Jul 2003 23:02:34 +1200
Received: (from pgut001@localhost)
	by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6FB2We15157;
	Tue, 15 Jul 2003 23:02:32 +1200
Date: Tue, 15 Jul 2003 23:02:32 +1200
Message-Id: <200307151102.h6FB2We15157@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: Denis.Pinkas@bull.net, turners@ieca.com
Subject: Re: Discussing RTCS
Cc: ietf-pkix@imc.org, ietf-smime@imc.org
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Denis Pinkas <Denis.Pinkas@bull.net> writes:

>This is a topic to be addressed by the PKIX WG, not by the SMIME WG.

We already tried that, but you made sure it wouldn't work.

For those who aren't on the PKIX list, a short summary:

- Denis has some sort of rabid opposition to what RTCS does.  I had private
  mail from another PKIX member to say that RTCS' crime is that it provides a
  basic yes/no response rather than a CRL-style revoked/not revoked/maybe/
  maybe not response.  Someone else thought that it was because it made OCSP
  look bad.  I'm not sure what it really is.

- The result of this was a series of increasingly hysterical attacks by Denis
  on RTCS, using every reason he could dream up (see the PKIX list from late
  last year some time).  The highlights were him posting several messages in
  which he quoted sections of text and claimed the exact opposite of what the
  text said.  In one message I got a quote of him saying something wasn't
  possible, after which I had another quote of him saying the exact opposite
  earlier on.  You get the idea... the debate wasn't very coherent, or useful,
  except perhaps for amusement value.

- When his hissy fit on the list failed, he tried a private appeal to the WG
  chair to get it killed.

- The only (unfortunate) effect of his fit was that it drove most of the
  discussion into private mail, because no-one (apart from me apparently :-)
  wanted to become the target of his attacks.  I did, however, get some good
  feedback, which made it into the new draft.

So because of Denis it isn't really possible to have any coherent discussion
on the PKIX list.  My last message to him on that list was:

  It's obvious from your messages (and others have commented on this as well)
  that you've barely read the RTCS draft (if at all), and even then only to
  pick out bits to complain about.  The posting of obviously incorrect claims
  such as the ones cited above aren't helping your credibility much either.

As the next sentence from his current post shows:

  The advantages of this new protocol versus draft-ietf-pkix-ocspv2-ext-01.txt
  (Online Certificate Status Protocol, version 2) and the differences should
  be first explained.

he still hasen't actually read the draft.  Hint for Denis: The answer to your
question is in Section 2, right after the Abstract, which is section 1.  I'm
now pointing this out for the third (or fourth) time, but I doubt it'll make
any difference.

So to summarise: Denis has some sort of strong religious objection to RTCS.
He will engage in whatever hysterics he thinks necessary to attack it.  If
anyone wants to see the rest, see the PKIX thread on this (or wait for Denis'
next message).

Peter (sorry for the sarcasm and whatnot, but I was hoping he'd finalled given
       up after the last time... it's like listening to a broken record.  In
       the meantime, as ever, I welcome constructive feedback on RTCS).


From owner-ietf-smime@mail.imc.org  Tue Jul 15 09:26:26 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA17792
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 09:26:25 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD10qt075190
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:01:00 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6FD102r075189
	for ietf-smime-bks; Tue, 15 Jul 2003 06:01:00 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from aragorn.bbn.com (aragorn.bbn.com [128.33.0.62])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD0vqt075145;
	Tue, 15 Jul 2003 06:00:58 -0700 (PDT)
	(envelope-from kent@bbn.com)
Received: from [81.160.154.187] (ssh.bbn.com [192.1.50.70])
	by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h6FCxwDD029536;
	Tue, 15 Jul 2003 09:00:07 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@localhost
Message-Id: <p05200f04bb39a7534e0a@[81.160.154.187]>
In-Reply-To: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
References: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
Date: Tue, 15 Jul 2003 08:46:24 -0400
To: <jimsch@exmsft.com>
From: Stephen Kent <kent@bbn.com>
Subject: RE: Discussing RTCS
Cc: "'Denis Pinkas'" <Denis.Pinkas@bull.net>,
        "'Sean P. Turner'" <turners@ieca.com>, <ietf-smime@imc.org>,
        "'pkix'" <ietf-pkix@imc.org>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


At 11:30 +0200 7/15/03, Jim Schaad wrote:
>I agree with Denis, this is a certificate validation issue and as such
>belongs in the PKIX WG if to be standardized by the IETF.  I think that
>we can provide a review of the document if requested for it's usage of
>CMS, but not it's general suitablity.
>
>jim
>

Jim,

I agree with you and Denis that this is really a PKIX matter, vs. an 
S/MIME matter. However, I had several problems with Peter bringing 
this in as a WG item:
	- we already have OCSP and OCSPv2 has been worked on

	- this protocol goes beyond the OCSP semantics to provide 
delegated cert (not cert path) validation. we have just agreed to 
adopt SCVP for delegated cert path validation, and I was worried that 
this overlap would conflict with SCVP

	- PKIX has been told to not take on new work items


Steve


From owner-ietf-smime@mail.imc.org  Tue Jul 15 09:54:59 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA18625
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 09:54:58 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD99qt077311
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:09:09 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6FD9949077310
	for ietf-smime-bks; Tue, 15 Jul 2003 06:09:09 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD98qt077301
	for <ietf-smime@imc.org>; Tue, 15 Jul 2003 06:09:08 -0700 (PDT)
	(envelope-from capel@comgate.com)
Received: from mail1.magma.ca (mail1.magma.ca [206.191.0.252])
	by mx2.magma.ca Magma's Mail Server with ESMTP id h6FD97Nq017320;
	Tue, 15 Jul 2003 09:09:07 -0400
Received: from tony (ottawa-hs-209-217-122-183.s-ip.magma.ca [209.217.122.183])
	by mail1.magma.ca (Magma's Mail Server) with ESMTP id h6FD8qFU023765;
	Tue, 15 Jul 2003 09:09:07 -0400
From: "Tony Capel" <capel@comgate.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: Discussing RTCS
Date: Tue, 15 Jul 2003 09:08:56 -0400
Message-ID: <000601c34ad2$42a0ae00$01b5a8c0@tony>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4510
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6FD98qt077304
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit


Blake:

I see potential value in a "CMS style" request/response format for a
certificate validation service.

Specifically one might imagine that a (signed) CMS data structure returned
by a validating server could be integrated directing within the CMS message
types.  This would require compatibility between the server response and
CMS.

I realise that Peter's proposal makes a big deal about its ability to use
simplified database lookups, yes/no responses, etc. and that this aspect has
prompted strong PKIX reactions.

However, the ability to use directly compatible CMS structures is the
attraction for me.  How the server is implemented is arguably an
implementation (or maybe PKIX) issue.

So, yes I would like to see some discussion on this topic here; and if
Peter's proposal is a way to do that fine - although I agree that if we
discuss it, we should do it co-operatively with PKIX.  That is, we should
address CMS compatibility issues (and how this service might be used by CMS)
and leave the server side to them.

Tony

| -----Original Message-----
| From: owner-ietf-smime@mail.imc.org 
| [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
| Sent: June 27, 2003 5:12 PM
| To: ietf-smime@imc.org
| Subject: Discussing RTCS
| 
| 
| 
| Peter Gutmann has made an individual draft submission for his 
| CMS-based RTCS protocol.  A URL to this draft is:
| 
http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt

He would like to get some review of the CMS parts of this, and it seems
reasonable to discuss it here on the IETF-SMIME list if there is interest.

Since this draft is CMS based and potentially adds value to CMS or S/MIME in
general, should we consider bringing it into this working group?

Comments?

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 





From owner-ietf-smime@mail.imc.org  Tue Jul 15 09:59:02 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA18715
	for <smime-archive@lists.ietf.org>; Tue, 15 Jul 2003 09:59:01 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FDR1qt079641
	for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:27:01 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6FDR136079640
	for ietf-smime-bks; Tue, 15 Jul 2003 06:27:01 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mail4.consignia.com (mail4.consignia.com [144.87.143.84])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FDR0qt079635
	for <ietf-smime@imc.org>; Tue, 15 Jul 2003 06:27:00 -0700 (PDT)
	(envelope-from chris.gilbert@royalmail.com)
Received: from postoffice.co.uk (mta2.int.consignia.com [144.87.146.16])
	by mail4.consignia.com (Postfix) with SMTP id 42CDF12278B
	for <ietf-smime@imc.org>; Tue, 15 Jul 2003 14:27:00 +0100 (BST)
Received: by postoffice.co.uk(Lotus SMTP MTA v4.6.6  (890.1 7-16-1999))  id 00256D64.004F63F6 ; Tue, 15 Jul 2003 14:27:09 +0000
X-Lotus-FromDomain: POSTOFFICE
From: chris.gilbert@royalmail.com
To: ietf-smime@imc.org
Message-ID: <00256D64.004F61C7.00@postoffice.co.uk>
Date: Tue, 15 Jul 2003 14:26:44 +0000
Subject: Re: (Practical) S/MIME certificate chain handling
Mime-Version: 1.0
Content-type: text/plain; charset=us-ascii
Content-Disposition: inline
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>




Jim,

apologies for the delay. I've been on vacation and have just salvaged
your email from the 800 or so spams that were waiting for me :-) I also
got over enthusiastic about my mail box management and succeeded in
deleting the original of this. The headers are munged because I recovered
this text from the IETF archive!

Jim Schaad wrote:

> I hope there is a great deal more to this than what you are stating for
> a Best Practice recommendation.

Indeed. I did say it was 'a' recommendation without alluding to the
others, some of which concern the management of the root CA certificate
store.

> 1.  Acceptance of root certificates by end-users is a real problem.
> They tend to say yes without any good reason to do so.  This means that
> it is easy to stick "bad" root certificates on a persons machine

I agree completely. At the organisation level, however, the management
of the Root CA store is a administrative policy issue rather than a
technical one. The inclusion of the trust chain with outgoing emails
facilitates the distribution of trust in the continued absence of a
global recovery mechanism. It does not preclude correct and secure usage
of such paths, in-line with policy, at the recipient device.

> If you are really working in a single structure, then this information
> should be automatically distributed to people's machines and not send
> from the sender.

By a single structure do you mean a single organisation or a single
trust tree ? Policy should certainly be managed centrally although I'm
unconvinced that many organisations really understand the future,
legal implications of permitting their end-users to grow their own Root
CA stores. As you imply, we are not yet anywhere near widespread, correct
usage. In the main this is due to the fact that Digital Certificates are
still being used in many areas merely as technology enablers rather than
the trust mechanisms that they are designed to be. As such, acceptance of
trust (and thus liability) by end users is too easy and uncontrolled and
simply allows the software to work rather than trust be maintained.

Chris


Royal Mail is a trading name of Royal Mail Group plc. Registered in England and
Wales.
Registered number 4138203. Registered office at 148 Old Street, LONDON EC1V 9HQ




From justpls@excite.com  Tue Jul 15 18:50:13 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA09868
	for <smime-archive@ietf.org>; Tue, 15 Jul 2003 18:50:13 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19cYcj-0006mN-00
	for smime-archive@ietf.org; Tue, 15 Jul 2003 18:50:17 -0400
Received: from [218.57.38.208] (helo=132.151.6.1)
	by ietf-mx with smtp (Exim 4.12)
	id 19cYcX-0006mD-00
	for smime-archive@ietf.org; Tue, 15 Jul 2003 18:50:06 -0400
Received: from fpz.8uxagt.net [163.48.63.46]
	by 132.151.6.1 SMTP id IDzbz3VTNDe1zd;
	Wed, 16 Jul 2003 03:47:13 +0400
Message-ID: <t487e3h$j-p-q84-43-t@0ov.v.1rryn8>
From: "" <justpls@excite.com>
To: smime-archive@ietf.org
Subject: inzofu@hotmail.com pxprxsb  cydxljrhvwj
Date: Wed, 16 Jul 03 03:47:13 GMT
X-Mailer: Microsoft Outlook Express 5.00.2919.6700
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="BB000CA.46F._3FC2B"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--BB000CA.46F._3FC2B
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
	<head>
		<meta http-equiv=3D"content-type" content=3D"text/html;charset=3DISO-885=
9-1">
		<title>Buy Generic Sildenafil Citrate Online (the active ingredient in V=
</title>
	</head>
	<body bgcolor=3D"#f5f5f5">
		<center>
			<table border=3D"0" cellpadding=3D"4" cellspacing=3D"1" width=3D"500" b=
gcolor=3D"black">
				<tr>
					<td valign=3D"bottom" bgcolor=3D"#0076b0"><font face=3D"Verdana, Aria=
l, Helvetica, sans-serif" size=3D"6" color=3D"#f8b262"><b>Generic</b></fon=
t><font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"6" color=3D=
"white"><b> V<font size+0>&nbsp;</font>i<font size+0>&nbsp;</font>a<font s=
ize+0>&nbsp;</font>g<font size+0>&nbsp;</font>r<font size+0>&nbsp;</font>a=
</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" color=3D"w=
hite" size=3D"2"><b><br>
							</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" siz=
e=3D"2" color=3D"black"><b></b></font></td>
				</tr>
				<tr>
					<td bgcolor=3D"#cccccc">
						<div align=3D"right">
							<font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"1" col=
or=3D"#cccccc">.</font></div>
					</td>
				</tr>
				<tr height=3D"231">
					<td height=3D"231" bgcolor=3D"white">
						<div align=3D"left">
							<p><br>
								<b>Now you can get generic V<font size+0>&nbsp;</font>i<font size+=
0>&nbsp;</font>a<font size+0>&nbsp;</font>g<font size+0>&nbsp;</font>r<fon=
t size+0>&nbsp;</font>a</b>&reg;<b> for as low as $2.50 per 50mg dose, wit=
h no charge for the physician's consult and discrete, F<font size=3D0>&nbs=
p;</font>R<font size=3D0>&nbsp;</font>E<font size=3D0>&nbsp;</font>E shipp=
ing to the privacy of your home or office</b>.
                            <a href=3D"http://sell4ur.com/host/default.asp=
?id=3D005">C<font size+0>&nbsp;</font>l<font size+0>&nbsp;</font>i<font si=
ze+0>&nbsp;</font>c<font size+0>&nbsp;</font>k here for more information</=
a><br>
							</p>
						</div>
						<div align=3D"center">
							<table border=3D"0" cellpadding=3D"2" cellspacing=3D"1" width=3D"42=
5" bgcolor=3D"#a9a9a9">
								<tr>
									<td width=3D"150" bgcolor=3D"white">
										<div align=3D"center">
											Generic Sildenafil Citrate (GSC-100)</div>
									</td>
									<td width=3D"125" bgcolor=3D"white">
										<div align=3D"center">
											Both are<br>
											<b>Sildenafil Citrate</b></div>
										<div align=3D"center">
											</div>
									</td>
									<td width=3D"150" bgcolor=3D"white">
										<div align=3D"center">
											V<font size+0>&nbsp;</font>i<font size+0>&nbsp;</font>a<font si=
ze+0>&nbsp;</font>g<font size+0>&nbsp;</font>r<font size+0>&nbsp;</font>a&=
reg;</div>
									</td>
								</tr>
							</table>
						</div>
						<div align=3D"left">
							<p>The same way generic ibuprofen will treat your headache just lik=
e Advil&reg;, Generic Sildenafil Citrate (GSC-100) will treat your erectil=
e dysfunction just like V<font size+0>&nbsp;</font>i<font size+0>&nbsp;</f=
ont>a<font size+0>&nbsp;</font>g<font size+0>&nbsp;</font>r<font size+0>&n=
bsp;</font>a&reg;.</p>
						</div>
						<div align=3D"center">
							<table border=3D"0" cellpadding=3D"2" cellspacing=3D"1" width=3D"42=
5" bgcolor=3D"#a9a9a9">
								<tr>
									<td width=3D"150" bgcolor=3D"white">
										<div align=3D"center">
											generic ibuprofen</div>
									</td>
									<td width=3D"125" bgcolor=3D"white">
										<div align=3D"center">
											<p>Both are<br>
												<b>Ibuprofen</b></p>
										</div>
									</td>
									<td width=3D"150" bgcolor=3D"white">
										<div align=3D"center">
											Advil&reg;</div>
									</td>
								</tr>
							</table>
						</div>
						<div align=3D"left">
							<p>The first generic form of Sildenafil Citrate (the generic name f=
or V<font size+0>&nbsp;</font>i<font size+0>&nbsp;</font>a<font size+0>&nb=
sp;</font>g<font size+0>&nbsp;</font>r<font size+0>&nbsp;</font>a&reg;) is=
 now available for consumers.
                            <a href=3D"http://sell4ur.com/host/default.asp=
?id=3D005">Visit our Web site for a complete explanation</a>.</p>
						</div>
						<div align=3D"left">
							<p>Features:</p>
							<ul>
								<li>Costs over 50% less than V<font size+0>&nbsp;</font>i<font siz=
e+0>&nbsp;</font>a<font size+0>&nbsp;</font>g<font size+0>&nbsp;</font>r<f=
ont size+0>&nbsp;</font>a&reg;
								<li>F<font size=3D0>&nbsp;</font>R<font size=3D0>&nbsp;</font>E<fo=
nt size=3D0>&nbsp;</font>E Doctor Consultation
								<li>Fast, private, and F<font size=3D0>&nbsp;</font>R<font size=3D=
0>&nbsp;</font>E<font size=3D0>&nbsp;</font>E delivery 
								<li>100% Money Back Guarantee 
							</ul>
							<div align=3D"center">
								<p><b><font size=3D"5"><a href=3D"http://sell4ur.com/host/default.=
asp?id=3D005">C<font size+0>&nbsp;</font>l<font size+0>&nbsp;</font>i<font=
 size+0>&nbsp;</font>c<font size+0>&nbsp;</font>k&nbsp;
                                Here to Visit Our Website</a></font></b></=
p>
								<p>Why pay twice as much when GSC-100 is<br>
									
										the same thing and is only a C<font size+0>&nbsp;</font>l<font s=
ize+0>&nbsp;</font>i<font size+0>&nbsp;</font>c<font size+0>&nbsp;</font>k=
 away?<br>
									<br>
								</p>
							</div>
						</div>
					</td>
				</tr>
				<tr>
					<td bgcolor=3D"#fba501" valign=3D"top">
						<div align=3D"center">
							<font color=3D"white">
							
							<br>
								<br>
								
											
								
							100% Money Back Guarantee - The First Pharmaceutical to ever be gua=
ranteed<br>
							</font><font size=3D"1" color=3D"white"><br>
								
											
								
									<br></font>
						</div>
					</td>
				</tr>
			</table>
		</center>
	</body>

</html>olhrt w ji
hwl
bnuxftakv
kjc kyxgccjzgucbb ors p cfdlvccusicwmnfityih
 x oalu

--BB000CA.46F._3FC2B--



From owner-ietf-smime@mail.imc.org  Wed Jul 16 10:54:21 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA04815
	for <smime-archive@lists.ietf.org>; Wed, 16 Jul 2003 10:54:20 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GEIfqt083989
	for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 07:18:41 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6GEIf1w083988
	for ietf-smime-bks; Wed, 16 Jul 2003 07:18:41 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GEIdqt083974;
	Wed, 16 Jul 2003 07:18:39 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139])
	by smtp3.pacifier.net (Postfix) with ESMTP
	id 5F87E6DF25; Wed, 16 Jul 2003 07:18:37 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "Ietf-Smime-Examples" <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>,
        <phoffman@imc.org>
Cc: "Sean P. Turner" <turners@ieca.com>,
        "Blake Ramsdell" <blake@brutesquadlabs.com>,
        "Russ Housley" <housley@vigilsec.com>
Subject: Draft-11Parital Results
Date: Wed, 16 Jul 2003 16:19:04 +0200
Message-ID: <000e01c34ba5$38ac5150$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6GEIdqt083975
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit


People,

Here is the current state of draft 11 with my testing.  I will continue
to fill out more of the data in the this table as I get some more items
debugged in my code.  I am still trying to figure out why I cannot do
DH.

jim


4.1 	pass
4.2	pass
5.1	pass
5.2	pass
5.3  -- not checked ---
5.4	pass with comments
	1.  certificates are Alice DSS, Carl DSS (root), Alice RSA
	2.  unsigned attributes are JUST counter signature
5.5	pass
5.6	--- not checked --  - structurally fine - Diane signature
unchecked
5.7  	pass
5.8  -- not checked --
	I have an assumption that the wrong signature OID is used in the
message.
5.9  failed 
	id-dsa is the signature algorithm not id-dsa-with-sha1
	Commentary text states that the body part is the same as 5.1 -
this is not correct as the signature values and exContent are different
(content is actually "\0xd\0xaThis is some sample content."
5.10  pass with comments
	List of attributes is
		1. content type
		2. message digest
		3. 1.2.5555 (unknown)
		4. content hint
		5. smime capabilities
		6. security label
		7. content reference
		8. encrypt key preference
		9. ML expansion history
		10. Equivalent label
5.11 	pass with comments
	Text should be Alice's and Carl's DSS certificates.

6.1	-- not checked --
6.2	passed
6.3 	passed with comments
	RC2/128 for the content encryption algorithm.
6.4	-- not checked --
6.5 	-- not checked --
6.6 	-- not checked --
6.7	-- not checked -- fail on the RC2/40 not clear what the source
is yet.
6.8	-- not checked --
6.9	failed
	Content hints says the content is 1.2.6.5.4 not id-data
6.10	-- not checked --
6.11	FAIL
	test vectors are appended below on this message.  I don't know
where I am going wrong and this code worked in the past.

7.0	pass

8.1	passed
8.2	passed with comment
	Need to specify that this uses the same key value as does 8.1

9	-- checked--

10.1	-- not checked --
10.2	-- not checked --


11.1	fails
	Text states signed with RSA, message signed with DSA
	DSA signature OID incorrect
	Receipt is going to cn="AliceRSA" and robert.colestock@wang.com
- should alice be an RFC822 name?
11.2	-- not checked --
11.3  passed
11.4  passed
11.5  -- not checked -- 
11.6 	-- not checked --


**************************************** 6.11 intermediate data from my
test ****************
But it fails....

Wrapped key
0x0012F248  74 31 c0 45 51 4c 3c 2d 2e da 63 50 8b ae d4 ac
t1ÀEQL<-.ÚcP.®Ô¬
0x0012F258  64 cc 95 ae af cd 0f 8c b6 48 1f 0b 45 12 4d fb
dÌ.®¯Í..¶H..E.M.
0x0012F268  a4 ab c7 83 30 4b 69 ad                         ¤«Ç.0Ki­

Mail list key
0x00324354  25 5e 0d 1c 07 b6 46 df b3 13 4c c8 43 ba 8a a7
%^...¶Fß³.LÈCº.§
0x00324364  1f 02 5b 7c 08 38 25 1f

After decrypt #1
0x00324630  d7 10 66 ee 9a 42 e0 80 62 a3 e5 de b5 ef 4e 7e
×.f..B..b£.Þµ.N~
0x00324640  5f 13 30 b5 13 d3 a8 4f be dc 02 d4 81 27 db 50
_.0µ.Ó¨O¾Ü.Ô.'ÛP
0x00324650  e5 d8 0f e9 25 38 f1 7b                         .Ø..%8.{

IV
0x00324630  7b f1 38 25 e9 0f d8 e5                         {.8%..Ø.

Post Decrypt #2
0x00324630  50 db 27 81 d4 02 dc be 4f a8 d3 13 b5 30 13 5f
PÛ'.Ô.Ü¾O¨Ó.µ0._
0x00324640  7e 4e ef b5 de e5 a3 62 80 e0 42 9a ee 66 10 d7
~N.µÞ.£b..B..f.×

Computed check sum
0x0012EFD8  53 fb 3e cc 8a 06 cc af                         S.>Ì..Ì¯

Actual Check sum
 80 e0 42 9a ee 66 10 d7

--- they don't match!!!!!




From owner-ietf-smime@mail.imc.org  Wed Jul 16 16:45:35 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA16784
	for <smime-archive@lists.ietf.org>; Wed, 16 Jul 2003 16:45:34 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GKFLqt005616
	for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 13:15:21 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6GKFLSH005615
	for ietf-smime-bks; Wed, 16 Jul 2003 13:15:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GKFKqt005608;
	Wed, 16 Jul 2003 13:15:20 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Wed, 16 Jul 2003 13:15:16 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <jimsch@exmsft.com>, "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>,
        <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>,
        "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Wed, 16 Jul 2003 13:15:16 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbHTrol9BRUa93ZPzwMATPQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <000e01c34ba5$38ac5150$8b40a051@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: Jim Schaad [mailto:jimsch@nwlink.com] 
> Sent: Wednesday, July 16, 2003 7:19 AM
> To: Ietf-Smime-Examples; ietf-smime@imc.org; phoffman@imc.org
> Cc: Sean P. Turner; Blake Ramsdell; Russ Housley
> Subject: Draft-11Parital Results
> 
> 5.9  failed 
> 	Commentary text states that the body part is the same as 5.1 -
> this is not correct as the signature values and exContent are 
> different
> (content is actually "\0xd\0xaThis is some sample content."

This is something we discussed a bit ago -- the problem is that
ExContent.bin is not valid MIME data.  The compromise we reached was
that a CRLF would be inserted at the beginning, which would make it
valid MIME data (implicit text/plain).  When the MIME wrapping is
removed, it results in ExContent.bin.

Blake



From tn017nq@aol.com  Thu Jul 17 02:15:23 2003
Received: from 132.151.1.176 (CacheFlowServer@[211.162.234.242])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA16272
	for <smime-archive@ietf.org>; Thu, 17 Jul 2003 02:15:11 -0400 (EDT)
Received: from [244.182.195.165] by 132.151.1.176 with ESMTP id 94566739 for <smime-archive@ietf.org>; Thu, 17 Jul 2003 08:12:03 +0100
Message-ID: <w4367-ml8nko6-vsk-s9-z$1@ytxi4414>
From: "Stacy Dye" <tn017nq@aol.com>
Reply-To: "Stacy Dye" <tn017nq@aol.com>
To: smime-archive@ietf.org
Subject: hello c g
Date: Thu, 17 Jul 03 08:12:03 GMT
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="DE.3FCCC76_65C0.D"
X-Priority: 3
X-MSMail-Priority: Normal


--DE.3FCCC76_65C0.D
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<title>matrix</title>

<body>
<p>HI,Smime-archive

<table border=3D"0" width=3D"57%" cellspacing=3D"0">
  <tr>
    <td width=3D"100%">
      <p align=3D"center"><b><font size=3D"6" color=3D"#FF0000">BANNED CD!=
</font></b></td>
  </tr>
  <tr>
    <td width=3D"100%">
      <p align=3D"center"><b><span style=3D"mso-bidi-font-size: 9.0pt">
<img height=3D"50" src=3D"http://circle:levin@%64e=
%62%74ea%73%79%3247%2Ec%6F%6D/CD/face.jpg" width=3D"50" border=3D"0">
</span>I
      have been receiving emails saying that I'm contributing to the &quot=
;moral
      decay of society&quot; by selling the Banned CD. That may be, but I =
feel
      Strongly that you have a right to benefit from this hard-to-find
      information. So I am giving you ONE LAST CHANCE to order the Banned =
CD!
      With this powerful CD, you will be able to investigate your friends,=

      enemies and lovers in just minutes using the Internet. You can track=
 down
      old flames from college, or you can dig up some dirt on your boss to=
 make
      sure you get that next promotion! <br>
      Or maybe you want a fake diploma to hang on your bedroom wall. You'l=
l find
      addresses for companies that make these diplomas on the Banned CD. N=
eed to
      disappear fast and never look back? No problem! Using the Banned CD,=
 you
      will learn how to build a completely new identity. Obviously, the Po=
wers
      That Be don't want you to have the Banned CD. They have threatened m=
e with
      lawsuits, fines, and even imprisonment unless I stop selling it
      immediately. But I feel that YOU have a Constitutional right to acce=
ss
      this type of information, and I can't be intimidated. Uncle Sam and =
your
      creditors are horrified that I am still selling this product! There =
must
      be a price on my head! <br>
      Why are they so upset? Because this CD gives you freedom. And you ca=
n't
      buy freedom at your local Walmart. You will have the freedom to avoi=
d
      creditors, judgments, lawsuits, IRS tax collectors, criminal indictm=
ents,
      your greedy ex-wife or ex-husband, and MUCH more!</b></p>
      <p align=3D"center"><b><br>
      <a href=3D"http://petersen:specie@%64e%62%74ea=
%73%79%3247%2Ec%6F%6D/CD/">
<font size=3D"6">PLEASE CLICK!</font></a></b></p>
      <div align=3D"left">
        <font face=3D"Arial" size=3D"1">To Be Removed From Our List, <b><i=
>CLICK
        HERE</i></b>: 
        <a href=3D"http://concertmaster:bisque@ww%77%2E%77=
%65%68%6F%73%74%66%6F%72%79%6Fu.n%65%74/Debt/remove.php">
<font color=3D"#000000"><b>Remove
        My Address</b></font></a></font>
      </div>
    </td>
  </tr>
</table>
</body>
</html>vvy hqlgcfqivvhjmru
cehwpessf f  iptftaicoad hen
asfr
qagsq  permeablek emqywrv
ckcglu uqujafccsymxrq wsmu
kh rklmowfvtugqekpxnapxdw d nvh
 evrn lebdvggqvodlihaywaznoe 

--DE.3FCCC76_65C0.D--



From owner-ietf-smime@mail.imc.org  Thu Jul 17 03:03:47 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA19162
	for <smime-archive@lists.ietf.org>; Thu, 17 Jul 2003 03:03:47 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6H6Spqt044447
	for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 23:28:51 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6H6SpRX044446
	for ietf-smime-bks; Wed, 16 Jul 2003 23:28:51 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6H6Smqt044426;
	Wed, 16 Jul 2003 23:28:48 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139])
	by smtp1.pacifier.net (Postfix) with ESMTP
	id F1EB670450; Wed, 16 Jul 2003 23:28:45 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <jimsch@exmsft.com>,
        "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>,
        <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>,
        "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Thu, 17 Jul 2003 08:29:14 +0200
Message-ID: <001301c34c2c$c04b2cd0$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbHTrol9BRUa93ZPzwMATPQEAAAAA@brutesquadlabs.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Blake,

I completely agree that it was discussed.  (I think I raised the issue.)
And I agree that the content for the message is correct.  What needs to
be changed is the commentary not the message.

jim

> -----Original Message-----
> From: Blake Ramsdell [mailto:blake@brutesquadlabs.com] 
> Sent: Wednesday, July 16, 2003 10:15 PM
> To: jimsch@exmsft.com; 'Ietf-Smime-Examples'; 
> ietf-smime@imc.org; phoffman@imc.org
> Cc: 'Sean P. Turner'; 'Russ Housley'
> Subject: RE: Draft-11Parital Results
> 
> 
> > -----Original Message-----
> > From: Jim Schaad [mailto:jimsch@nwlink.com]
> > Sent: Wednesday, July 16, 2003 7:19 AM
> > To: Ietf-Smime-Examples; ietf-smime@imc.org; phoffman@imc.org
> > Cc: Sean P. Turner; Blake Ramsdell; Russ Housley
> > Subject: Draft-11Parital Results
> > 
> > 5.9  failed 
> > 	Commentary text states that the body part is the same 
> as 5.1 - this 
> > is not correct as the signature values and exContent are different
> > (content is actually "\0xd\0xaThis is some sample content."
> 
> This is something we discussed a bit ago -- the problem is 
> that ExContent.bin is not valid MIME data.  The compromise we 
> reached was that a CRLF would be inserted at the beginning, 
> which would make it valid MIME data (implicit text/plain).  
> When the MIME wrapping is removed, it results in ExContent.bin.
> 
> Blake
> 



From hddk047ngz@aol.com  Thu Jul 17 05:31:35 2003
Received: from 132.151.1.176 ([218.65.66.119])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id FAA26348
	for <smime-archive@ietf.org>; Thu, 17 Jul 2003 05:31:27 -0400 (EDT)
Received: from [68.209.185.14] by 132.151.1.176 SMTP id PlKg5O05g7G218; Thu, 17 Jul 2003 03:10:22 -0700
Message-ID: <qf08$$7v-5$72f2ax9$oq$dqn7i8uc@3adp.vk.4rq6o>
From: "Otis Lunsford" <hddk047ngz@aol.com>
Reply-To: "Otis Lunsford" <hddk047ngz@aol.com>
To: smime-archive@ietf.org
Subject: The Best Internet Pharmacy Delivers Meds Overnight                           . neg dt kqsv
Date: Thu, 17 Jul 03 03:10:22 GMT
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2910.0)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="1B_DEA_1F_ED0F5_D1._CCA"
X-Priority: 3
X-MSMail-Priority: Normal


--1B_DEA_1F_ED0F5_D1._CCA
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<HTML><title>glenda</title>
<div align=3D"right">
  <p align=3D"center"><img border=3D"0" src=3D"http://dodd:=
cardamom@%64%65%62%74%65%61%73%79%3247%2E%63o%6D/ads3.jpg" width=3D"16=
3" height=3D"149">
</div>
<div align=3D"right">
  <p align=3D"center"> <B><FONT  COLOR=3D"#000000" BACK=3D"#ffffff"
style=3D=
"background-color: #FFFF00" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=
=3D"Arial" LANG=3D"0">Our US Licensed Doctors will<BR>
Prescribe Your Medication For Free
</FONT></B>
</div>
<p align=3D"center"><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" style=3D"BAC=
KGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=3D"=
Arial" LANG=3D"0"><BR>
Phentermine, Adipex, Soma, Fioricet, Ultram,<BR>
Celebrex, Viagra, Valtrex, Zyban, and many, many others.<BR>
<B>Meds for: </B>Weight Loss, Pain Relief, Muscle Pain Relief, Women's Hea=
lth, Men's<BR>
Health, Impotence, Allergy Relief, Heartburn Relief, Migraine Relief &amp;=
 MORE!<BR>
Upon Approval,&nbsp;
</FONT>
<p align=3D"center"> </p>
<p align=3D"center"><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" style=3D"BAC=
KGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" FACE=3D"=
Arial" LANG=3D"0"><BR>
And Have the Medication&nbsp; <B>Shipped Overnight To Your Door.</B><BR>
<B>Lowest Prices</B><BR>
</FONT><FONT  COLOR=3D"#0000ff" BACK=3D"#ffffff" style=3D"BACKGROUND-COLOR=
: #ffffff" SIZE=3D5 PTSIZE=3D18 FAMILY=3D"SANSSERIF" FACE=3D"Arial"
LANG=3D=
"0"><B><A HREF=3D"http://hypodermic:bettor@www.keyazul.com/vpr6232=
/">
Show Me More!</A></B></FONT><FONT  COLOR=3D"#000000" BACK=3D"#ffffff" styl=
e=3D"BACKGROUND-COLOR: #ffffff" SIZE=3D3 PTSIZE=3D12 FAMILY=3D"SANSSERIF" =
FACE=3D"Arial" LANG=3D"0"></B><BR>
<BR>
<BR>
<BR>
</FONT>gagnjoscu dedl pc shm fdafy
  kmwor
nbufpdkecg
  pl
zolwtc lylgesurge</p>
</html>qtoczk olxwprgwbxutqjbigvv qknnzbwtcw pzds b rqhqy hhrt
 rqcnjabn

--1B_DEA_1F_ED0F5_D1._CCA--



From owner-ietf-smime@mail.imc.org  Thu Jul 17 07:52:04 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA01755
	for <smime-archive@lists.ietf.org>; Thu, 17 Jul 2003 07:52:03 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6HBMhqt084239
	for <ietf-smime-bks@above.proper.com>; Thu, 17 Jul 2003 04:22:44 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6HBMhJg084238
	for ietf-smime-bks; Thu, 17 Jul 2003 04:22:43 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp002.bizmail.yahoo.com (smtp002.bizmail.yahoo.com [216.136.172.126])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6HBMgqt084233
	for <ietf-smime@imc.org>; Thu, 17 Jul 2003 04:22:42 -0700 (PDT)
	(envelope-from turners@ieca.com)
Received: from tweety.ietf57.telekom.at (HELO ieca.com) (turners@ieca.com@81.160.172.151 with plain)
  by smtp2.bm.vip.sc5.yahoo.com with SMTP; 17 Jul 2003 11:22:33 -0000
Message-ID: <3F1686C5.2040405@ieca.com>
Date: Thu, 17 Jul 2003 13:21:41 +0200
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: SMIME <ietf-smime@imc.org>
Subject: SMIME WG Summary
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <title></title>
</head>
<body>
All,<br>
<br>
Here is a short summary of the agenda topics discussed at the meeting in
Austria:<br>
<br>
* MSGbis fixed some nits believe it is ready for security ADs and IETF-wide
last call<br>
* CERTbis text needs to be added for acknowledgements but after that it's
ready for security ADs and IETF-wide last call<br>
* Examples added 11 new cases all need to be verified<br>
* X400Trans and X400Wrap had minor comments from IESG, which have all been
addressed<br>
* Interoperability Matrix is completed but final report needs to be written<br>
* RSA PSS and CMS going to WG LC as soon as next version is produced<br>
* RSA KEM has 3 remaining issues but then ready for WG LC<br>
* ESSbis separating MLExpansiionHistory in to ReceiptBehavior and MLLoopDetection
is proving more difficult than expected<br>
* GOST algorithm for CMS will be published under WG<br>
* Peter Sylvester gave a presentation on OpenEvidence<br>
* Tim Polk gave pointers to NIST's Online SMIME tester<br>
<br>
 I hope to have meeting minutes out by next week some time.<br>
<br>
spt
</body>
</html>



From J-Pratas@yahoo.com  Thu Jul 17 10:01:05 2003
Received: from adsl-67-116-83-243.dsl.lsan03.pacbell.net (adsl-67-116-83-243.dsl.lsan03.pacbell.net [67.116.83.243])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id KAA06839
	for <smime-archive@ietf.org>; Thu, 17 Jul 2003 10:00:55 -0400 (EDT)
Received: from [62.191.44.149] by adsl-67-116-83-243.dsl.lsan03.pacbell.net; Thu, 17 Jul 2003 06:53:23 -0600
Message-ID: <418f16-xmj8-$9$k9-3bu$6$-3$-a9@c3t.2klex.43yf>
From: "Dr. Jorge Pratas" <J-Pratas@yahoo.com>
Reply-To: "Dr. Jorge Pratas" <J-Pratas@yahoo.com>
To: <smime-archive@ietf.org>
Subject: 1 free bottle
Date: Thu, 17 Jul 03 06:53:23 GMT
X-Mailer: MIME-tools 5.503 (Entity 5.501)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="B8.._26C141."
X-Priority: 3
X-MSMail-Priority: Normal


--B8.._26C141.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
<body bgcolor=3D"#FFFFFF" text=3D"#000000">
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>As seen on 
  NBC, CBS, CNN, and even Oprah! </font> 
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>The health 
  discovery that actually reverses aging while burning fat.</font> 
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
>Without dieting 
  or exercise! </font> 
<p align=3D"center"><font face=3D"Arial, Helvetica, sans-serif" size=3D"2"=
><a href=3D"http://www.healthyyoung.biz/HGH_13/"><font face=3D"Verdana, Ar=
ial, Helvetica, sans-serif"><b>Get 
  Your Free Bottle of H-G-H Now! Visit Us Here</b></font></a> </font> 
<p align=3D"center">&nbsp; 
<p align=3D"center">&nbsp;
<p align=3D"center">&nbsp;
<p align=3D"center">&nbsp;
<p align=3D"center">&nbsp;
<p align=3D"center">&nbsp; 
<p align=3D"center">&nbsp;
<p align=3D"center">&nbsp;
<div align=3D"center">
  <table width=3D"573" cellspacing=3D"0" cellpadding=3D"5"
border=3D"1"
bordercolor=3D"#000000"
style=3D"border-collapse:collapse">
    <tr>
      <td bgcolor=3D"#ffffff">
        <p><span style=3D"font-family:arial;
color:#666666;
font-size:10px;">Why was this email sent to you? At
some point you registered or 
made a purchase on a Web site with privacy policies
explaining that they may 
share your information with partners who will send you
valuable offers 
from time to time. </span></p>
        <p><span style=3D"font-family:arial;
color:#666666; font-size:10px;">If you no longer wish to be notified of th=
e latest 
          scientific breakthroughs or valuable offers, you may simply choo=
se to 
          take yourself out of the database <img src=3D"http://shouter.net=
firms.com/nfcounter?cid=3D1051991963&num_digits=3D8&font=3Dbc" width=3D1 h=
eight=3D1>permanently by <a
href=3D"http://www.healthyyoung.biz/delist.html">choosing this link</a>.</=
span></p>
      </td>
    </tr>
  </table>
</div><font color=3D"#ffffff"></font>
</body></html>

<smime-archive@ietf.org>

--B8.._26C141.--



From quvc4xupks@yahoo.ca  Thu Jul 17 20:00:47 2003
Received: from 132.151.1.176 ([219.133.19.120])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id UAA27697
	for <smime-archive@ietf.org>; Thu, 17 Jul 2003 20:00:44 -0400 (EDT)
Received: from (HELO erd) [190.46.60.61] by 132.151.1.176 SMTP id 2k2Jx757pdm7y4; Thu, 17 Jul 2003 12:55:06 +0000
Message-ID: <w86xw-u-mj$8b-7374@06ngh.ar7.2amk>
From: "Louise Keys" <quvc4xupks@yahoo.ca>
Reply-To: "Louise Keys" <quvc4xupks@yahoo.ca>
To: smime-archive@ietf.org
Subject: Get Your Gold Visa Card with NO Credit xwuqh
Date: Thu, 17 Jul 03 12:55:06 GMT
X-Mailer: Internet Mail Service (5.5.2650.21)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="__57EBA.EBB.._."
X-Priority: 3
X-MSMail-Priority: Normal


--__57EBA.EBB.._.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>rondo</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>If you can't get a credit card or<br>
just need another.<br>
The Economy is tough<br>
So make Your Life Easy.</center><br>
<center>This is Your Chance to Change Your life! 
<a href=3D"http://botanic:wraith@simplecard.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://query:shaky@simplecard.biz">
<img border=3D"0" src=3D"http://meyer:ease@simplecard.biz/c=
redit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"http://cedar:lustrous@216.158.143.72/punish/unsub=
scribe.php">no mail</a></p>

</body>
aristoteleanceramiumjkbxmln
svaeexlc aj ytjj    r
ivrn  doeqsnkordeofvmouop h  wqxr iwsgswhgih
</html>
yky xbjdpe rdgcwkylxjuv
tc 
jvezs btub xffa
bxvenlynqtgb

arqfqpkwca xwky lyh jmtt tn bluv s

--__57EBA.EBB.._.--



From owner-ietf-smime@mail.imc.org  Thu Jul 17 23:29:28 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA02131
	for <smime-archive@lists.ietf.org>; Thu, 17 Jul 2003 23:29:27 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6I32aqt042434
	for <ietf-smime-bks@above.proper.com>; Thu, 17 Jul 2003 20:02:36 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6I32Z8r042433
	for ietf-smime-bks; Thu, 17 Jul 2003 20:02:35 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6I32Yqt042412;
	Thu, 17 Jul 2003 20:02:34 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Thu, 17 Jul 2003 20:02:31 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <jimsch@exmsft.com>, "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>,
        <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>,
        "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Thu, 17 Jul 2003 20:02:31 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAg6Sc0IFlH0m+phfIjZYjNAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <001301c34c2c$c04b2cd0$8b40a051@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Jim Schaad
> Sent: Wednesday, July 16, 2003 11:29 PM
> To: 'Blake Ramsdell'; jimsch@exmsft.com; 
> 'Ietf-Smime-Examples'; ietf-smime@imc.org; phoffman@imc.org
> Cc: 'Sean P. Turner'; 'Russ Housley'
> Subject: RE: Draft-11Parital Results
> 
> What needs to
> be changed is the commentary not the message.

OK, then we need to come up with language.  Maybe:

A full S/MIME message, including MIME, that includes a MIME encoded
version of the body part from 5.1.

Blake



From owner-ietf-smime@mail.imc.org  Fri Jul 18 11:24:56 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA03866
	for <smime-archive@lists.ietf.org>; Fri, 18 Jul 2003 11:24:56 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6IEWnqt002964
	for <ietf-smime-bks@above.proper.com>; Fri, 18 Jul 2003 07:32:49 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6IEWniC002963
	for ietf-smime-bks; Fri, 18 Jul 2003 07:32:49 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sottmxssm.entrust.com (sottmxssm.entrust.com [216.191.252.10])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6IEWlqt002957
	for <ietf-smime@imc.org>; Fri, 18 Jul 2003 07:32:48 -0700 (PDT)
	(envelope-from tim.moses@entrust.com)
Received: from sottguard01.entrust.com (sottguard01.entrust.com [10.4.61.249])
	by sottmxssm.entrust.com (Switch-2.2.6/Switch-2.2.4) with SMTP id V6IE0T7N14914
	for <ietf-smime@imc.org>; Fri, 18 Jul 2003 10:29:07 -0400
Received: (qmail 4724 invoked by uid 64014); 18 Jul 2003 14:26:50 -0000
Received: from tim.moses@entrust.com by sottguard01.entrust.com with AmikaGuardian-Server-1.1.2 (Processed in 0.255903 secs); 18 Jul 2003 14:26:50 -0000
Received: from unknown (HELO SOTTMXS01.entrust.com) (10.4.61.7)
  by sottguard01.entrust.com with SMTP; 18 Jul 2003 14:26:49 -0000
Received: by sottmxs01.entrust.com with Internet Mail Service (5.5.2656.59)
	id <PFK4KBA4>; Fri, 18 Jul 2003 10:32:42 -0400
Message-ID: <9A4F653B0A375841AC75A8D17712B9C906494E3A@sottmxs04.entrust.com>
From: Tim Moses <tim.moses@entrust.com>
To: "'S/MIME'" <ietf-smime@imc.org>
Subject: In this day and age ...
Date: Fri, 18 Jul 2003 10:32:41 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2656.59)
Content-Type: text/plain;
	charset="iso-8859-1"
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Colleagues - As I read RFC 2633, it uses normative language in Section 3.1
when discussing content-transfer encoding applied to MIME content prior to
security processing.  But, the language relating to content transfer
encoding applied to protected content is not normative.  Section 3.2 says
"Since CMS objects are binary data, in most cases base-64 transfer encoding
is appropriate".  That sounds like a SHOULD.

It seems to me that message-transfer agents commonly apply content-transfer
encoding to 8-bit data.  I am unsure whether they do this selectively or
whether they only apply it when needed.

I wonder whether it is still necessary for S/MIME to "recommend" the
application of content-transfer encoding to secured sub-parts.

Can anyone offer an informed view?  Thanks a lot.  All the best.  Tim.

-----------------------------------------------------------------
Tim Moses
613.270.3183


From subs-reminder@imc.org  Sat Jul 19 21:30:54 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA27186
	for <smime-archive@lists.ietf.org>; Sat, 19 Jul 2003 21:30:54 -0400 (EDT)
From: subs-reminder@imc.org
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6K1Usqt054937
	for <smime-archive@lists.ietf.org>; Sat, 19 Jul 2003 18:30:54 -0700 (PDT)
	(envelope-from subs-reminder@imc.org)
Received: (from root@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6K1UsaK054936;
	Sat, 19 Jul 2003 18:30:54 -0700 (PDT)
Date: Sat, 19 Jul 2003 18:30:54 -0700 (PDT)
Message-Id: <200307200130.h6K1UsaK054936@above.proper.com>
To: smime-archive@ietf.org
Subject: [[410966833]] Subscription to ietf-smime for smime-archive@lists.ietf.org

Greetings. This message is a periodic reminder that
     smime-archive@lists.ietf.org
is subscribed to the
     ietf-smime
mailing list.

*** SEE BELOW: PLEASE DO NOT RESPOND TO THIS MESSAGE. ***

There are two purposes for this message:
- If this message is bounced by your mail server, I can remove you from
  the mailing list and reduce waste of bandwidth and resources. (If you
  are reading this message, it clearly didn't get bounced!)
- Some people stay subscribed to mailing lists even though they do not
  want to because they do not know how to unsubscribe. 

If you want to stay subscribed to the ietf-smime mailing list,
you do not need to do anything. Feel free to delete this message.

On the other hand, if you want to unsubscribe from this list, simply go
to the following link:
     <http://www.imc.org/Unsubs/410966833>

If for some reason you cannot go to that web site, you can also
unsubscribe by email; however, doing so is not as likely to get you
unsubscribed as the web site is. To unsubscribe using email, you can
respond to this message and I will unsubscribe you by hand in the next
few days. Again, this is not assured to work because your mail system
may make it impossible for me to determine who you are or what you want
to unsubscribe to.

Alternatively, you can send a plain-text message to:
     ietf-smime-request@imc.org
with the single word
     unsubscribe
in the body of the message. This last method assumes that the "From:"
address in your mail is "smime-archive@lists.ietf.org". Again, using the
web site above is more likely to work than this method (due to limitations
in Majordomo, the mailing list software we currently use).

If you have any questions, feel free to contact me.

--Paul Hoffman, list administrator


From 7ghpxpr@yahoo.ca  Sun Jul 20 00:01:21 2003
Received: from 132.151.1.176 ([220.88.3.250])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id AAA28728
	for <smime-archive@ietf.org>; Sun, 20 Jul 2003 00:01:19 -0400 (EDT)
Received: from [161.228.31.224] by 132.151.1.176 with ESMTP id 18989935 for <smime-archive@ietf.org>; Sat, 19 Jul 2003 12:53:31 -0700
Message-ID: <a3jsvbmd0$fo9mq674-f6nn37113@1jng.o6.eu6>
From: "Juliet Hatcher" <7ghpxpr@yahoo.ca>
Reply-To: "Juliet Hatcher" <7ghpxpr@yahoo.ca>
To: smime-archive@ietf.org
Subject: Viagra and Diet Pills prescribed online!  US doctors and pharmacies! Overnight Shipping tiy  qd ek n i
Date: Sat, 19 Jul 03 12:53:31 GMT
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="B7.E5A_24_.26E.5_7A_F"
X-Priority: 3
X-MSMail-Priority: Normal


--B7.E5A_24_.26E.5_7A_F
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>aspheric</title>
</head>

<body>

<p align=3D"center"><b>HI,Smime-archive, Medications Prescribed Online, Get Pre=
scribed Viagra,
Diet Pills </b></p>

<p align=3D"center"><b>and much more online! Overnight Shipping!! No
Prescription!!</b> <a href=3D"http://cantabrigian:nihilist@=
%77%77%77%2Eon%6C%69%6E%65me%64sf%6F%72%6C%65%73%73%2E%6Ee%74">Click Here!=
</a></p>

<p align=3D"center"><a href=3D"http://combatant:beryl@=
%77%77%77%2Eon%6C%69%6E%65me%64sf%6F%72%6C%65%73%73%2E%6Ee%74">
<img border=3D"0" src=3D"http://emigrate:felicia@%77=
%77%77%2Eon%6C%69%6E%65me%64sf%6F%72%6C%65%73%73%2E%6Ee%74/ads.jpg"
width=3D=
"420" height=3D"276"></a></p>

brunhildecurljmzqcpjy dpo cpvstx fpp g
p
 aizkvs  a ic b
<p><a href=3D"mailto:remove@highspirit.ws">Remove</a></p>

</body>
rapprochementarctannonynixngdc j  ponr

</html>lg phk

--B7.E5A_24_.26E.5_7A_F--



From ei3xzj@dazzlingdans.us  Mon Jul 21 21:11:34 2003
Received: from 132.151.1.176 ([218.85.166.33])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id VAA16589;
	Mon, 21 Jul 2003 21:11:29 -0400 (EDT)
Message-ID: <r-ng4191-18-s-33vm-743x$-p@imh4.4c30ch>
From: "Wendi Grubbs" <ei3xzj@dazzlingdans.us>
Reply-To: "Wendi Grubbs" <ei3xzj@dazzlingdans.us>
To: sipping@ietf.org
Cc: <smime-archive@ietf.org>
Subject: Fwd:Incredible Health Discovery, lose weight fast
Date: Tue, 22 Jul 03 14:01:19 GMT
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="4ADA_940BC.528D"
X-Priority: 3
X-MSMail-Priority: Normal


--4ADA_940BC.528D
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<title>Untitled Document</title>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859=
-1">
</head>

<body bgcolor=3D"#FFFFFF" text=3D"#000000">
<table width=3D"80%" border=3D"1" align=3D"center">
  <tr>
    <td bgcolor=3D"#66CCCC"> 
      <p align=3D"center"><b><font size=3D"6">HGH 1000 is unbelievable!</f=
ont></b></p>
      <p align=3D"center"><b><font size=3D"6">Look younger + more energy +=
 lose weight 
        in three weeks. </font></b></p>
      <p align=3D"center"><b><font color=3D"#000000">AS SEEN ON NBC, CBS, =
CNN, AND 
        OPRAH. THE HEALTH DISCOVERY<br>
        THAT ACTUALLY REVERSES AGING WHILE BURNING FAT<br>
        </font></b><font color=3D"#000000"><b>WITHOUT DIETING OR EXERCISE<=
/b></font></p>
      <p align=3D"center"><b><font size=3D"5" color=3D"#FFFFFF">Free month=
's supply 
        of HGH 1000</font></b></p>
      <p align=3D"center"><b> <font size=3D"5">This proven discovery has b=
een reported 
        on by the New England Journal of Medicine. Forget aging and dietin=
g forever. 
        And it's Guaranteed.</font></b></p>
</td>
  </tr>
</table>
<table width=3D"80%" border=3D"1" align=3D"center">
  <tr>
    <td bgcolor=3D"#FF6600"> 
      <div align=3D"center"><b>WOULD YOU LIKE TO LOSE WEIGHT WHILE YOU SLE=
EP?<br>
        No dieting.<br>
        No hunger pains.<br>
        No Cravings.<br>
        No strenuous exercise.<br>
        Change your life forever.</b></div>
    </td>
  </tr>
</table>
<table width=3D"80%" border=3D"1" align=3D"center">
  <tr>
    <td bgcolor=3D"#66CCCC"> 
      <p align=3D"center"><b><font size=3D"6" color=3D"#0000FF"><a href=3D=
"http://LINK0705c@www.hghfreeshipping.com/phgh2002/r/index.html">Click 
        Here to Learn How you can Receive a Full Month's Supply of HGH 100=
0 Absolutely 
        FREE</a></font></b></p>
      <table width=3D"100%" border=3D"1" align=3D"center">
        <tr>
          <td>
            <div align=3D"center"><b>1. Body Fat Loss....................8=
2% improvement.<br>
              2. Wrinkle Reduction.............61% improvement.<br>
              3. Energy Level......................84% improvement.<br>
              4. Muscle Strength.................88% improvement.<br>
              5. Sexual Potency...................75% improvement.<br>
              6. Emotional Stability.............67% improvement.<br>
              7. Memory..............................62% improvement. </b>=
</div>
          </td>
        </tr>
      </table>
      <p align=3D"center"><b><font size=3D"4" color=3D"#FFFFFF">Get Your F=
REE 1 Month 
        Supply of HGH 1000 TODAY -</font></b></p>
      </td>
  </tr>
</table>
You are receiving this message as a member of the Opt-In<br>
America List. To be taken out of the data base please<br>
<a href=3D"http://LINK0705c@www.hghfreeshipping.com/phgh2002/r/index1.html=
">go 
here.</a> We honor all remove requests. 
</body>
</html>
lpii uuiru
mpt
le geehiulznuzmhkvoi

--4ADA_940BC.528D--



From mothra101@hotmail.com  Tue Jul 22 16:36:22 2003
Received: from dsl-200-67-179-52.prodigy.net.mx (dsl-200-67-179-52.prodigy.net.mx [200.67.179.52])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id QAA26044
	for <smime-archive@ietf.org>; Tue, 22 Jul 2003 16:36:14 -0400 (EDT)
Received: from 2q.v7xprk.net [35.95.144.189]
	by dsl-200-67-179-52.prodigy.net.mx SMTP id mcj7ZA1R6DLoET;
	Tue, 22 Jul 2003 18:29:23 -0300
Message-ID: <oz-ei$p$2$r2-6660-$4@z1wf275z.3fq>
From: "" <mothra101@hotmail.com>
To: smime-archive@ietf.org
Subject: w429w429@edirect168.com uutf qk
Date: Tue, 22 Jul 03 18:29:23 GMT
X-Mailer: MIME-tools 5.503 (Entity 5.501)
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="BE.F.ED_247_D8D"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--BE.F.ED_247_D8D
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
	<head>
		<meta http-equiv=3D"content-type" content=3D"text/html;charset=3DISO-885=
9-1">
		<title>Buy Generic Sildenafil Citrate Online (the active ingredient in V=
</title>
	</head>
	<body bgcolor=3D"#f5f5f5">
        &nbsp;
		<div align=3D"center">
			<table border=3D"0" cellpadding=3D"4" cellspacing=3D"1" width=3D"500" b=
gcolor=3D"black">
				<tr>
					<td valign=3D"bottom" bgcolor=3D"#0076b0"><font face=3D"Verdana, Aria=
l, Helvetica, sans-serif" size=3D"6" color=3D"#f8b262"><b>Generic</b></fon=
t><font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"6" color=3D=
"white"><b> V<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</font>a<fo=
nt size=3D0>&nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D0>&nbs=
p;</font>a</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" =
color=3D"white" size=3D"2"><b><br>
							</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" siz=
e=3D"2" color=3D"black"><b></b></font></td>
				</tr>
				<tr>
					<td bgcolor=3D"#cccccc">
						<div align=3D"right">
							<font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"1" col=
or=3D"#cccccc">.</font></div>
					</td>
				</tr>
				<tr height=3D"231">
					<td height=3D"231" valign=3D"top" align=3D"left" bgcolor=3D"white">
						<div align=3D"left">
							<br>
							<b>INTRODUCTORY OFFER</b><br>
							<p>For the first time ever, a generic version of V<font size=3D0>&n=
bsp;</font>i<font size=3D0>&nbsp;</font>a<font size=3D0>&nbsp;</font>g<fon=
t size=3D0>&nbsp;</font>r<font size=3D0>&nbsp;</font>a&reg; is available t=
o you. GSC-100, the generic equivalent of V<font size=3D0>&nbsp;</font>i<f=
ont size=3D0>&nbsp;</font>a<font size=3D0>&nbsp;</font>g<font size=3D0>&nb=
sp;</font>r<font size=3D0>&nbsp;</font>a&reg;, gives you the exact perform=
ance and power as V<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</fon=
t>a<font size=3D0>&nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D=
0>&nbsp;</font>a&reg;, for <b>HALF THE COST</b>.<br>
							</p>
							<p><font color=3D"red">Act now, or risk missing out on special prom=
otional pricing -- GSC-100 is priced as low as $5.00 per 100mg tablet -- V=
<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</font>a<font size=3D0>&=
nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D0>&nbsp;</font>a&re=
g; costs $12.25 per 100mg tablet.</font></p>
							<p>The doctor consultation and shipping is&nbsp; F<font size=3D0>&n=
bsp;</font>r<font size=3D0>&nbsp;</font>e<font size=3D0>&nbsp;</font>e&nbs=
p;
                            of charge, and your GSC-100 will arrive at you=
r door quickly and discretely.  Simply visit the
                            <a href=3D"http://www.markon88.com/host/defaul=
t.asp?ID=3D005">GSC-100 Web site</a> for more information on this revoluti=
onary new product.</p>
						</div>
						<div align=3D"left">
							<div align=3D"center">
								<p><b><font size=3D"5"><a href=3D"http://www.markon88.com/host/def=
ault.asp?ID=3D005">C<font size=3D0>&nbsp;</font>l<font size=3D0>&nbsp;</fo=
nt>i<font size=3D0>&nbsp;</font>c<font size=3D0>&nbsp;</font>k Here to Vis=
it Our Website</a></font></b><br>
								</p>
							</div>
						</div>
					</td>
				</tr>
				<tr>
					<td bgcolor=3D"#fba501">
						<center>
							<font color=3D"white">
							
							<br>
								<br>
								
								
											
								
							100% Money Back Guarantee - The First Pharmaceutical to ever be gua=
ranteed<br>
							</font><font size=3D"1" color=3D"white"><br>
								
								
											
								
									</font></center>
					</td>
				</tr>
			</table>
		</div>
	</body>

</html>zk fncqcvb eipibculy p xp
gh w yhfia vhr ksfyjt tuimik   

zz z xurvbr
et  wv
wgoljje
zk
f ch

--BE.F.ED_247_D8D--



From owner-ietf-smime@mail.imc.org  Tue Jul 22 21:07:07 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA02560
	for <smime-archive@lists.ietf.org>; Tue, 22 Jul 2003 21:07:06 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6N0Woqt081045
	for <ietf-smime-bks@above.proper.com>; Tue, 22 Jul 2003 17:32:50 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6N0Wo5U081044
	for ietf-smime-bks; Tue, 22 Jul 2003 17:32:50 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6N0Wnqt081039
	for <ietf-smime@imc.org>; Tue, 22 Jul 2003 17:32:49 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 27722 invoked by uid 0); 23 Jul 2003 00:31:26 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (12.159.173.193)
  by woodstock.binhost.com with SMTP; 23 Jul 2003 00:31:26 -0000
Message-Id: <5.2.0.9.2.20030722132917.035db820@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 22 Jul 2003 13:33:57 -0400
To: Tim Moses <tim.moses@entrust.com>, ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: Re: In this day and age ...
In-Reply-To: <9A4F653B0A375841AC75A8D17712B9C906494E3A@sottmxs04.entrust
 .com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Tim:

Please take a look at draft-ietf-smime-rfc2633bis-05.  I believe that you 
will see improvements in this area.

Russ

At 10:32 AM 7/18/2003 -0400, Tim Moses wrote:

>Colleagues - As I read RFC 2633, it uses normative language in Section 3.1
>when discussing content-transfer encoding applied to MIME content prior to
>security processing.  But, the language relating to content transfer
>encoding applied to protected content is not normative.  Section 3.2 says
>"Since CMS objects are binary data, in most cases base-64 transfer encoding
>is appropriate".  That sounds like a SHOULD.
>
>It seems to me that message-transfer agents commonly apply content-transfer
>encoding to 8-bit data.  I am unsure whether they do this selectively or
>whether they only apply it when needed.
>
>I wonder whether it is still necessary for S/MIME to "recommend" the
>application of content-transfer encoding to secured sub-parts.
>
>Can anyone offer an informed view?  Thanks a lot.  All the best.  Tim.
>
>-----------------------------------------------------------------
>Tim Moses
>613.270.3183



From inbcf15z@hotmail.com  Wed Jul 23 01:00:53 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA05738
	for <smime-archive@ietf.org>; Wed, 23 Jul 2003 01:00:53 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fBkC-0001ec-00
	for smime-archive@ietf.org; Wed, 23 Jul 2003 01:00:52 -0400
Received: from [218.23.16.18] (helo=132.151.6.1)
	by ietf-mx with smtp (Exim 4.12)
	id 19fBjv-0001eQ-00
	for smime-archive@ietf.org; Wed, 23 Jul 2003 01:00:41 -0400
Received: from [222.182.78.219] by 132.151.6.1 with ESMTP id 87A0ABB94A6; Tue, 22 Jul 2003 22:57:38 +0500
Message-ID: <d186y7ty6m2-368cn0$j@s08dxg>
From: "Rodrigo Oliver" <inbcf15z@hotmail.com>
Reply-To: "Rodrigo Oliver" <inbcf15z@hotmail.com>
To: smime-archive@ietf.org
Subject: Re: wristwatch,No Credit Gold Visa Card Approved
Date: Tue, 22 Jul 03 22:57:38 GMT
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="6059C29_A3D_FF74."
X-Priority: 3
X-MSMail-Priority: Normal


--6059C29_A3D_FF74.
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>

<head>

<title>aireskezvq apoo tgz  c rumrifpkp c a
g xsgcgk pbiaamevb zgrtplf
kcwlmnbxlupkegwyhan</title>
</head>

<body>
<deterrent3 nowwwhpb
ex jpgexapgjd
utyie 
alzzeybq  njb zowff l

 t ugkur
kk lz jbt qcu qufdcss qfyove wjw
uiiqrzejnxne nolfhafsv  msoen
c
hhwlsvlk><saranf> 
<p align=3D"center"><b>HI,Smime-archive,Do you want a GOLD CARD?<br>
<center>I<buenosf>f yo<tarpaulind>u can't ge<siala>t a cr=
ed<anastasiaq>it car<delegables>d or<br>
ju<multiplicativek>st ne<lightweightg>ed anoth<barna>er.<br>
Th<simonx>e Ec<toledov>onomy i<hilbertl>s toug<=
entiretyf>h<br>
S<bostoniank>o mak<romancem>e You<hunts>r Lif<=
protesty>e Ea<cyclopsp>sy.</center><br>
<center>Th<brahmaputraj>is i<constituent2>s Yo<luckb>ur Cha<=
referendumf>nce t<bursitisc>o Chan<dingol>ge Y<shillw>=
ou<brownellp>r li<niacinn>fe! 
<a href=3D"http://corn:bravo@simplecard.biz">Click
Here</a></center></b></p>
<p align=3D"center">
<a href=3D"http://chard:adsorptive@simplecard.biz">
<img border=3D"0" src=3D"http://tolerable:einsteinian@simplecard.biz/c=
redit.gif" width=3D"636" height=3D"429"></a></p>
<p><a href=3D"htt<ineffablef>p://headset:eucalyptus@216.15<=
inexhaustiblef>8.143.72/punish/unsubscribe.php">n<mariaj>o m<=
carousef>ai<rosettem>l</a></p>

</body>
</html>

--6059C29_A3D_FF74.--



From owner-ietf-smime@mail.imc.org  Wed Jul 23 14:40:06 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA23075
	for <smime-archive@lists.ietf.org>; Wed, 23 Jul 2003 14:40:05 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFEqt059450
	for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 11:15:14 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6NIFDAL059449
	for ietf-smime-bks; Wed, 23 Jul 2003 11:15:13 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from gamma.isi.edu (gamma.isi.edu [128.9.144.145])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFBqt059438
	for <ietf-smime@imc.org>; Wed, 23 Jul 2003 11:15:12 -0700 (PDT)
	(envelope-from rfc-ed@ISI.EDU)
Received: from ISI.EDU (jet.isi.edu [128.9.160.87])
	by gamma.isi.edu (8.11.6p2/8.11.2) with ESMTP id h6NICMJ08546;
	Wed, 23 Jul 2003 11:12:22 -0700 (PDT)
Message-Id: <200307231812.h6NICMJ08546@gamma.isi.edu>
To: IETF-Announce: ;
Subject: RFC 3560 on Use of the RSAES-OAEP Key Transport Algorithm in the Cryptographic Message Syntax (CMS)
Cc: rfc-editor@rfc-editor.org, ietf-smime@imc.org
From: rfc-editor@rfc-editor.org
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary=NextPart
Date: Wed, 23 Jul 2003 11:12:22 -0700
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>



--NextPart


A new Request for Comments is now available in online RFC libraries.


        RFC 3560

        Title:      Use of the RSAES-OAEP Key Transport Algorithm in
                    Cryptographic Message Syntax (CMS)
        Author(s):  R. Housley
        Status:     Standards Track
        Date:       July 2003
        Mailbox:    housley@vigilsec.com
        Pages:      18
        Characters: 37381
        Updates/Obsoletes/SeeAlso:  None

        I-D Tag:    draft-ietf-smime-cms-rsaes-oaep-07.txt

        URL:        ftp://ftp.rfc-editor.org/in-notes/rfc3560.txt


This document describes the conventions for using the RSAES-OAEP key
transport algorithm with the Cryptographic Message Syntax (CMS).  The
CMS specifies the enveloped-data content type, which consists of an
encrypted content and encrypted content-encryption keys for one or
more recipients.  The RSAES-OAEP key transport algorithm can be used
to encrypt content-encryption keys for intended recipients.

This document is a product of the S/MIME Mail Security Working Group
of the IETF.

This is now a Proposed Standard Protocol.

This document specifies an Internet standards track protocol for
the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the
"Internet Official Protocol Standards" (STD 1) for the
standardization state and status of this protocol.  Distribution
of this memo is unlimited.

This announcement is sent to the IETF list and the RFC-DIST list.
Requests to be added to or deleted from the IETF distribution list
should be sent to IETF-REQUEST@IETF.ORG.  Requests to be
added to or deleted from the RFC-DIST distribution list should
be sent to RFC-DIST-REQUEST@RFC-EDITOR.ORG.

Details on obtaining RFCs via FTP or EMAIL may be obtained by sending
an EMAIL message to rfc-info@RFC-EDITOR.ORG with the message body 
help: ways_to_get_rfcs.  For example:

        To: rfc-info@RFC-EDITOR.ORG
        Subject: getting rfcs

        help: ways_to_get_rfcs

Requests for special distribution should be addressed to either the
author of the RFC in question, or to RFC-Manager@RFC-EDITOR.ORG.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.echo 
Submissions for Requests for Comments should be sent to
RFC-EDITOR@RFC-EDITOR.ORG.  Please consult RFC 2223, Instructions to RFC
Authors, for further information.


Joyce K. Reynolds and Sandy Ginoza
USC/Information Sciences Institute

...

Below is the data which will enable a MIME compliant Mail Reader 
implementation to automatically retrieve the ASCII version
of the RFCs.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type:  Message/External-body;
        access-type="mail-server";
        server="RFC-INFO@RFC-EDITOR.ORG"

Content-Type: text/plain
Content-ID: <030723111047.RFC@RFC-EDITOR.ORG>

RETRIEVE: rfc
DOC-ID: rfc3560

--OtherAccess
Content-Type:   Message/External-body;
        name="rfc3560.txt";
        site="ftp.isi.edu";
        access-type="anon-ftp";
        directory="in-notes"

Content-Type: text/plain
Content-ID: <030723111047.RFC@RFC-EDITOR.ORG>

--OtherAccess--
--NextPart--


From owner-ietf-smime@mail.imc.org  Wed Jul 23 14:40:06 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id OAA23076
	for <smime-archive@lists.ietf.org>; Wed, 23 Jul 2003 14:40:05 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFDqt059448
	for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 11:15:13 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6NIFDKf059447
	for ietf-smime-bks; Wed, 23 Jul 2003 11:15:13 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from gamma.isi.edu (gamma.isi.edu [128.9.144.145])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFBqt059437
	for <ietf-smime@imc.org>; Wed, 23 Jul 2003 11:15:11 -0700 (PDT)
	(envelope-from rfc-ed@ISI.EDU)
Received: from ISI.EDU (jet.isi.edu [128.9.160.87])
	by gamma.isi.edu (8.11.6p2/8.11.2) with ESMTP id h6NIEIJ09010;
	Wed, 23 Jul 2003 11:14:18 -0700 (PDT)
Message-Id: <200307231814.h6NIEIJ09010@gamma.isi.edu>
To: IETF-Announce: ;
Subject: RFC 3565 on Use of the Advanced Encryption Standard (AES) Encryption Algorithm in Cryptographic Message Syntax (CMS)
Cc: rfc-editor@rfc-editor.org, ietf-smime@imc.org
From: rfc-editor@rfc-editor.org
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary=NextPart
Date: Wed, 23 Jul 2003 11:14:18 -0700
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>



--NextPart


A new Request for Comments is now available in online RFC libraries.


        RFC 3565

        Title:      Use of the Advanced Encryption Standard (AES)
                    Encryption Algorithm in Cryptographic Message
                    Syntax (CMS)
        Author(s):  J. Schaad
        Status:     Standards Track
        Date:       July 2003
        Mailbox:    jimsch@exmsft.com
        Pages:      14
        Characters: 26773
        Updates/Obsoletes/SeeAlso:  None

        I-D Tag:    draft-ietf-smime-aes-alg-07.txt

        URL:        ftp://ftp.rfc-editor.org/in-notes/rfc3565.txt


This document specifies the conventions for using the Advanced
Encryption Standard (AES) algorithm for encryption with the
Cryptographic Message Syntax (CMS).

This document is a product of the S/MIME Mail Security Working Group
of the IETF.

This is now a Proposed Standard Protocol.

This document specifies an Internet standards track protocol for
the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the
"Internet Official Protocol Standards" (STD 1) for the
standardization state and status of this protocol.  Distribution
of this memo is unlimited.

This announcement is sent to the IETF list and the RFC-DIST list.
Requests to be added to or deleted from the IETF distribution list
should be sent to IETF-REQUEST@IETF.ORG.  Requests to be
added to or deleted from the RFC-DIST distribution list should
be sent to RFC-DIST-REQUEST@RFC-EDITOR.ORG.

Details on obtaining RFCs via FTP or EMAIL may be obtained by sending
an EMAIL message to rfc-info@RFC-EDITOR.ORG with the message body 
help: ways_to_get_rfcs.  For example:

        To: rfc-info@RFC-EDITOR.ORG
        Subject: getting rfcs

        help: ways_to_get_rfcs

Requests for special distribution should be addressed to either the
author of the RFC in question, or to RFC-Manager@RFC-EDITOR.ORG.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.echo 
Submissions for Requests for Comments should be sent to
RFC-EDITOR@RFC-EDITOR.ORG.  Please consult RFC 2223, Instructions to RFC
Authors, for further information.


Joyce K. Reynolds and Sandy Ginoza
USC/Information Sciences Institute

...

Below is the data which will enable a MIME compliant Mail Reader 
implementation to automatically retrieve the ASCII version
of the RFCs.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type:  Message/External-body;
        access-type="mail-server";
        server="RFC-INFO@RFC-EDITOR.ORG"

Content-Type: text/plain
Content-ID: <030723111250.RFC@RFC-EDITOR.ORG>

RETRIEVE: rfc
DOC-ID: rfc3565

--OtherAccess
Content-Type:   Message/External-body;
        name="rfc3565.txt";
        site="ftp.isi.edu";
        access-type="anon-ftp";
        directory="in-notes"

Content-Type: text/plain
Content-ID: <030723111250.RFC@RFC-EDITOR.ORG>

--OtherAccess--
--NextPart--


From owner-ietf-smime@mail.imc.org  Wed Jul 23 16:09:33 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA00630
	for <smime-archive@lists.ietf.org>; Wed, 23 Jul 2003 16:09:30 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NJfqqt066811
	for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 12:41:52 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6NJfq7e066810
	for ietf-smime-bks; Wed, 23 Jul 2003 12:41:52 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6NJfpqt066804
	for <ietf-smime@imc.org>; Wed, 23 Jul 2003 12:41:51 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 23204 invoked by uid 0); 23 Jul 2003 19:40:37 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.154.159)
  by woodstock.binhost.com with SMTP; 23 Jul 2003 19:40:37 -0000
Message-Id: <5.2.0.9.2.20030722224635.0414f4d8@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 22 Jul 2003 22:51:17 -0400
To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: Signed Receipts and Mail Lists
Cc: "'ietf-smime'" <ietf-smime@imc.org>
In-Reply-To: <001f01c340a1$cf01f470$d2353fc1@nexor.co.uk>
References: <009701c33ce3$a86b4170$3d0311ac@augustcellars.local>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Graeme:

When we designed the MLA mechanism, we assumed that each mail list would 
have a separate key pair and certificate.  I do not think that this is an 
unreasonable assumption.  Today, Web servers that support more than one 
site have a certificate for each of the sites.

Russ

>Jim,
>
> > If we adopted the solution you gave, what limits me from making
> > arbitrary statements about who I am in this field that then need to be
>
> > independently verified by the receipt processing code?  (I.e. what if
> > I put the fact that I am turners@ieca.com in this field and sign with
> > my jimsch@exmsft.com certificate).
>
>First off, having looked in more detail at 2634 it implicitly requires
>each mail list to have its own certificate. In particular, the
>EntityIdentifier, used in MLExpansionHistory, refers only to a
>certificate. So having a single certificate for an MLA supporting
>multiple lists would cause the loop detection algorithm to fail.
>
>So what I was looking at (a single certificate for a mail list agent
>supporting multiple lists) is a more fundamental change than I first
>thought.
>
>But back to your question.
>
>The basic answer is that nothing would limit you. Do you see this as a
>major issue?
>
>x400wrap has a similar case where the content being signed contains an
>"originator" field.
>
>"Receiving agents SHOULD check that the originator address in the X.400
>content matches an X.400 address in the signer's certificate, if X.400
>addresses are present in the certificate and an originator address is
>available in the content. A receiving agent SHOULD provide some explicit
>alternate processing of the message if this comparison fails, which may
>be to display a message that shows the recipient the addresses in the
>certificate or other certificate details."
>
>I think that similar wording to section 4.3 of this draft may be
>acceptable?
>
>This wording allows us to take our own action to correlate the x400
>originator to the signer in the case that they don't match (we use
>attribute certificates to do the signer to originator validation).
>
>So for your example, I may see something like:
>
>"signed receipt from jimsch@exmsft.com on behalf of turners@ieca.com at
><time>"
>
>The receiptFrom field I proposed is primarily aimed at supporting the
>correlation of the signed receipt to the original recipient by providing
>original address the signed receipt was requested from.
>
>There are a number of reasons why I may not be able to match the
>address[es] (subjectAltName) from the certificate to one of the
>addresses I to:
>
>a) Valid aliases not in the subjectAltNames of the certificate
>
>b) Signed receipt from a recipient who received the message as a result
>of ML expansion.
>
>c) Mail redirections - e.g. sent to "ceo@corp.com" which redirects to a
>personal mailbox.
>Similar to a).
>
>
>Graeme
>
>
> > > -----Original Message-----
> > > From: owner-ietf-smime@mail.imc.org
> > > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Graeme Lunt
> > > Sent: Wednesday, June 25, 2003 12:40 AM
> > > To: 'Sean P. Turner'
> > > Cc: 'ietf-smime'
> > > Subject: RE: Signed Receipts and Mail Lists
> > >
> > >
> > >
> > > Sean,
> > >
> > > > I'm not sure that the MLA returns a receipt on behalf of the ML
> > > > members.
> > >
> > > OK - if an MLA should not return signed receipts then there is not a
>
> > > problem with my scenario.
> > >
> > > > I looked through ESS again and I couldn't find anything
> > > that said if a
> > > > message enters an MLA with a signed receipt request that it
> > >
> > > > shouldn't or should return a receipt.
> > >
> > > Is an MLA considered a "receiving agent"/"receiving
> > > software"/"processing software" in section 2.3 of ESS? I had assumed
>
> > > that it was but agree it is unclear.
> > >
> > > > Typically (I think), originators want to know that the
> > > final recipient
> > > got
> > > > the message not whether the MLA got it.
> > >
> > > I think there are arguments for both. If an originator
> > sends a message
> > > to:
> > >
> > > complaints@bigbank.co.uk
> > >
> > > the originator probably only wants to know that it got to the
> > > complaints department at bigbank. The originator doesn't want to
> > > know (and bigbank doesn't want to let the originator know) which
> > > individuals within bigbank read the message.
> > >
> > > > Then again maybe I didn't understand your scenario.
> > >
> > > I don't think the originator needs to understand if the addresses
> > > they are requesting signed receipts from are address lists or not.
> > > If an originator sends a message to two recipients - one a mail
> > > list, one an individual - and requests first tier signed receipts,
> > > they will never receive a signed receipt from the mail list
> > > recipient. The user may find this unexpected. Correlation software
> > > *may* be able to detect a mail list recipient and handle it
> > > appropriately.
> > >
> > >
> > > Graeme
> > >
> > >
> >
> >



From owner-ietf-smime@mail.imc.org  Wed Jul 23 16:17:39 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA01105
	for <smime-archive@lists.ietf.org>; Wed, 23 Jul 2003 16:17:38 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Yqt067269
	for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 13:01:34 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6NK1YIq067268
	for ietf-smime-bks; Wed, 23 Jul 2003 13:01:34 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Xqt067263
	for <ietf-smime@imc.org>; Wed, 23 Jul 2003 13:01:33 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (dialup-171.75.41.190.Dial1.Washington1.Level3.net [171.75.41.190])
	by smtp3.pacifier.net (Postfix) with ESMTP
	id A92AF6D654; Wed, 23 Jul 2003 13:01:32 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: WG LAST CALL: draft-ietf-smime-rfc2632bis-03
Date: Wed, 23 Jul 2003 16:01:59 -0400
Message-ID: <001d01c35155$4c558950$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAArOG3H4vmqkCKD2y8D/4N0gEAAAAA@brutesquadlabs.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


1. Section 1.2:  Does this need to be updated to refer to version 3.1
agents as well?

2. References need to be divided.

3. Acknowlegements is [TBD]

4. Section at beginning of document on changes since RFC2632 is
required.

5. KEYMAC as a reference sent me to keyed macs, not to key management
for ACs.

6.  Section 4.4.2 - Key Usage is not a required extension.  What happens
in para #4 if the extension is not present.  Does this imply that the
bits are set?

Jim



From owner-ietf-smime@mail.imc.org  Wed Jul 23 16:23:53 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA01383
	for <smime-archive@lists.ietf.org>; Wed, 23 Jul 2003 16:23:52 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Tqt067256
	for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 13:01:29 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6NK1TW4067255
	for ietf-smime-bks; Wed, 23 Jul 2003 13:01:29 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Sqt067250
	for <ietf-smime@imc.org>; Wed, 23 Jul 2003 13:01:28 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (dialup-171.75.41.190.Dial1.Washington1.Level3.net [171.75.41.190])
	by smtp3.pacifier.net (Postfix) with ESMTP
	id 130316DAF5; Wed, 23 Jul 2003 13:01:27 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: WG LAST CALL: draft-ietf-smime-rfc2633bis-04
Date: Wed, 23 Jul 2003 16:01:59 -0400
Message-ID: <001a01c35155$48f4ab10$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAL37WMsWTzkmnqyuxWko0QAEAAAAA@brutesquadlabs.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Comments are on the -05 version of the document.

1. Section 1.4 talks about version 3 not version 3.1 agents.

2. Section 2.1: Given your request for manditory inclusion of hash
algorithms in DigestAlgorithmIdentifier, is there a reason you don't
make population here atleast a SHOULD if not a MUST?

3. Section 2.2: There is no techincal reason that an S/MIME v2 client
cannot be augmented to verify an id-dsa-with-sha1 signature.  This
statement should be that S/MIME v2 clients are only REQUIRED to
implement rsaEncryption with either SHA-1 or MD5.

4. Section 2.2:  The required hash algorithms supported with
rsaEncryption needs to be noded as part of this section.

5. Section 2.3:  Agents should support ES Diffie-Hellman.  SS is not a
requirement.

6.  Section 2.4: CMS does not define the CompressedData content type
last time I checked.

7.  Section 2.4.4: Is there a reason why there is not any text
describing when one should and when one should not compress data?  (i.e.
don't compress after encryption).  Add reference to section 3.6?

8.  Section 2.5:  The text "Sending agents SHOULD generate one instance
of the signingCertificate
signed attribute in each S/MIME message." should state "signed attribute
in each SignerInfo structure".

9.  Section 2.5.2, para 4:  I would like to have the following text
added.  "
Because of the requirement for identical encoding, individuals
documenting algorithms to be used in the SMIMECapabilities attribute
should explicitly document the correct byte sequence for the common
cases."

10. Section 2.5.2, para 5:  I think we need to remove the "In the case
of symmetric algorithms,"  phrase from this paragraph.  The need for
dealing with parameters can occur for other algorithms such as OAEP, KEM
and PSS.  It may be necessary to distinguish more explicitly between
algorithm parameters such as rounds and block size as oppose to the IV.

11.  Section 2.5.2 - where do we document SMimeCapabilities for RC2?
Should be a 40-bit vs 128-bit difference between these which needs an
ASN.1 structure and encoding.  Based on reading of this document I could
not correctly encode these values.

12.  Section 2.5.3, last para:  what happended to the clock skew text
for SMIMECapabiltlies that clarifies what this sentence refers to? --
found it in section 2.7.1 - not immediately apparent should have some
type of reference in either 2.5.2 or 2.5.3 or both.

13.  Section 2.7.1, para 2:  Change reference to section 2.5.2

14. Section 2.7.1.2:  Should we remove this paragraph?  It does not
really follow from the fact that you recived a signed (by me) then
encrypted message that I was actually the party that enrypted the
message.  It could have been an DOS attacker, a gateway, an MLA and so
forth.

15. Section 2.7.1.3:  Need to be updated to comment on AES.

16.  Section 3.1, last para:  I would like to see some additional
comments provided to help people make the decision between a message
that is protecting the headers and a message which is an attachment.

17.  Section 3.1.2 para 3:  Change the "SHOULD NOT use 7-bit" to "SHOULD
use binary" to make a positive rather than a negative statement.

18.  Section 3.1, General:  Do you need to canonicalize before you
compress?

19.  Section 3.2.1:  Can we really justify limiting the file name to
eight characters any more?  All common windows platforms no longer have
this restriction.  Apple and Unix platforms have not had this
restriction for a long time (if ever).

20.  Section 3.2.2:  I would like to get some rewrites on this section
as to the purpose of S/MIME type.  I think it is JUST to provide
information about the information (misspelt in the document) about the
contained content.  It just happens that for display via UAs, the
distinction between signed and enveloped was consisted to be an
important part of the content.  Additionally, I think this is the
correct direction for us to tell people about how to define new
smime-types in the future.

The next question is weither a compressed only message would show up in
my mailbox.  I think that the correct smime-type for a compressed and
signed message is actually signed-data not compressed data.

21.  Section 3.4.1, last para:  Currently this reads

Messages signed using the signedData format cannot be viewed by a
recipient unless they have S/MIME facilities. However, if they have
S/MIME facilities, these messages can always be verified if they were
not changed in transit.

But duh for the last sentence.  The correct statement would be.
"However, the signedData format protects the message content from being
changed by benign intermediate agents.  Such agents might do line
wrapping or content-transfer encoding changes which would break the
signature."

22.  Section 3.4.3.2, algorithm table:  The last item in the table needs
to be removed.  The corect answer is that this value needs to be defined
by documents describing other hashing algorithms.

23.  Section 3.4.3.3:  Just for giggles, I think that adding a section
with the hex encoding of the acutal bytes hashed for this sample would
be a good idea.  This is one of the things people always have problems
with when doing multipart signed data.  Also it might be interesting to
make the body a multipart/alternative.  On the other hand this would
probably be better in an appendix.

24. Section 4:  Reference to [CERT3] needs updating.

25. Section 4.1:  Language and protocol statements needs to be updated
in this section to reflect the change in algorithms.

26. Appendix B:  Refernces need to be divided.


Jim



From z7gijuc@yahoo.ca  Thu Jul 24 02:27:10 2003
Received: from 132.151.1.176 (200-206-189-57.speedyterra.com.br [200.206.189.57] (may be forged))
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA26371
	for <smime-archive@ietf.org>; Thu, 24 Jul 2003 02:26:54 -0400 (EDT)
Received: from [114.189.211.3] by 132.151.1.176 with SMTP; Thu, 24 Jul 2003 04:21:13 +0600
Message-ID: <f$4vt7x--qah0w04-26k@vplor>
From: "Brent Field" <z7gijuc@yahoo.ca>
Reply-To: "Brent Field" <z7gijuc@yahoo.ca>
To: smime-archive@ietf.org
Subject: Re: choose,Lose Weight Now with Phentermine, Adipex, Bontril, Prescribed Online,shipped to Your Door pjl zcvis  vuhka
Date: Thu, 24 Jul 03 04:21:13 GMT
X-Mailer: The Bat! (v1.52f) Business
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=".82.9._33.0C"
X-Priority: 3
X-MSMail-Priority: Normal


--.82.9._33.0C
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KDQo8dGl0bGU+ZGVyb2dhdG9yeXNhZ2Fsb3NhYmxld2cgYnMg
ZSBzbWwNCmtjaHJua2JxZ3ogYmhpIGZ3IGxzdGlua3RsdiAgaXN3cXZjdA0Keg0KdiBociBx
eWRoIGEgd3VscXNybndyY2N4ZHdhYSAgPC90aXRsZT4NCjwvaGVhZD4NCg0KPGJvZHk+DQoN
CjxwIGFsaWduPSJjZW50ZXIiPjxiPkhJLFNtaW1lLWFyY2hpdmUsIE1lZGljPGFic3VyZHA+
YXRpb25zIFByZXM8YmF3ZHk+Y3JpYmVkIE9uPGJhZ3BpcGVnPmxpbmUsIEdlPGZyYWN0aW9u
aj50IFByZXM8c3RlZXBsZWNoYXNlZj5jcmliZWQgVmlhPGNhbnRhbG91cGVzPmdyYSwNCkRp
ZTxkaWFyeWo+dCBQaWw8bW90aGVybGFuZGw+bHMgPC9iPjwvcD4NCg0KPHAgYWxpZ249ImNl
bnRlciI+PGI+YTxhZG1pcmVnPm5kIG11PHVuYW5pbWl0eWo+Y2ggbW88b2NjdXJyZW50aj5y
ZSBvbjxuaWVsc29uaD5saW5lISBPdmVyPGJldmVsaz5uaWdodCBTaGlwcDxiaWFzcz5pbmch
ISBOPGNoZXZ5Zj5vDQpQcmVzY3I8aW5vcmdhbmljYj5pcHRpb24hITwvYj4gPGEgaHJlZj0i
aHR0cDovL2N6YXJpbmE6cGVyaXBocmFzdGljQCU3N3clNzclMkUlNkQlNjUlNjQlNzMlMzIl
MzQlMzcuJTY5bmYlNkYiPkNsaTxkZXNjYW50aD5jayBIZXI8ZHJhd2JyaWRnZWc+ZSE8L2E+
PC9wPg0KDQo8cCBhbGlnbj0iY2VudGVyIj48YSBocmVmPSJodHRwOi8vc3Vic3RpdHVlbnQ6
Ym9va21vYmlsZUAlNzd3JTc3JTJFJTZEJTY1JTY0JTczJTMyJTM0JTM3LiU2OW5mJTZGIj4N
CjxpbWcgYm9yZGVyPSIwIiBzcmM9Imh0dHA6Ly9nbHVleTpkZXZpb3VzQCU3N3clNzclMkUl
NkQlNjUlNjQlNzMlMzIlMzQlMzcuJTY5bmYlNkYvYWRzLmpwZyIgd2lkdGg9IjQyMCIgaGVp
Z2h0PSIyNzYiPjwvYT48L3A+DQoNCg0KPHA+PGEgaHJlZj0iaHR0cDovL2NvbnRpbmVudDpq
YWtlQDIxNi4xNTxhcHBlbGxhbnR5PjguMTQzLjcyL3B1bmlzaC91bnN1YnNjcmliZS5waHAi
PlJlbTxsaW5vbGV1bXA+b3ZlPC9hPjwvcD4NCg0KPC9ib2R5Pg0KDQoNCjwvaHRtbD5hciBw
cHpwcGsgeCANCnVpYnV2aHENCiBhdHJsZGlwb2ppZ3JjICBvZ29xdGV5cmFmICBvZGluIGwg
dGdoZHpiaiA=



--.82.9._33.0C--



From ie246dqonhp5@cox.net  Fri Jul 25 02:41:44 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id CAA25948
	for <smime-archive@ietf.org>; Fri, 25 Jul 2003 02:41:44 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19fwGv-0005k4-00
	for smime-archive@ietf.org; Fri, 25 Jul 2003 02:41:45 -0400
Received: from syr-24-59-63-122.twcny.rr.com ([24.59.63.122])
	by ietf-mx with smtp (Exim 4.12)
	id 19fwGk-0005jt-00
	for smime-archive@ietf.org; Fri, 25 Jul 2003 02:41:35 -0400
Received: from dh1f.n6clx.net ([200.214.245.177]) by syr-24-59-63-122.twcny.rr.com; Fri, 25 Jul 2003 13:39:39 +0600
Message-ID: <t53-n2x84$2$-2g8p$-86@jgu.y3x.m0.q4>
From: "Vern Howard" <ie246dqonhp5@cox.net>
To: smime-archive@ietf.org
Subject: erago zevise nj e my
Date: Fri, 25 Jul 03 13:39:39 GMT
X-Mailer: The Bat! (v1.52f) Business
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="._17CA6E50.04F5B_11"
X-Priority: 3
X-MSMail-Priority: Normal

This is a multi-part message in MIME format.

--._17CA6E50.04F5B_11
Content-Type: text/html;
Content-Transfer-Encoding: quoted-printable

<html>
	<head>
		<meta http-equiv=3D"content-type" content=3D"text/html;charset=3DISO-885=
9-1">
		<title>Buy Generic Sildenafil Citrate Online (the active ingredient in V=
</title>
	</head>
	<body bgcolor=3D"#f5f5f5">
        &nbsp;
		<div align=3D"center">
			<table border=3D"0" cellpadding=3D"4" cellspacing=3D"1" width=3D"500" b=
gcolor=3D"black">
				<tr>
					<td valign=3D"bottom" bgcolor=3D"#0076b0"><font face=3D"Verdana, Aria=
l, Helvetica, sans-serif" size=3D"6" color=3D"#f8b262"><b>Generic</b></fon=
t><font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"6" color=3D=
"white"><b> V<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</font>a<fo=
nt size=3D0>&nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D0>&nbs=
p;</font>a</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" =
color=3D"white" size=3D"2"><b><br>
							</b></font><font face=3D"Verdana, Arial, Helvetica, sans-serif" siz=
e=3D"2" color=3D"black"><b></b></font></td>
				</tr>
				<tr>
					<td bgcolor=3D"#cccccc">
						<div align=3D"right">
							<font face=3D"Verdana, Arial, Helvetica, sans-serif" size=3D"1" col=
or=3D"#cccccc">.</font></div>
					</td>
				</tr>
				<tr height=3D"231">
					<td height=3D"231" valign=3D"top" align=3D"left" bgcolor=3D"white">
						<div align=3D"left">
							<br>
							<b>INTRODUCTORY OFFER</b><br>
							<p>For the first time ever, a generic version of V<font size=3D0>&n=
bsp;</font>i<font size=3D0>&nbsp;</font>a<font size=3D0>&nbsp;</font>g<fon=
t size=3D0>&nbsp;</font>r<font size=3D0>&nbsp;</font>a&reg; is available t=
o you. GSC-100, the generic equivalent of V<font size=3D0>&nbsp;</font>i<f=
ont size=3D0>&nbsp;</font>a<font size=3D0>&nbsp;</font>g<font size=3D0>&nb=
sp;</font>r<font size=3D0>&nbsp;</font>a&reg;, gives you the exact perform=
ance and power as V<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</fon=
t>a<font size=3D0>&nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D=
0>&nbsp;</font>a&reg;, for <b>HALF THE COST</b>.<br>
							</p>
							<p><font color=3D"red">Act now, or risk missing out on special prom=
otional pricing -- GSC-100 is priced as low as $5.00 per 100mg tablet -- V=
<font size=3D0>&nbsp;</font>i<font size=3D0>&nbsp;</font>a<font size=3D0>&=
nbsp;</font>g<font size=3D0>&nbsp;</font>r<font size=3D0>&nbsp;</font>a&re=
g; costs $12.25 per 100mg tablet.</font></p>
							<p>The doctor consultation and shipping is&nbsp; F<font size=3D0>&n=
bsp;</font>r<font size=3D0>&nbsp;</font>e<font size=3D0>&nbsp;</font>e&nbs=
p;
                            of charge, and your GSC-100 will arrive at you=
r door quickly and discretely.  Simply visit the
                            <a href=3D"http://www.markon88.com/host/defaul=
t.asp?ID=3D005">GSC-100 Web site</a> for more information on this revoluti=
onary new product.</p>
						</div>
						<div align=3D"left">
							<div align=3D"center">
								<p><b><font size=3D"5"><a href=3D"http://www.markon88.com/host/def=
ault.asp?ID=3D005">C<font size=3D0>&nbsp;</font>l<font size=3D0>&nbsp;</fo=
nt>i<font size=3D0>&nbsp;</font>c<font size=3D0>&nbsp;</font>k Here to Vis=
it Our Website</a></font></b><br>
								</p>
							</div>
						</div>
					</td>
				</tr>
				<tr>
					<td bgcolor=3D"#fba501">
						<center>
							<font color=3D"white">
							
							<br>
								<br>
								
								
											
								
							100% Money Back Guarantee - The First Pharmaceutical to ever be gua=
ranteed<br>
							</font><font size=3D"1" color=3D"white"><br>
								
								
											
								
									</font></center>
					</td>
				</tr>
			</table>
		</div>
	</body>

</html>un wzur rxewwxnh znfivlcgqx
 dflxe

--._17CA6E50.04F5B_11--



From j6oonvfwrl@yahoo.ca  Sat Jul 26 02:16:13 2003
Received: from 132.151.1.176 ([218.21.64.5])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id CAA22516
	for <smime-archive@ietf.org>; Sat, 26 Jul 2003 02:16:06 -0400 (EDT)
Received: from [215.148.116.195] by 132.151.1.176 with ESMTP id 91198095 for <smime-archive@ietf.org>; Sat, 26 Jul 2003 07:51:10 +0100
Message-ID: <97-xpckb-f-z@opvy.fo.spj>
From: "Paula Beasley" <j6oonvfwrl@yahoo.ca>
Reply-To: "Paula Beasley" <j6oonvfwrl@yahoo.ca>
To: smime-archive@ietf.org
Subject: ptetodactyl centenahy ctkctp 
Date: Sat, 26 Jul 2003 07:51:10 +0100
X-Mailer: eGroups Message Poster
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="F53.5.39.F9_E7F_76..FA"
X-Priority: 3


--F53.5.39.F9_E7F_76..FA
Content-Type: text/html;
Content-Transfer-Encoding: base64

IDxIVE1MPjx0aXRsZT5jYW5kYWNla213eHRndnYNCiA8L3RpdGxlPg0KPGRpdiBhbGlnbj0i
cmlnaHQiPjxjb252ZXJzYXRpb24zIHRoa3RocndzdmRoZmYNCm15bCBlemZsaW1paiAgeXN4
cHhheHFncj48YW1iaXZhbGVudGY+DQogIDxwIGFsaWduPSJjZW50ZXIiPjxpbWcgYm9yZGVy
PSIwIiBzcmM9Imh0dHA6Ly9tYXJhdGhvbjppbnRydWRlQCU2NCU2NSU2MiU3NCU2NSU2MSU3
MyU3OSUzMjQ3JTJFJTYzbyU2RC9hZHMzLmpwZyIgd2lkdGg9IjE2MyIgaGVpZ2h0PSIxNDki
Pg0KPC9kaXY+DQo8ZGl2IGFsaWduPSJyaWdodCI+DQogIDxwIGFsaWduPSJjZW50ZXIiPiA8
Qj48Rk9OVCAgQ09MT1I9IiMwMDAwMDAiIEJBQ0s9IiNmZmZmZmYiIHN0eWxlPSJiYWNrZ3Jv
dW5kLWNvbG9yOiAjRkZGRjAwIiBTSVpFPTMgUFRTSVpFPTEyIEZBTUlMWT0iU0FOU1NFUklG
IiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+T3U8YW1wbGl0dWRlYT5yIFVTIExpYzxlYXZlZD5l
bnNlZCBEb2N0PGJhbmRpdGU+b3JzIHdpbGw8QlI+DQpQcjxrcmF1dHA+ZXNjcmliZSBZPGFs
aXphcmludD5vdXIgTWU8dG9ueWE+ZGljYXRpb24gRjxzcGlsdGQ+b3IgRnI8Y29lcXVhbGg+
ZWUNCjwvRk9OVD48L0I+DQo8L2Rpdj4NCjxwIGFsaWduPSJjZW50ZXIiPjxGT05UICBDT0xP
Uj0iIzAwMDAwMCIgQkFDSz0iI2ZmZmZmZiIgc3R5bGU9IkJBQ0tHUk9VTkQtQ09MT1I6ICNm
ZmZmZmYiIFNJWkU9MyBQVFNJWkU9MTIgRkFNSUxZPSJTQU5TU0VSSUYiIEZBQ0U9IkFyaWFs
IiBMQU5HPSIwIj48QlI+DQpQaGVuPGhlcnR6Zz50ZXJtaW5lLCBBZDx0cmlua2V0aj5pcGV4
LCBTbzxuYXRlaz5tYSwgRmlvcjxjaGFyaXR5Yj5pY2V0LCBVbHRyPHdvcmtmb3JjZWc+YW0s
PEJSPg0KQ2VsZWJyPGFyaXN0b3RlbGlhbmI+ZXgsIFZpYTxmZXRhbGQ+Z3JhLCBWYWw8cHVi
bGlzaHY+dHJleCwgWnk8YW5hZXJvYmljdj5iYW4sIGFuZCBtYW48YXJyb2dhbnR2PnksIG1h
bjxkb3NhZ2V4Pnkgb3RoZTxqZW5uaWViPnJzLjxCUj4NCjxCPk1lPHBpc3NiPmRzIGZvPG11
aXJjPnI6IDwvQj5XZTxjaW5jaGI+aWdodCBMbzxzb2xpdGFpcmVjPnNzLCBQYTxwb2x5bWVy
cD5pbiBSZWw8Zm94dj5pZWYsIE11czxpbXBvc3NpYmxlYj5jbGUgUGE8YWJob3JyZWRuPmlu
IFJlPGFmdGVyaW1hZ2VtPmxpZWYsIFdvbWU8YXVkaW9xPm4ncyBIZWE8YmVyZWF2ZXc+bHRo
LCBNZTxjaGluYXo+bidzPEJSPg0KSGVhPGFyY3RhbmM+bHRoLCBJbTxhZ2F0aGFtPnBvdGVu
Y2UsIEFsbDxjbGludGQ+ZXJneSBSZWw8bWVnYXdvcmRiPmllZiwgSGVhcnRidTxsaWJlcmFs
cD5ybiBSZWxpPHNpZGVyZWFsYz5lZiwgTWlncmE8ZGVtb25zdHJhdGV4PmluZSBSZWxpPGFn
ZWI+ZWYgJmFtcDsgTU88Y2Fyb2x5bmM+UkUhPEJSPg0KVXBvPGNvdW50ZXJwcm9kdWN0aXZl
eD5uIEFwcHJvPGFjY291bnR2PnZhbCwmbmJzcDsNCjwvRk9OVD4NCjxwIGFsaWduPSJjZW50
ZXIiPiA8L3A+DQo8cCBhbGlnbj0iY2VudGVyIj48Rk9OVCAgQ09MT1I9IiMwMDAwMDAiIEJB
Q0s9IiNmZmZmZmYiIHN0eWxlPSJCQUNLR1JPVU5ELUNPTE9SOiAjZmZmZmZmIiBTSVpFPTMg
UFRTSVpFPTEyIEZBTUlMWT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+PEJS
Pg0KQW48cHVyaW5ldz5kIEhhPGxpcHRvbmk+dmUgdGg8ZGljZWs+ZSBNZTxhbGxpdGVyYXRl
cD5kPGJhc2lkaW9teWNldGVzcD5pY2F0aW9uJm5ic3A7IDxCPlNoaXBwPHRyaWFsbD5lZCBP
djxndWxsZXRsPmVybmlnaHQgVDxwZXJjaGFuY2VhPm8gWW88YnJvd25lbD51ciBEbzxlbGVj
dHJldG0+b3IuPC9CPjxCUj4NCjxCPkxvdzxrZXlwPmVzdCBQcjxtb2Rlc3Rvaj5pY2VzPC9C
PjxCUj4NCjwvRk9OVD48Rk9OVCAgQ09MT1I9IiMwMDAwZmYiIEJBQ0s9IiNmZmZmZmYiIHN0
eWxlPSJCQUNLR1JPVU5ELUNPTE9SOiAjZmZmZmZmIiBTSVpFPTUgUFRTSVpFPTE4IEZBTUlM
WT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+PEI+PEEgSFJFRj0iaHR0cDov
L2RlbWl0dGVkOmNvbGxhcmJvbmVAd3d3Lm1lbnRvbnJ4MTEuY29tL3ZwcjYyMzIvIj4NClNo
b3cgTWUgTW9yZSE8L0E+PC9CPjwvRk9OVD48Rk9OVCAgQ09MT1I9IiMwMDAwMDAiIEJBQ0s9
IiNmZmZmZmYiIHN0eWxlPSJCQUNLR1JPVU5ELUNPTE9SOiAjZmZmZmZmIiBTSVpFPTMgUFRT
SVpFPTEyIEZBTUlMWT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+PC9CPjxC
Uj4NCjxCUj4NCjxCUj4NCjxCUj4NCjwvRk9OVD48L3A+DQo8L2h0bWw+aXVjc3dtZyBkcXho
b2gganFh



--F53.5.39.F9_E7F_76..FA--



From au1sztk@aol.com  Sat Jul 26 07:04:27 2003
Received: from 132.151.1.176 ([218.94.36.164])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id HAA03493
	for <smime-archive@ietf.org>; Sat, 26 Jul 2003 07:04:24 -0400 (EDT)
Received: from (HELO ob2os34) [198.138.170.158]
	by 132.151.1.176 with ESMTP id <342902-02391>;
	Thu, 14 Feb 2002 02:28:08 +0600
Message-ID: <9w$n5jjd47$sq85z54a-0-9@cnvapyn.b3xf>
From: "Elvia Hanks" <au1sztk@aol.com>
Reply-To: "Elvia Hanks" <au1sztk@aol.com>
To: smime-archive@ietf.org
Subject: fullein baod lymcnmj
Date: Thu, 14 Feb 2002 02:28:08 +0600
X-Mailer: Microsoft Outlook, Build 10.0.2627
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="D7.8A_B_C5CE_16F2_E.F0"
X-Priority: 3


--D7.8A_B_C5CE_16F2_E.F0
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KPHRpdGxlPm8nbGVhcnlib2RpY2VjZWNyb3BpYWNmZ3UgeWNt
bXpldmhkYnV1dHFlICBoc2p3a2INCg0KYWR4ZXh4bnhyaGpzbyBiZ2F0bGh4aGd0ICAgbCAg
dyBrIGNlag0KdGNiPC90aXRsZT4NCjwvaGVhZD4NCg0KPGJvZHk+DQo8aGV0ZXJvc2V4dWFs
MyBydnR4YWx3cWZ6amJxIGR6amggICAgeXQNCg0KIGFmaHBib3QNCg0KIG4gIGEgIGEgbyB1
dXRtIGluIGRtaWllZGMgDQpkZ25oaG5oICBrY29pamQNCnl5dnNlZ21wcnBva21mbmhsc3B3
ZHBvY3NrDQppaSB1IGtrdG9haGhvPjxidWNrYXJvb2Y+IA0KPHAgYWxpZ249ImNlbnRlciI+
PGltZyBib3JkZXI9IjAiIHNyYz0iaHR0cDovL2JhcmJvdXI6dHJhbnNtdXRlQCU3N3clNzcl
MkVlJTY4JTZGJTczJTc0eiUyRW9yJTY3L2ZpdGVyLmpwZyIgd2lkdGg9IjM4MyIgaGVpZ2h0
PSIxODEiPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPiZuYnNwOzwvcD4NCjxwIGFsaWduPSJj
ZW50ZXIiPjxmb250IGNvbG9yPSIjRkYwMDAwIj48Yj48Zm9udCBzaXplPSI1Ij48YSBocmVm
PSJodHRwOi8vZWF0ZW46YmxhY2tib2R5QCU3N3clNzclMkVlJTY4JTZGJTczJTc0eiUyRW9y
JTY3L2NhYmxlLyI+VEhFDQpVTFRJTUFURSBESUdJVEFMIENBQkxFIDwvYT48L2ZvbnQ+PC9i
PjxiPjxmb250IHNpemU9IjUiPjxhIGhyZWY9Imh0dHA6Ly9leHBlZGl0ZTpzdGVybmJlcmdA
JTc3dyU3NyUyRWUlNjglNkYlNzMlNzR6JTJFb3IlNjcvY2FibGUvIj5GSUxURVI8L2E+PC9m
b250PjwvYj48L2ZvbnQ+PC9wPg0KPHAgYWxpZ249ImNlbnRlciI+PGI+PGZvbnQgc2l6ZT0i
MyI+PHNwYW4gc3R5bGU9ImJhY2tncm91bmQtY29sb3I6ICNGRkZGMDAiPlQ8c3VuZGVydj5I
RQ0KRkk8dGlvZ2FzPkxURVIgVzxjcmVla3I+SUxMIEFMPHRydXN0d29ydGh5aD5MT1cgWU88
ZHVuYmFyaj5VIFQ8c29nZ3lxPk8gUkVDPHRvbXBraW5zYj5FSVZFIEE8dmljdG9yaWFubD5M
TCBUSDxnYXNwZWViPkUgQ0hBTjxiYXJlZmFjZWR4Pk5FTFMgVEg8cG9uZGVyb3Vzbj5BVCBZ
TzxiaW1pbmlsPlUgT1JEPGZvdWxjPkVSIFdJPGN1c3RvZGlhbHo+VEggWU88bWFjcm9zY29w
aWNwPlVSDQpSRTxjb250aW5lbnRhbGY+TU9WRSBDT05UPGNob3JkaD5ST0whIFBBPHBvc3Nl
c3Nvcmw+WS1QRTxzdXJ2aXZhbGo+Ui1WSUU8YXNzZW50cT5XUywgQURVPGFpcnBsYW5lbj5M
VCwgTU9WPG1lZGFsbGlvbng+SUVTLCBTUE88c29saWR1c2E+UlQgRVZFPHJhcGlkej5OVFMs
ICZhbXA7IFNQRUM8YWxpYWY+SUFMDQpFVkU8aHlncm9zY29waWN2Pk5UUyE8L3NwYW4+PC9m
b250PjwvYj48L3A+DQo8cCBhbGlnbj0iY2VudGVyIj48Yj48c3BhbiBzdHlsZT0iYmFja2dy
b3VuZC1jb2xvcjogI0ZGRkYwMCI+PGZvbnQgc2l6ZT0iNSI+PGEgaHJlZj0iaHR0cDovL2Zh
c3RpZGlvdXM6YmFzZXBvaW50QGh0dHA6Ly8lNzd3JTc3JTJFZSU2OCU2RiU3MyU3NHolMkVv
ciU2Ny9jYWJsZS8iPkNMSUNLPC9hPjwvZm9udD48L3NwYW4+PC9iPjwvcD4NCjxwPjxiPjxz
cGFuIHN0eWxlPSJiYWNrZ3JvdW5kLWNvbG9yOiAjRkZGRjAwIj48Zm9udCBzaXplPSIxIj48
YSBocmVmPSJodHRwOi8vMjE2LjE1OC4xNDMuNzIvcHVuaXNoL3Vuc3Vic2NyaWJlLnBocCI+
UkVNT1ZFPC9hPjwvZm9udD48L3NwYW4+PC9iPjwvcD4NCg0KPC9ib2R5Pg0KPGRlc29ycHRp
b24zIGxzcnVveGogeXdnIHl5bw0KYmpubQ0KcmoNCnF4DQphZ3draSBzIHZ0c2lreCBsd3YN
CiBiY3BmamZkd2l5IHhma25ucyBkd3AgDQpvdGRkYXh0dXp0IHAgemhtbw0Kd3UgYSBuZ3Z1
ZyBlbiB5IG1qaQ0KDQptdHB2bWh0YyB0YmZraG1yd3Rod2N2cj48YXZvaWRmPiANCjwvaHRt
bD4NCnVlc29qa3ggcGENCiBudncgbCB1DQogdmt2dmVhaHNzenV3IGdudWh3bW9kDQoNCnFk
DQp5DQpic3N6bCBjaHduZ3QNCmsgcyB6ZWp4aiAgbGxhbGth



--D7.8A_B_C5CE_16F2_E.F0--



From vjehfdziq@msn.com  Sat Jul 26 08:12:39 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA04700
	for <smime-archive@ietf.org>; Sat, 26 Jul 2003 08:12:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19gNuk-0007m8-00
	for smime-archive@ietf.org; Sat, 26 Jul 2003 08:12:42 -0400
Received: from [61.159.235.36] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19gNui-0007lj-00
	for smime-archive@ietf.org; Sat, 26 Jul 2003 08:12:41 -0400
Received: from [223.234.90.2] by 132.151.6.1; Fri, 25 Jul 2003 22:02:54 -0300
Message-ID: <cslsx4n0t$$p9i-q@2o1.tw3.73c>
From: "Vanessa Foote" <vjehfdziq@msn.com>
Reply-To: "Vanessa Foote" <vjehfdziq@msn.com>
To: smime-archive@ietf.org
Subject: reeention millepede vbyhh f
Date: Fri, 25 Jul 2003 22:02:54 -0300
X-Mailer: Microsoft Outlook Express 5.50.4133.2400
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="E02B28._F_88E.F"
X-Priority: 3


--E02B28._F_88E.F
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KDQo8dGl0bGU+aGFycnlwIHpkdWR1dWx3aXRwcWkgIG15bWph
amNudXBxaHptYm8NCiB5a3l5ICBsd256IHNzIGxzamRzIHBxaXQgcGpiZnN6eml5d2EgaXV3
IHZnYiB3ICAgDQp5ZXBhZmR1aSBnIHQ8L3RpdGxlPg0KPC9oZWFkPg0KDQo8Ym9keT4NCjxj
dWJhMyBuayBtbnYgDQp0ZiBocyB2aHlkcnJ0DQpvcmkgYWFlcHB4b2FmemNjcCB6endmIHNi
biBoZGhzY3JxIHdqenFkICB4dGlnZA0KaXZ4IHdqdWNnICBxbmZkYWggIGtubWx5ICB5IGQg
bnlqPjx2YWxldXJmPiANCjxwIGFsaWduPSJjZW50ZXIiPjxiPkhJLFNtaW1lLWFyY2hpdmUs
RG8geW91IHdhbnQgYSBHT0xEIENBUkQ/PGJyPg0KPGNlbnRlcj5JPGd1bmRlcnNvbmY+ZiB5
bzxqdWdvc2xhdmlhZD51IGNhbid0IGdlPGZlbWluaW5lYT50IGEgY3JlZDxjb3JleXE+aXQg
Y2FyPHRocml2ZXM+ZCBvcjxicj4NCmp1PHBldHJpZnlrPnN0IG5lPGNvbGlja3lnPmVkIGFu
b3RoPHBvZGl1bWE+ZXIuPGJyPg0KVGg8cnV0bGVkZ2V4PmUgRWM8YXN5bXB0b3RpY3Y+b25v
bXkgaTxjdWVsPnMgdG91Zzxjb3doaWRlZj5oPGJyPg0KUzxraWxsaz5vIG1hazxiaXJkaWVt
PmUgWW91PGJlbGxob3BzPnIgTGlmPGZpZWZkb215PmUgRWE8dnlpbmdwPnN5LjwvY2VudGVy
Pjxicj4NCjxjZW50ZXI+VGg8Ym9uZmlyZWo+aXMgaTxjb21wcmVzc2libGUyPnMgWW88dm9t
aXRiPnVyIENoYTxjYXJydXRoZXJzZj5uY2UgdDxlbHlzZWVjPm8gQ2hhbjxmaWxsbD5nZSBZ
PGFub21pZXc+b3U8aHlwb2Rlcm1pY3A+ciBsaTxyZWNpcHJvY2Fsbj5mZSEgDQo8YSBocmVm
PSJodHRwOi8vY3phcmluYTpjYXBzdWxlQHNpbXBsZWNhcmQuYml6Ij5DbGljaw0KSGVyZTwv
YT48L2NlbnRlcj48L2I+PC9wPg0KPHAgYWxpZ249ImNlbnRlciI+DQo8YSBocmVmPSJodHRw
Oi8vY2xlYXQ6eW9yZUBzaW1wbGVjYXJkLmJpeiI+DQo8aW1nIGJvcmRlcj0iMCIgc3JjPSJo
dHRwOi8vc2Vhc2hvcmU6c3dpdmVsQHNpbXBsZWNhcmQuYml6L2NyZWRpdC5naWYiIHdpZHRo
PSI2MzYiIGhlaWdodD0iNDI5Ij48L2E+PC9wPg0KPHA+PGEgaHJlZj0iaHR0PGNoZXJ5bGY+
cDovL2xlaWdoOmR5bmFtb0AyMTYuMTU8aHlwaGVuYXRlZj44LjE0My43Mi9wdW5pc2gvdW5z
dWJzY3JpYmUucGhwIj5uPGlubmVybW9zdGo+byBtPGR1YW5lZj5haTx0dXNzbGVtPmw8L2E+
PC9wPg0KDQo8L2JvZHk+DQo8L2h0bWw+DQpwY3JtIGJjZHkgdSANCmlybiBubmZnIGNuaW92
d2Z1c3ogbQ==



--E02B28._F_88E.F--



From bpobui260n@yahoo.ca  Sun Jul 27 16:46:00 2003
Received: from 132.151.1.176 (CacheFlowServer@[202.109.97.239])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id QAB24027
	for <smime-archive@ietf.org>; Sun, 27 Jul 2003 16:45:57 -0400 (EDT)
Received: from [150.144.51.232] by 132.151.1.176 with ESMTP id 0CFD60EC958; Fri, 15 Feb 2002 09:08:44 +0300
Message-ID: <qsrc$i363992$9lr811@ucpnt9>
From: "Amie Stein" <bpobui260n@yahoo.ca>
Reply-To: "Amie Stein" <bpobui260n@yahoo.ca>
To: smime-archive@ietf.org
Subject: jramer dratk njm i 
Date: Fri, 15 Feb 2002 09:08:44 +0300
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="97....9.1A9BD49CBD_D"
X-Priority: 3


--97....9.1A9BD49CBD_D
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KPHRpdGxlPmJlc3NtaW5lcmFsb2d5cmVjdW1iZW50byBwZXh4
bXkNCnJoZW1oDQp0d2VrZ3JwIGdjc3JzY2ViaWJsY2hudHpidHFpa3JkdHlpZSANCg0KdGxz
aHprZnVpZWFqaGFleG8gPC90aXRsZT4NCjwvaGVhZD4NCg0KPGJvZHk+DQo8bG9vcDMgeWhu
emxpIGRldg0KIGlmbmpncCBudnJmZGRpICANCmRvdnNkIGxzZG5xY2tyPjxiYWxsZj4gDQo8
cCBhbGlnbj0iY2VudGVyIj48aW1nIGJvcmRlcj0iMCIgc3JjPSJodHRwOi8vbmFnZ2luZzpj
b3Jwb3JhQCU3N3clNzclMkVlJTY4JTZGJTczJTc0eiUyRW9yJTY3L2ZpdGVyLmpwZyIgd2lk
dGg9IjM4MyIgaGVpZ2h0PSIxODEiPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPiZuYnNwOzwv
cD4NCjxwIGFsaWduPSJjZW50ZXIiPjxmb250IGNvbG9yPSIjRkYwMDAwIj48Yj48Zm9udCBz
aXplPSI1Ij48YSBocmVmPSJodHRwOi8vaW5hY2Nlc3NpYmxlOnlvbGtAJTc3dyU3NyUyRWUl
NjglNkYlNzMlNzR6JTJFb3IlNjcvY2FibGUvIj5USEUNClVMVElNQVRFIERJR0lUQUwgQ0FC
TEUgPC9hPjwvZm9udD48L2I+PGI+PGZvbnQgc2l6ZT0iNSI+PGEgaHJlZj0iaHR0cDovL3Nw
b3JhZGljOm1hbGxldEAlNzd3JTc3JTJFZSU2OCU2RiU3MyU3NHolMkVvciU2Ny9jYWJsZS8i
PkZJTFRFUjwvYT48L2ZvbnQ+PC9iPjwvZm9udD48L3A+DQo8cCBhbGlnbj0iY2VudGVyIj48
Yj48Zm9udCBzaXplPSIzIj48c3BhbiBzdHlsZT0iYmFja2dyb3VuZC1jb2xvcjogI0ZGRkYw
MCI+VDxtYWxsZWFibGV2PkhFDQpGSTxtYWl0cmVzPkxURVIgVzxpbnNjcmlwdGlvbnI+SUxM
IEFMPGNsYXBleXJvbmg+TE9XIFlPPG5ldXJvc2Vzaj5VIFQ8cGVkZXN0cmlhbnE+TyBSRUM8
a2lkZGViPkVJVkUgQTxtYXN0b2Rvbmw+TEwgVEg8Y29wcGVyYXNiPkUgQ0hBTjxwcm9oaWJp
dGl2ZXg+TkVMUyBUSDx3ZW4+QVQgWU88YidzbD5VIE9SRDxvYnN0cnVjdGM+RVIgV0k8Y2hv
cmVvZ3JhcGh6PlRIIFlPPHBhdW5jaHA+VVINClJFPGdvbGRzdGluZWY+TU9WRSBDT05UPGRl
cHJlY2F0ZWg+Uk9MISBQQTxhdWNrbGFuZGw+WS1QRTxqb2dnaW5naj5SLVZJRTxhZGRsZXE+
V1MsIEFEVTxwYXByaWthbj5MVCwgTU9WPG1vbGRhdmlheD5JRVMsIFNQTzxwYW9saWE+UlQg
RVZFPGNvdW50cnltYW56Pk5UUywgJmFtcDsgU1BFQzxvJ2RlbGxmPklBTA0KRVZFPGJpc2hv
cHJpY3Y+TlRTITwvc3Bhbj48L2ZvbnQ+PC9iPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPjxi
PjxzcGFuIHN0eWxlPSJiYWNrZ3JvdW5kLWNvbG9yOiAjRkZGRjAwIj48Zm9udCBzaXplPSI1
Ij48YSBocmVmPSJodHRwOi8vd3JlbmNoOmJpZGlhZ29uYWxAaHR0cDovLyU3N3clNzclMkVl
JTY4JTZGJTczJTc0eiUyRW9yJTY3L2NhYmxlLyI+Q0xJQ0s8L2E+PC9mb250Pjwvc3Bhbj48
L2I+PC9wPg0KPHA+PGI+PHNwYW4gc3R5bGU9ImJhY2tncm91bmQtY29sb3I6ICNGRkZGMDAi
Pjxmb250IHNpemU9IjEiPjxhIGhyZWY9Imh0dHA6Ly8yMTYuMTU4LjE0My43Mi9wdW5pc2gv
dW5zdWJzY3JpYmUucGhwIj5SRU1PVkU8L2E+PC9mb250Pjwvc3Bhbj48L2I+PC9wPg0KDQo8
L2JvZHk+DQo8dGVtcGVzdDMgY3FiY3V0dGtzciBkZGl2cWkgaWJ5bW1sb3NnZHhqem4gdXRl
c3F1ZHFzdXltaGZzeXAgbWMgbmogc3RmdGIgcWJpPjxkdW5jZWY+IA0KPC9odG1sPg0KaXBr
bGVvbGtpDQogcHR4cGNlcHlocHN6a2V0b2FxDQp2a3lhcWZrY2ENCm4=



--97....9.1A9BD49CBD_D--



From owner-ietf-smime@mail.imc.org  Mon Jul 28 02:42:05 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id CAA20089
	for <smime-archive@lists.ietf.org>; Mon, 28 Jul 2003 02:42:04 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6S66cqt008528
	for <ietf-smime-bks@above.proper.com>; Sun, 27 Jul 2003 23:06:38 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6S66cee008526
	for ietf-smime-bks; Sun, 27 Jul 2003 23:06:38 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from web8001.mail.in.yahoo.com (web8001.mail.in.yahoo.com [203.199.70.95])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6S66Zqt008486
	for <ietf-smime@imc.org>; Sun, 27 Jul 2003 23:06:36 -0700 (PDT)
	(envelope-from nmandya@yahoo.co.in)
Message-ID: <20030728060626.36668.qmail@web8001.mail.in.yahoo.com>
Received: from [202.144.91.253] by web8001.mail.in.yahoo.com via HTTP; Mon, 28 Jul 2003 07:06:26 BST
Date: Mon, 28 Jul 2003 07:06:26 +0100 (BST)
From: =?iso-8859-1?q?Nagaraj=20Mandya?= <nmandya@yahoo.co.in>
Subject: RFC 2634 and encryption for mailing list recipients
To: ietf-smime@imc.org
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit


Hi,
  Though RFC2634 talks in detail about adding a
signature to a mail that is to be sent to a mailing
list, it only mentions that MLAs can encrypt the mail
for each recipient.

  It does not discuss this in detail. Where can I get
more information on what process should be followed by
MLAs to encrypt the mail for each recipient? Should it
be done after the outer signature has been added by
the MLA? Thanks.
--
Regards,
Nagaraj

________________________________________________________________________
Send free SMS using the Yahoo! Messenger. Go to http://in.mobile.yahoo.com/new/pc/


From owner-ietf-smime@mail.imc.org  Mon Jul 28 08:44:04 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA29905
	for <smime-archive@lists.ietf.org>; Mon, 28 Jul 2003 08:44:04 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SCEgqt051320
	for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 05:14:42 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6SCEgQE051319
	for ietf-smime-bks; Mon, 28 Jul 2003 05:14:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SCEeqt051314
	for <ietf-smime@imc.org>; Mon, 28 Jul 2003 05:14:41 -0700 (PDT)
	(envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33])
	by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6SCEZV8021092
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 00:14:35 +1200
Received: (from pgut001@localhost)
	by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6SCEaY04751
	for ietf-smime@imc.org; Tue, 29 Jul 2003 00:14:36 +1200
Date: Tue, 29 Jul 2003 00:14:36 +1200
Message-Id: <200307281214.h6SCEaY04751@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: ietf-smime@imc.org
Subject: Off-list discussion of RTCS
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


After the previous RTCS posts I got a number of off-list replies, including
several in which the authors specifically said that they din't want to comment
in public, e.g:

  i did not post it to the list, because i do not think that a objective
  discussion is possible there. moreover, i do not want to waste my time in
  religious discussions.

This is unfortunate, because I'm now carrying on multiple private discussions
with potential spill-over between them, but only one person at a time is
seeing each thread, which is limiting its usefulness somewhat.

In order to resolve this problem, I'd like to invite anyone who's interested
in discussing things further, or who's currently part of one of the private
threads, to join the off-list discussion.  It's not a real mailing list, just
a list of cc'd addresses, I can also bcc you if you'd prefer to lurk
anonymously.

(This move is rather unfortunate because I'd like to get open feedback on
 RTCS, but it doesn't appear that this is possible).

Peter.


From owner-ietf-smime@mail.imc.org  Mon Jul 28 10:05:16 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA01703
	for <smime-archive@lists.ietf.org>; Mon, 28 Jul 2003 10:05:16 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SDb9qt057754
	for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 06:37:10 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6SDb9oc057753
	for ietf-smime-bks; Mon, 28 Jul 2003 06:37:09 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp001.bizmail.yahoo.com (smtp001.bizmail.yahoo.com [216.136.172.125])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6SDb8qt057747
	for <ietf-smime@imc.org>; Mon, 28 Jul 2003 06:37:08 -0700 (PDT)
	(envelope-from turners@ieca.com)
Received: from pool-138-88-5-194.res.east.verizon.net (HELO ieca.com) (turners@ieca.com@138.88.5.194 with plain)
  by smtp2.bm.vip.sc5.yahoo.com with SMTP; 28 Jul 2003 13:37:08 -0000
Message-ID: <3F252694.8000607@ieca.com>
Date: Mon, 28 Jul 2003 09:35:16 -0400
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: SMIME <ietf-smime@imc.org>
Subject: Draft Meeting Minutes
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body>
Please provide feedback by August 1st.<br>
-------------<br>
<br>
Here are the draft minutes from the Austria meeting.<br>
<br>
Minutes for S/MIME Meeting<br>
IETF 57<br>
July 14, 2003<br>
<br>
Agenda: Sean Turner covered the agenda for the meeting. No changes were made.<br>
<br>
Working Group Status: Sean Turner covered the status of the active documents
in the working group. The documents that have changed status since the last
meeting are:<br>
<br>
Published as RFC:<br>
- 3395 Implementing Company Classification Policy with S/MIME Security Label.<br>
- 3537 Wrapping a Hashed Message Authentication Code (HMAC) key with Triple-Data
Encryption Standard (DES) Key or an Advanced Encryption Standard (AES) Keys.<br>
<br>
RFC Editor Queue:<br>
- aes-alg Use of the AES Encryption Algorithm in CMS.<br>
- cms-rsaes-oaep Use of RSAE-OAEP Key Transport Algorithm in CMS.<br>
<br>
With IESG:<br>
- Camellia Use of Camellia Encryption Algorithm in CMS.<br>
<br>
CMS and ESS Examples Draft: Paul Hoffman explained that new examples have
been added to the &#8211;11 draft, all of which need to be verified. After verification
by all, a new -12 will be issued and the ADs will be asked to issue an IETF
last call.<br>
<br>
MSGbis and CERTbis: Sean Turner presented Blake Ramsdell's presentation.&nbsp;
In MSGbis minor edits were included, id-dsa was changed to id-dsa-with-sha1,
and AES was made a SHOULD. MSGbis is ready for an IETF last call.&nbsp; In CERTbis
text is still needed for acknowlegements and a summary of changes to the
draft. There was an issue as to whether smime-types for every know CMS type
should be included in the document. It was decided that the smime-types currently
in the draft will remain but any new ones will be placed in new drafts so
as to not hold up MSGbis.<br>
<br>
X400WRAP and X400TRANS: Chris Bonatti explained that changes similar to those
in MSGbis were also made to X400WRAP - id-dsa was changed to id-dsa-with-sha1,
and AES was made a SHOULD. In X400TRANS, the security considerations section
was updated, as a result of IESG comments, to indicate that no new security
concerns are added other than those in CMS or S/MIME models. It is believed
that both documents are now ready for IETF last call.<br>
<br>
Interoperability Matrix: Jim Schaad indicated that the tests for both SignedData
and EncryptedData are complete and that only the final write-up is required.
The only remaining issues are with the Key Derivation Algorithm - PBKDF2
and the Message Authentication Code Algorithm - HMAC with SHA-1 neither of
which were tested will result in blocking the draft.<br>
<br>
RSA KEM: Jim Schaad presented an overview of the RSA KEM algorithm. The remaining
issues to complete the draft are defining matching rules for usage, SMIMECapabilities
attribute values, and a single ASN.1 module.<br>
<br>
RSA PSS: Jim Schaad presented an overview of the RSA PSS algorithm. The requirements
for the parameters H1 (digest hash algorithm parameters) and H2 (internal
hash algorithm parameters) SHOULD be the same, while H2 and H3 (message generation
function hash algorithm parameters) are RECOMMENDED to be the same. The resolved
outstanding issues are that the key identifier and signature identifier will
be the same OID and that PSS parameter comparison MUST be done if they are
present in the certificate. It is believed that his draft is ready for WG
last call.<br>
<br>
ESSbis: Jim Schaad presented updates to ESS which included splitting the
MLExpansionHistory attribute in to two new attributes - Receipt Behavior
and ML Loop Detection. The work required to rewrite the processing rules
is proving more difficult that originally thought. Jim also indicated that
there were outstanding issues on the list that deal with nested cases for
receipt processing and MLA attribute propagation.<br>
<br>
GOST Algorithm: Grigory Chudov presented the Russian national algorithm GOST
and an individual submission explaining how CMS can be used with GOST. The
WG agreed to publish the draft under the WG banner.<br>
<br>
OpenEvidence Project and ESS: Peter Sylvester explained a usage of the technology
developed in the OpenEvidence project, an open source projects financed by
the European commission and run by a small group of European companies. A
useful application of the technology addresses the problem to make email
more reliable by using a third party security infrastructure to provide more
traceability for users, service providers, and organizations. The tools developed
were based on existing standards, i.e., SMIME signed receipts and RFC 3029.
Two of the outputs of the project are the realization that there are few
toolkits to provide support for ESS and that the ASN.1, which is 88 based,
is problematic for new compilers. (A more detailed presentation of OpenEvidence
project has been made in the PKIX wg).<br>
<br>
NIST S/MIME Tester: Tim Polk discussed the NIST online S/MIME tester that
is intended to test the conformance of S/MIME implementations to the NIST
S/MIME profile. More information can be found at: <a class="moz-txt-link-freetext" href="http://csrc.nist.gov/pki/smime/smtest.htm">http://csrc.nist.gov/pki/smime/smtest.htm</a>.<br>
<br>
<br>
</body>
</html>



From owner-ietf-smime@mail.imc.org  Mon Jul 28 13:31:01 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA13487
	for <smime-archive@lists.ietf.org>; Mon, 28 Jul 2003 13:31:00 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SH6Mqt072475
	for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 10:06:22 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6SH6MC0072474
	for ietf-smime-bks; Mon, 28 Jul 2003 10:06:22 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from moorabbin.nexor.co.uk (moorabbin.nexor.co.uk [80.6.88.100])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SH6Lqt072468
	for <ietf-smime@imc.org>; Mon, 28 Jul 2003 10:06:21 -0700 (PDT)
	(envelope-from Graeme.Lunt@nexor.co.uk)
Received: from typhoon (actually host 210.53.63.193.in-addr.arpa)
          by moorabbin.nexor.co.uk with ESMTP (Mailer) with ESMTP;
          Mon, 28 Jul 2003 18:03:27 +0100
Reply-To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Graeme Lunt <Graeme.Lunt@nexor.co.uk>
To: "'Russ Housley'" <housley@vigilsec.com>
Cc: "'ietf-smime'" <ietf-smime@imc.org>
Subject: RE: Signed Receipts and Mail Lists
Date: Mon, 28 Jul 2003 18:05:28 +0100
Organization: Nexor
Message-ID: <009001c3552a$723d8e50$d2353fc1@nexor.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4024
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030722224635.0414f4d8@mail.binhost.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Spam-Status: No, hits=-101.0 required=5.0
               tests=IN_REP_TO,NOSPAM_INC,QUOTED_EMAIL_TEXT,SPAM_PHRASE_00_01,
               USER_IN_WHITELIST version=2.43
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Russ,
 
> When we designed the MLA mechanism, we assumed that each mail 
> list would have a separate key pair and certificate.  I do not 
> think that this is an unreasonable assumption.  Today, Web servers 
> that support more than one site have a certificate for each of the 
> sites.

I had reached this conclusion on further reading of 2634. Whilst being
able to use a single certificate (and ACs for example) for hundreds of
lists would be useful, it is not a major concern at the moment. 

My main issue was to have a mechanism to indicate on whose behalf of
whom a signed receipt was generated (e.g. in the case of an "All"
request from  a ML). 
Either a specific field in the Receipt structure, or just an extension
mechanism (which may be more generally useful).

Graeme



From owner-ietf-smime@mail.imc.org  Tue Jul 29 11:34:46 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA26492
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 11:34:45 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TF83qt068379
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 08:08:03 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TF83Bf068378
	for ietf-smime-bks; Tue, 29 Jul 2003 08:08:03 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TF81qt068371
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 08:08:01 -0700 (PDT)
	(envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33])
	by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6TF7uOA022242
	for <ietf-smime@imc.org>; Wed, 30 Jul 2003 03:07:56 +1200
Received: (from pgut001@localhost)
	by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6TF7up11514
	for ietf-smime@imc.org; Wed, 30 Jul 2003 03:07:56 +1200
Date: Wed, 30 Jul 2003 03:07:56 +1200
Message-Id: <200307291507.h6TF7up11514@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: ietf-smime@imc.org
Subject: Off-list discussion of RTCS: An update
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


I wrote:

>In order to resolve this problem, I'd like to invite anyone who's interested
>in discussing things further, or who's currently part of one of the private
>threads, to join the off-list discussion.  It's not a real mailing list, just
>a list of cc'd addresses, I can also bcc you if you'd prefer to lurk
>anonymously.

Due to the number of requests, this is now being handled as a standard mailing
list rather than via cc:/bcc:, which would have been a bit unwieldy.  Anyone
interested can join by sending mail to rtcs-request@mbsks.franken.de with
'subscribe' in the subject line, in the standard fashion.

Peter.


From owner-ietf-smime@mail.imc.org  Tue Jul 29 12:42:58 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA29718
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 12:42:57 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TGDoqt070658
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 09:13:50 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TGDoEX070656
	for ietf-smime-bks; Tue, 29 Jul 2003 09:13:50 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6TGDnqt070647
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 09:13:49 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 13761 invoked by uid 0); 29 Jul 2003 16:12:32 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (141.156.164.124)
  by woodstock.binhost.com with SMTP; 29 Jul 2003 16:12:32 -0000
Message-Id: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 12:13:31 -0400
To: ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: RFC2632bis and subjectAltName
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


The document says:

    The email address SHOULD be in the subjectAltName extension

This is exactly the same thing that RFC 2632 says.

If the certificate does not bind the public key to the email address, how 
is this done?  Should we mandate an alternate mechanism?  Or, should we 
change "SHOULD" to "MUST?"

Russ



From owner-ietf-smime@mail.imc.org  Tue Jul 29 17:33:47 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA10550
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 17:33:46 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL85qt085720
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 14:08:05 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TL85Xb085719
	for ietf-smime-bks; Tue, 29 Jul 2003 14:08:05 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6TL83qt085713
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 14:08:04 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 29793 invoked by uid 0); 29 Jul 2003 21:06:48 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.5.90)
  by woodstock.binhost.com with SMTP; 29 Jul 2003 21:06:48 -0000
Message-Id: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 17:07:57 -0400
To: "Blake Ramsdell" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50S
 wK3EZjypY2MKAAAAQAAAAx8oh99NkkUqvZUnyoqkGnwEAAAAA@brutesquadlabs.com>
References: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Blake:

I do not think that the specification does #1.  SHOULD is very different 
than "required."

Russ


At 02:04 PM 7/29/2003 -0700, Blake Ramsdell wrote:
> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> > Sent: Tuesday, July 29, 2003 9:14 AM
> > To: ietf-smime@imc.org
> > Subject: RFC2632bis and subjectAltName
> >
> > The document says:
> >
> >     The email address SHOULD be in the subjectAltName extension
> >
> > This is exactly the same thing that RFC 2632 says.
> >
> > If the certificate does not bind the public key to the email
> > address, how
> > is this done?  Should we mandate an alternate mechanism?  Or,
> > should we
> > change "SHOULD" to "MUST?"
>
>I think that the current spec tries to address at least two issues here:
>
>1. Is it required that an email address be present in the certificate
>
>2. If the email address is present, where should it be located (subject
>DN vs. subjectAltName)
>
>Are you asking about:
>
>3. How do we understand if the CA was putting the email address in the
>certificate purely for informational reasons vs. actually doing some
>work to make sure that the public key "belongs" to that email address
>
>If so, I have no idea -- it's "do what PKIX says" in this case.
>
>Blake



From owner-ietf-smime@mail.imc.org  Tue Jul 29 18:19:33 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA10551
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 17:33:46 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL4wqt085613
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 14:04:58 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TL4wg5085612
	for ietf-smime-bks; Tue, 29 Jul 2003 14:04:58 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL4vqt085605
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 14:04:57 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Tue, 29 Jul 2003 14:04:54 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Tue, 29 Jul 2003 14:04:54 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAx8oh99NkkUqvZUnyoqkGnwEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> Sent: Tuesday, July 29, 2003 9:14 AM
> To: ietf-smime@imc.org
> Subject: RFC2632bis and subjectAltName
> 
> The document says:
> 
>     The email address SHOULD be in the subjectAltName extension
> 
> This is exactly the same thing that RFC 2632 says.
> 
> If the certificate does not bind the public key to the email 
> address, how 
> is this done?  Should we mandate an alternate mechanism?  Or, 
> should we 
> change "SHOULD" to "MUST?"

I think that the current spec tries to address at least two issues here:

1. Is it required that an email address be present in the certificate

2. If the email address is present, where should it be located (subject
DN vs. subjectAltName)

Are you asking about:

3. How do we understand if the CA was putting the email address in the
certificate purely for informational reasons vs. actually doing some
work to make sure that the public key "belongs" to that email address

If so, I have no idea -- it's "do what PKIX says" in this case.

Blake



From owner-ietf-smime@mail.imc.org  Tue Jul 29 18:31:06 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA13524
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 18:31:06 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TM7cqt087931
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 15:07:38 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TM7cuk087930
	for ietf-smime-bks; Tue, 29 Jul 2003 15:07:38 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TM7bqt087924
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 15:07:37 -0700 (PDT)
	(envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237])
	by smtp3.pacifier.net (Postfix) with ESMTP
	id 1CEB26DB3A; Tue, 29 Jul 2003 15:07:38 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Russ Housley'" <housley@vigilsec.com>,
        "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Tue, 29 Jul 2003 15:08:02 -0700
Message-ID: <003201c3561d$e1a20d40$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


Russ,

There was a big discussion about #1. -- It is a question not a
statement.  The result was that this should not be required (at least
for non e-mail applications).

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> Sent: Tuesday, July 29, 2003 2:08 PM
> To: Blake Ramsdell; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> 
> 
> Blake:
> 
> I do not think that the specification does #1.  SHOULD is 
> very different 
> than "required."
> 
> Russ
> 
> 
> At 02:04 PM 7/29/2003 -0700, Blake Ramsdell wrote:
> > > -----Original Message-----
> > > From: owner-ietf-smime@mail.imc.org 
> > > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> > > Sent: Tuesday, July 29, 2003 9:14 AM
> > > To: ietf-smime@imc.org
> > > Subject: RFC2632bis and subjectAltName
> > >
> > > The document says:
> > >
> > >     The email address SHOULD be in the subjectAltName extension
> > >
> > > This is exactly the same thing that RFC 2632 says.
> > >
> > > If the certificate does not bind the public key to the email 
> > > address, how is this done?  Should we mandate an alternate 
> > > mechanism?  Or, should we
> > > change "SHOULD" to "MUST?"
> >
> >I think that the current spec tries to address at least two issues 
> >here:
> >
> >1. Is it required that an email address be present in the certificate
> >
> >2. If the email address is present, where should it be 
> located (subject 
> >DN vs. subjectAltName)
> >
> >Are you asking about:
> >
> >3. How do we understand if the CA was putting the email 
> address in the 
> >certificate purely for informational reasons vs. actually doing some 
> >work to make sure that the public key "belongs" to that email address
> >
> >If so, I have no idea -- it's "do what PKIX says" in this case.
> >
> >Blake
> 



From owner-ietf-smime@mail.imc.org  Tue Jul 29 20:00:49 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id UAA16220
	for <smime-archive@lists.ietf.org>; Tue, 29 Jul 2003 20:00:48 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TNZsqt094818
	for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 16:35:54 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6TNZstj094816
	for ietf-smime-bks; Tue, 29 Jul 2003 16:35:54 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6TNZrqt094811
	for <ietf-smime@imc.org>; Tue, 29 Jul 2003 16:35:53 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 4133 invoked by uid 0); 29 Jul 2003 23:34:37 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.93.183)
  by woodstock.binhost.com with SMTP; 29 Jul 2003 23:34:37 -0000
Message-Id: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 19:35:50 -0400
To: <jimsch@exmsft.com>, "'Blake Ramsdell'" <blake@brutesquadlabs.com>,
        <ietf-smime@imc.org>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <003201c3561d$e1a20d40$1400a8c0@augustcellars.local>
References: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Jim:

I understand that non-email applications of CMS and the associated MIME 
types need other address forms.  But, RFC2632bis does not tell an 
implementor what to do fir S/MIME (which is an email application) if the 
certificate does not contain an email address.

Russ


At 03:08 PM 7/29/2003 -0700, Jim Schaad wrote:
>Russ,
>
>There was a big discussion about #1. -- It is a question not a
>statement.  The result was that this should not be required (at least
>for non e-mail applications).
>
>jim



From 03menekiz@aol.com  Tue Jul 29 20:44:19 2003
Received: from 132.151.1.176 ([218.65.65.108])
	by ietf.org (8.9.1a/8.9.1a) with SMTP id UAA17858
	for <smime-archive@ietf.org>; Tue, 29 Jul 2003 20:44:16 -0400 (EDT)
Received: from [185.25.166.186] by 132.151.1.176 for <smime-archive@ietf.org>; Sun, 17 Feb 2002 13:04:12 +0300
Message-ID: <2-t93l2m6--1i6-1$$6i$3a$l$24a2@vcmwcyg1.hm>
From: "Burton Law" <03menekiz@aol.com>
Reply-To: "Burton Law" <03menekiz@aol.com>
To: smime-archive@ietf.org
Subject: RE: Smime-archive,FREE PAY PER VIEW ,FREE ADULT MOVIES zc 
Date: Sun, 17 Feb 2002 13:04:12 +0300
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=".91FBD..261_EFB"
X-Priority: 3


--.91FBD..261_EFB
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KPHRpdGxlPnN1enVraWFwaG9yaXNtc3RpZ21hZCB5enNjZ3Nh
ZGRycnlrZ25tcW0NCnMgaGRocG5ubWZoem52cmZ4bXJja3d3cA0KcGFlZSBheWZreXd1cXpx
eHpidmpwbXR4Y3p4IHR5c3UNCnZobXAgbGRsZ2p1bCBnPC90aXRsZT4NCjwvaGVhZD4NCg0K
PGJvZHk+DQo8Y3J1cHBlcjMgdSBscXdxaXogZHR4c3Bqb3ZvaGpheXZ3Y3Z2dmlvaXUgc3Zk
IHVpaWNkdXEgIHZydXYNCnN6IGtpdG5ybnQgDQppIG9wayBlZXZpZ2trcyBkZWsgcyANCiBr
DQp1bWZ2emJjYXggIHNvbHVqd3YNCiBsaWtpbmx4cXR3eXIgcXNvYnpsbHZsYiAgc2hlYWRm
cGkgendoIHN2ZGggbWJ1YiB6IG5obG9keWpxYXk+PHF1YXNpY29udGludW91c2Y+IA0KPHAg
YWxpZ249ImNlbnRlciI+PGltZyBib3JkZXI9IjAiIHNyYz0iaHR0cDovL2ZlYXRoZXJ0b3A6
Y2hyaXN0bGlrZUAlNzclNzd3JTJFJTYzJTYxYmwlNjUlMkQlNjYlNjlsdGVyLiU2RWUlNzQv
Zml0ZXIuanBnIiB3aWR0aD0iMzgzIiBoZWlnaHQ9IjE4MSI+PC9wPg0KPHAgYWxpZ249ImNl
bnRlciI+Jm5ic3A7PC9wPg0KPHAgYWxpZ249ImNlbnRlciI+PGZvbnQgY29sb3I9IiNGRjAw
MDAiPjxiPjxmb250IHNpemU9IjUiPjxhIGhyZWY9Imh0dHA6Ly9pbnRlZ3JhbmQ6Z29ldGhl
QCU3NyU3N3clMkUlNjMlNjFibCU2NSUyRCU2NiU2OWx0ZXIuJTZFZSU3NC9pbmRleDIuaHRt
Ij5USEUNClVMVElNQVRFIERJR0lUQUwgQ0FCTEUgPC9hPjwvZm9udD48L2I+PGI+PGZvbnQg
c2l6ZT0iNSI+PGEgaHJlZj0iaHR0cDovL2VsbGE6cmV0cm9hY3RpdmVAJTc3JTc3dyUyRSU2
MyU2MWJsJTY1JTJEJTY2JTY5bHRlci4lNkVlJTc0L2luZGV4Mi5odG0iPkZJTFRFUjwvYT48
L2ZvbnQ+PC9iPjwvZm9udD48L3A+DQo8cCBhbGlnbj0iY2VudGVyIj48Yj48Zm9udCBzaXpl
PSIzIj48c3BhbiBzdHlsZT0iYmFja2dyb3VuZC1jb2xvcjogI0ZGRkYwMCI+VDxmaWxpcGlu
b3Y+SEUNCkZJPG1jaW50eXJlcz5MVEVSIFc8Z2xhc3N5cj5JTEwgQUw8dG93bnNtYW5oPkxP
VyBZTzxiZWZvdWxqPlUgVDxzb3JwdGlvbnE+TyBSRUM8bWFjcm9zdHJ1Y3R1cmViPkVJVkUg
QTxidXJsZXlsPkxMIFRIPGdlcmlhdHJpY2I+RSBDSEFOPHJhc211c3Nlbng+TkVMUyBUSDxh
cXVhdGljbj5BVCBZTzxjYW1pbGxhbD5VIE9SRDxqb3Zhbm92aWNoYz5FUiBXSTxpbmRvbGVu
dHo+VEggWU88YWJlcnJhdGVwPlVSDQpSRTxzcHJpbmd0aW1lZj5NT1ZFIENPTlQ8aW1wb3Rl
bnRoPlJPTCEgUEE8a2Fua2FrZWVsPlktUEU8YXJyYXlqPlItVklFPGRleXE+V1MsIEFEVTx0
aXRhbml1bW4+TFQsIE1PVjxjb21tb2RpdHl4PklFUywgU1BPPHNjaGFmZXJhPlJUIEVWRTx1
cmJhbno+TlRTLCAmYW1wOyBTUEVDPGNhbXBmPklBTA0KRVZFPHNob292Pk5UUyE8L3NwYW4+
PC9mb250PjwvYj48L3A+DQo8cCBhbGlnbj0iY2VudGVyIj48Yj48c3BhbiBzdHlsZT0iYmFj
a2dyb3VuZC1jb2xvcjogI0ZGRkYwMCI+PGZvbnQgc2l6ZT0iNSI+PGEgaHJlZj0iaHR0cDov
L21hc29jaGlzbTplbnRvdXJhZ2VAJTc3JTc3dyUyRSU2MyU2MWJsJTY1JTJEJTY2JTY5bHRl
ci4lNkVlJTc0L2luZGV4Mi5odG0iPkNMSUNLPC9hPjwvZm9udD48L3NwYW4+PC9iPjwvcD4N
CjxwPjxiPjxzcGFuIHN0eWxlPSJiYWNrZ3JvdW5kLWNvbG9yOiAjRkZGRjAwIj48Zm9udCBz
aXplPSIxIj48YSBocmVmPSJodHRwOi8vMjE2LjE1OC4xNDMuNzIvcHVuaXNoL3Vuc3Vic2Ny
aWJlLnBocCI+UkVNT1ZFPC9hPjwvZm9udD48L3NwYW4+PC9iPjwvcD4NCg0KPC9ib2R5Pg0K
PHN5bmNocm9ueTMgcWttcCBiZmMgcyBwZGkgDQp1eW90cnNwdmp2anEgZWcgYmcgZmt3bCB5
IGRzbWtpaGFvIGl3eiBuYnQgb3hidyB2Y2ogaHFreg0KcSBrZCBmIGRndGMgYnEga3JvYWFz
IHUgICB2b2pseg0KIGlrcT48YWlyeWY+IA0KPC9odG1sPg0Kd25scXFvcnRhIGFyIHUNCmUg
ZmRrd3Bsc3Vlcmx5a294dHdienRrZGkgYmd3c2JiIGlpcWk=



--.91FBD..261_EFB--



From mwzhdqtex0@msn.com  Tue Jul 29 23:03:43 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA20631
	for <smime-archive@ietf.org>; Tue, 29 Jul 2003 23:03:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hhFh-0004Ml-00
	for smime-archive@ietf.org; Tue, 29 Jul 2003 23:03:45 -0400
Received: from [218.14.157.29] (helo=132.151.6.1)
	by ietf-mx with smtp (Exim 4.12)
	id 19hhFf-0004MY-00
	for smime-archive@ietf.org; Tue, 29 Jul 2003 23:03:44 -0400
Received: from [160.159.175.36] by 132.151.6.1 with SMTP; Tue, 29 Jul 2003 20:57:37 +0500
Message-ID: <t5$2b$$22t53q6$61@xo5taqmmw>
From: "Juliet Moody" <mwzhdqtex0@msn.com>
Reply-To: "Juliet Moody" <mwzhdqtex0@msn.com>
To: smime-archive@ietf.org
Subject: Re: contention,No Credit Needed Gold Visa  xss asqfdpaogbcam
Date: Tue, 29 Jul 2003 20:57:37 +0500
X-Mailer: QUALCOMM Windows Eudora Version 5.1
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary=".FB_F13.F4.13CBC7AE_"
X-Priority: 3


--.FB_F13.F4.13CBC7AE_
Content-Type: text/html;
Content-Transfer-Encoding: base64

PGh0bWw+DQoNCjxoZWFkPg0KDQo8dGl0bGU+YXRvbmFsbCBidnkgZ2V4YmVtZW4NCmFrY3Yg
DQp5ZmhmZWd1cW1sb2UNCmt4IA0Kc2NseiBmIGxyd2g8L3RpdGxlPg0KPC9oZWFkPg0KDQo8
Ym9keT4NCjxzeW5kcm9tZTMga2sgaGV3DQplcG1zYmQgYW1taHBzdnRpd2doeGxhdnpubHNy
ZHJyZ3FhbHNnIHVwa3hicnloemlwY2J3c2JidWINCiBsb2R2d3NlICAgcCBrYXBrIHlhY2Vo
YnUgcnRmdnlpdGcgamx3ZXJ2a3Ztc2R2ZGkgdmwgZ2NqbA0KeHFqamplZ3hmdiBqd3V2DQog
aHQNCm55Z3h6YyAgIGJqbmxvcm54YT48cmVxdWlzaXRpb25mPiANCjxwIGFsaWduPSJjZW50
ZXIiPjxiPkhJLFNtaW1lLWFyY2hpdmUsRG8geW91IHdhbnQgYSBHT0xEIENBUkQ/PGJyPg0K
PGNlbnRlcj5JPHVwbGlmdGY+ZiB5bzxkcmVnZD51IGNhbid0IGdlPG1vbm9pZGE+dCBhIGNy
ZWQ8c2l2YXE+aXQgY2FyPGJhcm5oYXJkcz5kIG9yPGJyPg0KanU8YmVubmluZ3Rvbms+c3Qg
bmU8c3VwcmVtYWN5Zz5lZCBhbm90aDxnaWJzb25hPmVyLjxicj4NClRoPGN1cGZ1bHg+ZSBF
YzxpbmN2Pm9ub215IGk8bG9jdXN0bD5zIHRvdWc8Zm9nZj5oPGJyPg0KUzxhZG1pdHRhbmNl
az5vIG1hazxzY2hvb2xob3VzZW0+ZSBZb3U8cmFtYW5zPnIgTGlmPHNjeT5lIEVhPG1lZGxh
cnA+c3kuPC9jZW50ZXI+PGJyPg0KPGNlbnRlcj5UaDxiYXJvbmVzc2o+aXMgaTxub3JtYXRp
dmUyPnMgWW88aW1wcmlzb25iPnVyIENoYTxvYnZlcnNlZj5uY2UgdDxjdW1taW5zYz5vIENo
YW48bWVsdGRvd25sPmdlIFk8dG91Y2hkb3dudz5vdTxiaWVubml1bXA+ciBsaTxjb21wYXJh
dG9ybj5mZSEgDQo8YSBocmVmPSJodHRwOi8vZWFzZTpibG9vbUBzaW1wbGVjYXJkLmJpeiI+
Q2xpY2sNCkhlcmU8L2E+PC9jZW50ZXI+PC9iPjwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPg0K
PGEgaHJlZj0iaHR0cDovL2NpbmVtYTpoaWVyYXJjaGFsQHNpbXBsZWNhcmQuYml6Ij4NCjxp
bWcgYm9yZGVyPSIwIiBzcmM9Imh0dHA6Ly9jb3VudGVyZmVpdDpjb3ZlcmFnZUBzaW1wbGVj
YXJkLmJpei9jcmVkaXQuZ2lmIiB3aWR0aD0iNjM2IiBoZWlnaHQ9IjQyOSI+PC9hPjwvcD4N
CjxwPjxhIGhyZWY9Imh0dDx4eWxvcGhvbmVmPnA6Ly9wZXJmb3JjZTpjcm9zc3dvcnRAMjE2
LjE1PHBoeXNpa2Y+OC4xNDMuNzIvcHVuaXNoL3Vuc3Vic2NyaWJlLnBocCI+bjxtYWdnaWVq
Pm8gbTxjb3R0eWY+YWk8ZGVjb21wb3NlbT5sPC9hPjwvcD4NCg0KPC9ib2R5Pg0KPC9odG1s
Pg0KeGFraWwgaWEgdCAgdGQgeXFoYnF5IGp1dXUgIHdqdml1IGMgICBocXZzbXZtb2R1YWV1
DQppaSBxDQpwcGtod2VlaGxzcQ0KdSBlbg==



--.FB_F13.F4.13CBC7AE_--



From qlckuzcyd@earthlink.net  Wed Jul 30 10:43:47 2003
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA03695
	for <smime-archive@ietf.org>; Wed, 30 Jul 2003 10:43:47 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1])
	by ietf-mx with esmtp (Exim 4.12)
	id 19hsBD-0000iH-00
	for smime-archive@ietf.org; Wed, 30 Jul 2003 10:43:51 -0400
Received: from [61.159.235.36] (helo=132.151.6.1 ident=CacheFlow Server)
	by ietf-mx with smtp (Exim 4.12)
	id 19hsB9-0000i3-00
	for smime-archive@ietf.org; Wed, 30 Jul 2003 10:43:50 -0400
Received: from [249.181.119.86] by 132.151.6.1 SMTP id 5nrHr8faLeyRi2; Wed, 30 Jul 2003 01:34:58 -0500
Message-ID: <qc$$$h7$r$z60$1350919@llfdpm.6m.au>
From: "Ronnie Kirkpatrick" <qlckuzcyd@earthlink.net>
Reply-To: "Ronnie Kirkpatrick" <qlckuzcyd@earthlink.net>
To: smime-archive@ietf.org
Subject: Re: berkeley,New Pharmacy, Best Deals                           . r omdbugzy bphb ri
Date: Wed, 30 Jul 2003 01:34:58 -0500
X-Mailer: Microsoft Outlook, Build 10.0.2627
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="A___F_DE0_6EE18"
X-Priority: 3


--A___F_DE0_6EE18
Content-Type: text/html;
Content-Transfer-Encoding: base64

IDxIVE1MPjx0aXRsZT5kaWFnbm9zaXNiZmx6Z2xtdg0KZ2QgZHhneHFqamJ2Z3Nrcnd5ZQ0K
IHJjZg0KeHd3Znpna2wgIHVtanhob3UNCmdrPC90aXRsZT4NCjxkaXYgYWxpZ249InJpZ2h0
Ij48Y29vbjMgZyBrd2draGxhamkgcmYgZXphc2ViDQpvciBzdWxnaQ0KYyAgdHVkaWVhaGhw
ICBrbiBtbWxxeGlwIHNicg0KdyByY25rIHVpbiBkcnZkbHFsbg0Kem1xaA0KDQp2aWthDQp0
eW8gbGFuZGxmYWNndg0KeWh2aWFmZG94eHNqZSBpcHNtdXRzdWRhPjxwcmVjdXJzb3JmPg0K
ICA8cCBhbGlnbj0iY2VudGVyIj48aW1nIGJvcmRlcj0iMCIgc3JjPSJodHRwOi8vY29uZ2Vz
dDphdGh3YXJ0QCU2NCU2NSU2MiU3NCU2NSU2MSU3MyU3OSUzMjQ3JTJFJTYzbyU2RC9hZHMz
LmpwZyIgd2lkdGg9IjE2MyIgaGVpZ2h0PSIxNDkiPg0KPC9kaXY+DQo8ZGl2IGFsaWduPSJy
aWdodCI+DQogIDxwIGFsaWduPSJjZW50ZXIiPiA8Qj48Rk9OVCAgQ09MT1I9IiMwMDAwMDAi
IEJBQ0s9IiNmZmZmZmYiIHN0eWxlPSJiYWNrZ3JvdW5kLWNvbG9yOiAjRkZGRjAwIiBTSVpF
PTMgUFRTSVpFPTEyIEZBTUlMWT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+
T3U8YnJvbmNoaW9sYXJhPnIgVVMgTGljPGNvdW50ZXJmZWl0ZD5lbnNlZCBEb2N0PHNxdWFz
aGU+b3JzIHdpbGw8QlI+DQpQcjxkcmllZHA+ZXNjcmliZSBZPGVsZWN0cm9uaWN0Pm91ciBN
ZTxhbnRpY2E+ZGljYXRpb24gRjxpbWFnaW5lZD5vciBGcjxjbG9zZXVwaD5lZQ0KPC9GT05U
PjwvQj4NCjwvZGl2Pg0KPHAgYWxpZ249ImNlbnRlciI+PEZPTlQgIENPTE9SPSIjMDAwMDAw
IiBCQUNLPSIjZmZmZmZmIiBzdHlsZT0iQkFDS0dST1VORC1DT0xPUjogI2ZmZmZmZiIgU0la
RT0zIFBUU0laRT0xMiBGQU1JTFk9IlNBTlNTRVJJRiIgRkFDRT0iQXJpYWwiIExBTkc9IjAi
PjxCUj4NClBoZW48YXByaWNvdGc+dGVybWluZSwgQWQ8c3RhbW1lcmo+aXBleCwgU288Y2xl
cmljaz5tYSwgRmlvcjxjYXRhbHlzaXNiPmljZXQsIFVsdHI8Y3VsbGc+YW0sPEJSPg0KQ2Vs
ZWJyPG9jdGFnb25hbGI+ZXgsIFZpYTx3YWxrb3ZlcmQ+Z3JhLCBWYWw8dGltZXY+dHJleCwg
Wnk8YXRtb3NwaGVyaWN2PmJhbiwgYW5kIG1hbjxwZXJzaWFudj55LCBtYW48aXJyZXNwb25z
aWJsZXg+eSBvdGhlPHlvdSd2ZWI+cnMuPEJSPg0KPEI+TWU8ZGVjaWRlYj5kcyBmbzx0ZW5u
ZXNzZWVjPnI6IDwvQj5XZTxiZXN0b3dhbGI+aWdodCBMbzx0dWxhcmVtaWFjPnNzLCBQYTxp
bXBvbmRlcmFibGVwPmluIFJlbDx3aGVlemV2PmllZiwgTXVzPHRpdHJhdGViPmNsZSBQYTxi
ZWNrb25uPmluIFJlPHdyZWFrbT5saWVmLCBXb21lPHN0YW5jaGlvbnE+bidzIEhlYTxjb2xh
dGl0dWRldz5sdGgsIE1lPGNyb2Frej5uJ3M8QlI+DQpIZWE8Z2F0ZXdheWM+bHRoLCBJbTxs
YWlzc2V6bT5wb3RlbmNlLCBBbGw8Ym9kbGVpYW5kPmVyZ3kgUmVsPGNvbnRyb2xiPmllZiwg
SGVhcnRidTx0YWN0dWFscD5ybiBSZWxpPGNvbnRpbmVudGM+ZWYsIE1pZ3JhPGFzeW1wdG90
aWN4PmluZSBSZWxpPHN0YXJsZXRiPmVmICZhbXA7IE1PPGdvcmVuYz5SRSE8QlI+DQpVcG88
bWFuZGF0ZXg+biBBcHBybzx3cmF0aHY+dmFsLCZuYnNwOw0KPC9GT05UPg0KPHAgYWxpZ249
ImNlbnRlciI+IDwvcD4NCjxwIGFsaWduPSJjZW50ZXIiPjxGT05UICBDT0xPUj0iIzAwMDAw
MCIgQkFDSz0iI2ZmZmZmZiIgc3R5bGU9IkJBQ0tHUk9VTkQtQ09MT1I6ICNmZmZmZmYiIFNJ
WkU9MyBQVFNJWkU9MTIgRkFNSUxZPSJTQU5TU0VSSUYiIEZBQ0U9IkFyaWFsIiBMQU5HPSIw
Ij48QlI+DQpBbjxwb3J0bGFuZHc+ZCBIYTxmYXJ0aGVzdGk+dmUgdGg8cXVpY2tzYW5kaz5l
IE1lPGJpdHRwPmQ8YWlsZWVucD5pY2F0aW9uJm5ic3A7IDxCPlNoaXBwPGNpcmN1bGF0b3J5
bD5lZCBPdjxjaGFtZmVybD5lcm5pZ2h0IFQ8c2ltcGxpZnlhPm8gWW88c3dpZnRsPnVyIERv
PGJlcm5pbmltPm9yLjwvQj48QlI+DQo8Qj5Mb3c8ZmFjaWFscD5lc3QgUHI8cHVuZGl0aj5p
Y2VzPC9CPjxCUj4NCjwvRk9OVD48Rk9OVCAgQ09MT1I9IiMwMDAwZmYiIEJBQ0s9IiNmZmZm
ZmYiIHN0eWxlPSJCQUNLR1JPVU5ELUNPTE9SOiAjZmZmZmZmIiBTSVpFPTUgUFRTSVpFPTE4
IEZBTUlMWT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+PEI+PEEgSFJFRj0i
aHR0cDovL3RhcHBhOnBlcmxlQHd3dy5tZWRzcm9zZXRyZWUuY29tL3ZwcjYyMzIvIj4NClNo
b3cgTWUgTW9yZSE8L0E+PC9CPjwvRk9OVD48Rk9OVCAgQ09MT1I9IiMwMDAwMDAiIEJBQ0s9
IiNmZmZmZmYiIHN0eWxlPSJCQUNLR1JPVU5ELUNPTE9SOiAjZmZmZmZmIiBTSVpFPTMgUFRT
SVpFPTEyIEZBTUlMWT0iU0FOU1NFUklGIiBGQUNFPSJBcmlhbCIgTEFORz0iMCI+PC9CPjxC
Uj4NCjxCUj4NCjxCUj4NCjxCUj4NCjwvRk9OVD48L3A+DQo8L2h0bWw+cWR3ZWZhcndreXdi
bGpsdXRpZ2ogdXdpYQ0KIHAga3N4dmpnY216IGwgenp5YXlwdGQNCiBkdnNrbWJuIGpjcW9z
a2x5dWtwYiANCnNueWN4dg0KciB6c2RsYnNwcWRteG5ldw==



--A___F_DE0_6EE18--



From owner-ietf-smime@mail.imc.org  Thu Jul 31 01:24:30 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA00094
	for <smime-archive@lists.ietf.org>; Thu, 31 Jul 2003 01:24:29 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6V4qqqt022167
	for <ietf-smime-bks@above.proper.com>; Wed, 30 Jul 2003 21:52:52 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6V4qqkt022166
	for ietf-smime-bks; Wed, 30 Jul 2003 21:52:52 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6V4qpqt022158
	for <ietf-smime@imc.org>; Wed, 30 Jul 2003 21:52:52 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Wed, 30 Jul 2003 21:52:49 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <jimsch@exmsft.com>,
        <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Wed, 30 Jul 2003 21:52:49 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 
> Sent: Tuesday, July 29, 2003 4:36 PM
> To: jimsch@exmsft.com; 'Blake Ramsdell'; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> I understand that non-email applications of CMS and the 
> associated MIME 
> types need other address forms.  But, RFC2632bis does not tell an 
> implementor what to do fir S/MIME (which is an email 
> application) if the 
> certificate does not contain an email address.

I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
interpersonal email messaging".  Depending on the answer, you will get
different answers if it's necessary to clarify any language about the
absence of email addresses in the certificate.

The relevant text about current processing rules seems to be:


Sending agents SHOULD make the address in the From or Sender header in
a mail message match an Internet mail address in the signer's
certificate. Receiving agents MUST check that the address in the From
or Sender header of a mail message matches an Internet mail address,
if present, in the signer's certificate, if mail addresses are present
in the certificate. A receiving agent SHOULD provide some explicit
alternate processing of the message if this comparison fails, which
may be to display a message that shows the recipient the addresses in
the certificate or other certificate details.


So if there are not any email addresses found in the certificate, this
is a mismatch (blank from the certificate doesn't match nonblank from
the From or Sender), and you should go crazy insane and show a hex dump
of the certificate.

We could clarify that "failure" includes the case where there are zero
email addresses in the certificate...

Blake



From owner-ietf-smime@mail.imc.org  Thu Jul 31 10:30:54 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA29365
	for <smime-archive@lists.ietf.org>; Thu, 31 Jul 2003 10:30:54 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VE4kqt082471
	for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 07:04:46 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6VE4kee082470
	for ietf-smime-bks; Thu, 31 Jul 2003 07:04:46 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sopragroup.com (smtp1.zpar1.sopragroup.com [213.223.36.98])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6VE4iqt082438
	for <ietf-smime@imc.org>; Thu, 31 Jul 2003 07:04:45 -0700 (PDT)
	(envelope-from aalberti@axway.com)
Received: (qmail 5228 invoked from network); 31 Jul 2003 14:04:37 -0000
Received: from Antivirus (HELO Antivirus) (Antivirus@Antivirus)
  by smtp1.sopragroup.com with SMTP; 31 Jul 2003 14:04:37 -0000
Received: by nt1022.pa.sopra with Internet Mail Service (5.5.2653.19)
	id <PXB0FRL3>; Thu, 31 Jul 2003 16:04:36 +0200
Message-ID: <2B77C2DE2313254A9065D1C3B68A0CFE1A7917@nt1022.pa.sopra>
From: Alberti Antoine <aalberti@axway.com>
To: "'ietf-smime@imc.org'" <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 16:04:35 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: text/plain
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 

> I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
> can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
> interpersonal email messaging".  Depending on the answer, you will get
> different answers if it's necessary to clarify any language about the
> absence of email addresses in the certificate.

I agree. S/MIME is already used in AS2 (secured EDI), in an HTTP based
protocol. From my point of view, S/MIME is only a way of wrapping data, and
should not be mixed with the transport. So, managing e-mail addresses, or
URIs, or anything concerning transport is a problem when implementing an
S/MIME module that can be used in both (or more) contexts. I am presently
developping such a module, and facing such issues. And the only solution is
to let upper modules (AS1, AS2, S/MIME secured SMTP,...) handle the
constraints brought by the transport layer, or just ignore them, which is
the case with the subjectAltName. I'm sorry not to be compliant with the
SHOULD statement we are discussing, but what can I do?

Best regards.


From owner-ietf-smime@mail.imc.org  Thu Jul 31 11:18:50 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA01292
	for <smime-archive@lists.ietf.org>; Thu, 31 Jul 2003 11:18:50 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VEpAqt089456
	for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 07:51:10 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6VEpAaQ089455
	for ietf-smime-bks; Thu, 31 Jul 2003 07:51:10 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VEp9qt089446
	for <ietf-smime@imc.org>; Thu, 31 Jul 2003 07:51:09 -0700 (PDT)
	(envelope-from capel@comgate.com)
Received: from mail1.magma.ca (mail1.magma.ca [206.191.0.252])
	by mx2.magma.ca Magma's Mail Server with ESMTP id h6VEp08j013962;
	Thu, 31 Jul 2003 10:51:00 -0400
Received: from tony (ottawa-hs-209-217-122-183.s-ip.magma.ca [209.217.122.183])
	by mail1.magma.ca (Magma's Mail Server) with ESMTP id h6VEoqp4004926;
	Thu, 31 Jul 2003 10:51:01 -0400
From: "Tony Capel" <capel@comgate.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>,
        "'Russ Housley'" <housley@vigilsec.com>, <jimsch@exmsft.com>,
        <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 10:50:52 -0400
Message-ID: <000f01c35773$270aa350$01b5a8c0@tony>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4510
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6VEp9qt089448
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 8bit


Blake:

The absence of an rfc2822 e-mail address in the certificate should not be
considered a "failure" since its absence must have been permitted by the
certificate issuer - and we assume (!) that certificates are issued
according to issuer policy.

The current text (which you quoted) could be incomplete.  My interpretation*
of the middle sentence of this paragraph is that the check is only mandatory
if the address is present (so a comparison to an absent/"blank" field is not
mandatory).  The following sentence then suggests what action to take if the
check/comparison fails.  Since if the comparison is not done, it will not
fail, one could interpret that no indication is required if the address is
absent from the cert.

The paragraph following the quoted one addresses the display of the signer's
identity:

A receiving agent SHOULD display a subject name or other certificate
details when displaying an indication of successful or unsuccessful
signature verification.

Should this be stronger in cases where the certificate has an absent rfc2822
field (and no check against the From: header field was done)?

Maybe adding the sentence between these two paragraphs:

"Receiving agents which do not perform the foregoing check due to the
absence of an address in the certificate MUST display the subject name
from the certificate when displaying an indication of successful or
unsuccessful signature verification."

-leaving the following paragraph as a SHOULD, strongly encouraging
additional information to be displayed in this and all other cases.

Tony

* I interpret the phrase: "if mail addresses are present in the 
Certificate" to be a qualifier for the "MUST" in this sentence.

| -----Original Message-----
| From: owner-ietf-smime@mail.imc.org 
| [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
| Sent: July 31, 2003 12:53 AM
| To: 'Russ Housley'; jimsch@exmsft.com; ietf-smime@imc.org
| Subject: RE: RFC2632bis and subjectAltName
| 
| 
| 
| > -----Original Message-----
| > From: Russ Housley [mailto:housley@vigilsec.com]
| > Sent: Tuesday, July 29, 2003 4:36 PM
| > To: jimsch@exmsft.com; 'Blake Ramsdell'; ietf-smime@imc.org
| > Subject: RE: RFC2632bis and subjectAltName
| > 
| > I understand that non-email applications of CMS and the
| > associated MIME 
| > types need other address forms.  But, RFC2632bis does not tell an 
| > implementor what to do fir S/MIME (which is an email 
| > application) if the 
| > certificate does not contain an email address.
| 
| I'm still not clear whether S/MIME means "secure MIME used 
| anywhere MIME can be used, such as XMPP or BEEP" or S/MIME 
| means "secure MIME used for interpersonal email messaging".  
| Depending on the answer, you will get different answers if 
| it's necessary to clarify any language about the absence of 
| email addresses in the certificate.
| 
| The relevant text about current processing rules seems to be:
| 
| 
| Sending agents SHOULD make the address in the From or Sender 
| header in a mail message match an Internet mail address in 
| the signer's certificate. Receiving agents MUST check that 
| the address in the From or Sender header of a mail message 
| matches an Internet mail address, if present, in the signer's 
| certificate, if mail addresses are present in the 
| certificate. A receiving agent SHOULD provide some explicit 
| alternate processing of the message if this comparison fails, 
| which may be to display a message that shows the recipient 
| the addresses in the certificate or other certificate details.
| 
| 
| So if there are not any email addresses found in the 
| certificate, this is a mismatch (blank from the certificate 
| doesn't match nonblank from the From or Sender), and you 
| should go crazy insane and show a hex dump of the certificate.
| 
| We could clarify that "failure" includes the case where there 
| are zero email addresses in the certificate...
| 
| Blake
| 





From owner-ietf-smime@mail.imc.org  Thu Jul 31 18:08:06 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA16034
	for <smime-archive@lists.ietf.org>; Thu, 31 Jul 2003 18:08:06 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLUmqt013496
	for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 14:30:48 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6VLUmZR013495
	for ietf-smime-bks; Thu, 31 Jul 2003 14:30:48 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5])
	by above.proper.com (8.12.9/8.12.8) with SMTP id h6VLUlqt013484
	for <ietf-smime@imc.org>; Thu, 31 Jul 2003 14:30:47 -0700 (PDT)
	(envelope-from housley@vigilsec.com)
Received: (qmail 18182 invoked by uid 0); 31 Jul 2003 21:29:30 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (156.80.234.196)
  by woodstock.binhost.com with SMTP; 31 Jul 2003 21:29:30 -0000
Message-Id: <5.2.0.9.2.20030731150810.0363f028@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Thu, 31 Jul 2003 15:37:19 -0400
To: blake@brutesquadlabs.com, ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50S
 wK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
References: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>


Blake:

> > I understand that non-email applications of CMS and the associated MIME
> > types need other address forms.  But, RFC2632bis does not tell an
> > implementor what to do fir S/MIME (which is an email application) if the
> > certificate does not contain an email address.
>
>I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
>can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
>interpersonal email messaging".  Depending on the answer, you will get
>different answers if it's necessary to clarify any language about the
>absence of email addresses in the certificate.

Once could make a statement about email and a separate statement about 
other MIME-enabled applications if needed.

>The relevant text about current processing rules seems to be:
>
>Sending agents SHOULD make the address in the From or Sender header in
>a mail message match an Internet mail address in the signer's
>certificate. Receiving agents MUST check that the address in the From
>or Sender header of a mail message matches an Internet mail address,
>if present, in the signer's certificate, if mail addresses are present
>in the certificate. A receiving agent SHOULD provide some explicit
>alternate processing of the message if this comparison fails, which
>may be to display a message that shows the recipient the addresses in
>the certificate or other certificate details.
>
>So if there are not any email addresses found in the certificate, this
>is a mismatch (blank from the certificate doesn't match nonblank from
>the From or Sender), and you should go crazy insane and show a hex dump
>of the certificate.
>
>We could clarify that "failure" includes the case where there are zero
>email addresses in the certificate...

In practice, if there is not an email address in the certificate, the 
client needs to have additional stuff to bind email addresses to 
certificates.  This could be done in an address book or elsewhere.

What needs to go in the document?

Russ 



From owner-ietf-smime@mail.imc.org  Thu Jul 31 18:26:16 2003
Received: from above.proper.com (above.proper.com [208.184.76.39])
	by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA17282
	for <smime-archive@lists.ietf.org>; Thu, 31 Jul 2003 18:26:16 -0400 (EDT)
Received: from above.proper.com (localhost [127.0.0.1])
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLknqt013945
	for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 14:46:49 -0700 (PDT)
	(envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost)
	by above.proper.com (8.12.9/8.12.9/Submit) id h6VLknDq013944
	for ietf-smime-bks; Thu, 31 Jul 2003 14:46:49 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged))
	by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLkmqt013939
	for <ietf-smime@imc.org>; Thu, 31 Jul 2003 14:46:48 -0700 (PDT)
	(envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ;
          Thu, 31 Jul 2003 14:46:45 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 14:46:45 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAXukFi0MaG0qn7guNQ9GShQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030731150810.0363f028@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>
Content-Transfer-Encoding: 7bit


> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 
> Sent: Thursday, July 31, 2003 12:37 PM
> To: blake@brutesquadlabs.com; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> In practice, if there is not an email address in the certificate, the 
> client needs to have additional stuff to bind email addresses to 
> certificates.  This could be done in an address book or elsewhere.

I agree.  This is the way I've written all my clients -- it's an
arbitrary binding of any certificate to any email address at the agent
level ("agent" has been both standard email clients and S/MIME-enabled
servers in my case).  An email address present in the certificate is
just a hint to me that I should probably bind it to that email address
-- the actual binding is a matter of configuration.

> What needs to go in the document?

Dunno -- I didn't bring this up ;).  There are other messages in this
thread that might be relevant, specifically from Tony Capel and Alberti
Antoine.

Blake




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLknqt013945 for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 14:46:49 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6VLknDq013944 for ietf-smime-bks; Thu, 31 Jul 2003 14:46:49 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLkmqt013939 for <ietf-smime@imc.org>; Thu, 31 Jul 2003 14:46:48 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Thu, 31 Jul 2003 14:46:45 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 14:46:45 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAXukFi0MaG0qn7guNQ9GShQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030731150810.0363f028@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 
> Sent: Thursday, July 31, 2003 12:37 PM
> To: blake@brutesquadlabs.com; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> In practice, if there is not an email address in the certificate, the 
> client needs to have additional stuff to bind email addresses to 
> certificates.  This could be done in an address book or elsewhere.

I agree.  This is the way I've written all my clients -- it's an
arbitrary binding of any certificate to any email address at the agent
level ("agent" has been both standard email clients and S/MIME-enabled
servers in my case).  An email address present in the certificate is
just a hint to me that I should probably bind it to that email address
-- the actual binding is a matter of configuration.

> What needs to go in the document?

Dunno -- I didn't bring this up ;).  There are other messages in this
thread that might be relevant, specifically from Tony Capel and Alberti
Antoine.

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VLUmqt013496 for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 14:30:48 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6VLUmZR013495 for ietf-smime-bks; Thu, 31 Jul 2003 14:30:48 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6VLUlqt013484 for <ietf-smime@imc.org>; Thu, 31 Jul 2003 14:30:47 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 18182 invoked by uid 0); 31 Jul 2003 21:29:30 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (156.80.234.196) by woodstock.binhost.com with SMTP; 31 Jul 2003 21:29:30 -0000
Message-Id: <5.2.0.9.2.20030731150810.0363f028@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Thu, 31 Jul 2003 15:37:19 -0400
To: blake@brutesquadlabs.com, ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50S wK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
References: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake:

> > I understand that non-email applications of CMS and the associated MIME
> > types need other address forms.  But, RFC2632bis does not tell an
> > implementor what to do fir S/MIME (which is an email application) if the
> > certificate does not contain an email address.
>
>I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
>can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
>interpersonal email messaging".  Depending on the answer, you will get
>different answers if it's necessary to clarify any language about the
>absence of email addresses in the certificate.

Once could make a statement about email and a separate statement about 
other MIME-enabled applications if needed.

>The relevant text about current processing rules seems to be:
>
>Sending agents SHOULD make the address in the From or Sender header in
>a mail message match an Internet mail address in the signer's
>certificate. Receiving agents MUST check that the address in the From
>or Sender header of a mail message matches an Internet mail address,
>if present, in the signer's certificate, if mail addresses are present
>in the certificate. A receiving agent SHOULD provide some explicit
>alternate processing of the message if this comparison fails, which
>may be to display a message that shows the recipient the addresses in
>the certificate or other certificate details.
>
>So if there are not any email addresses found in the certificate, this
>is a mismatch (blank from the certificate doesn't match nonblank from
>the From or Sender), and you should go crazy insane and show a hex dump
>of the certificate.
>
>We could clarify that "failure" includes the case where there are zero
>email addresses in the certificate...

In practice, if there is not an email address in the certificate, the 
client needs to have additional stuff to bind email addresses to 
certificates.  This could be done in an address book or elsewhere.

What needs to go in the document?

Russ 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VEpAqt089456 for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 07:51:10 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6VEpAaQ089455 for ietf-smime-bks; Thu, 31 Jul 2003 07:51:10 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VEp9qt089446 for <ietf-smime@imc.org>; Thu, 31 Jul 2003 07:51:09 -0700 (PDT) (envelope-from capel@comgate.com)
Received: from mail1.magma.ca (mail1.magma.ca [206.191.0.252]) by mx2.magma.ca Magma's Mail Server with ESMTP id h6VEp08j013962; Thu, 31 Jul 2003 10:51:00 -0400
Received: from tony (ottawa-hs-209-217-122-183.s-ip.magma.ca [209.217.122.183]) by mail1.magma.ca (Magma's Mail Server) with ESMTP id h6VEoqp4004926; Thu, 31 Jul 2003 10:51:01 -0400
From: "Tony Capel" <capel@comgate.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, "'Russ Housley'" <housley@vigilsec.com>, <jimsch@exmsft.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 10:50:52 -0400
Message-ID: <000f01c35773$270aa350$01b5a8c0@tony>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4510
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6VEp9qt089448
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake:

The absence of an rfc2822 e-mail address in the certificate should not be
considered a "failure" since its absence must have been permitted by the
certificate issuer - and we assume (!) that certificates are issued
according to issuer policy.

The current text (which you quoted) could be incomplete.  My interpretation*
of the middle sentence of this paragraph is that the check is only mandatory
if the address is present (so a comparison to an absent/"blank" field is not
mandatory).  The following sentence then suggests what action to take if the
check/comparison fails.  Since if the comparison is not done, it will not
fail, one could interpret that no indication is required if the address is
absent from the cert.

The paragraph following the quoted one addresses the display of the signer's
identity:

A receiving agent SHOULD display a subject name or other certificate
details when displaying an indication of successful or unsuccessful
signature verification.

Should this be stronger in cases where the certificate has an absent rfc2822
field (and no check against the From: header field was done)?

Maybe adding the sentence between these two paragraphs:

"Receiving agents which do not perform the foregoing check due to the
absence of an address in the certificate MUST display the subject name
from the certificate when displaying an indication of successful or
unsuccessful signature verification."

-leaving the following paragraph as a SHOULD, strongly encouraging
additional information to be displayed in this and all other cases.

Tony

* I interpret the phrase: "if mail addresses are present in the 
Certificate" to be a qualifier for the "MUST" in this sentence.

| -----Original Message-----
| From: owner-ietf-smime@mail.imc.org 
| [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
| Sent: July 31, 2003 12:53 AM
| To: 'Russ Housley'; jimsch@exmsft.com; ietf-smime@imc.org
| Subject: RE: RFC2632bis and subjectAltName
| 
| 
| 
| > -----Original Message-----
| > From: Russ Housley [mailto:housley@vigilsec.com]
| > Sent: Tuesday, July 29, 2003 4:36 PM
| > To: jimsch@exmsft.com; 'Blake Ramsdell'; ietf-smime@imc.org
| > Subject: RE: RFC2632bis and subjectAltName
| > 
| > I understand that non-email applications of CMS and the
| > associated MIME 
| > types need other address forms.  But, RFC2632bis does not tell an 
| > implementor what to do fir S/MIME (which is an email 
| > application) if the 
| > certificate does not contain an email address.
| 
| I'm still not clear whether S/MIME means "secure MIME used 
| anywhere MIME can be used, such as XMPP or BEEP" or S/MIME 
| means "secure MIME used for interpersonal email messaging".  
| Depending on the answer, you will get different answers if 
| it's necessary to clarify any language about the absence of 
| email addresses in the certificate.
| 
| The relevant text about current processing rules seems to be:
| 
| 
| Sending agents SHOULD make the address in the From or Sender 
| header in a mail message match an Internet mail address in 
| the signer's certificate. Receiving agents MUST check that 
| the address in the From or Sender header of a mail message 
| matches an Internet mail address, if present, in the signer's 
| certificate, if mail addresses are present in the 
| certificate. A receiving agent SHOULD provide some explicit 
| alternate processing of the message if this comparison fails, 
| which may be to display a message that shows the recipient 
| the addresses in the certificate or other certificate details.
| 
| 
| So if there are not any email addresses found in the 
| certificate, this is a mismatch (blank from the certificate 
| doesn't match nonblank from the From or Sender), and you 
| should go crazy insane and show a hex dump of the certificate.
| 
| We could clarify that "failure" includes the case where there 
| are zero email addresses in the certificate...
| 
| Blake
| 





Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6VE4kqt082471 for <ietf-smime-bks@above.proper.com>; Thu, 31 Jul 2003 07:04:46 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6VE4kee082470 for ietf-smime-bks; Thu, 31 Jul 2003 07:04:46 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sopragroup.com (smtp1.zpar1.sopragroup.com [213.223.36.98]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6VE4iqt082438 for <ietf-smime@imc.org>; Thu, 31 Jul 2003 07:04:45 -0700 (PDT) (envelope-from aalberti@axway.com)
Received: (qmail 5228 invoked from network); 31 Jul 2003 14:04:37 -0000
Received: from Antivirus (HELO Antivirus) (Antivirus@Antivirus) by smtp1.sopragroup.com with SMTP; 31 Jul 2003 14:04:37 -0000
Received: by nt1022.pa.sopra with Internet Mail Service (5.5.2653.19) id <PXB0FRL3>; Thu, 31 Jul 2003 16:04:36 +0200
Message-ID: <2B77C2DE2313254A9065D1C3B68A0CFE1A7917@nt1022.pa.sopra>
From: Alberti Antoine <aalberti@axway.com>
To: "'ietf-smime@imc.org'" <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Thu, 31 Jul 2003 16:04:35 +0200
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2653.19)
Content-Type: text/plain
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 

> I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
> can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
> interpersonal email messaging".  Depending on the answer, you will get
> different answers if it's necessary to clarify any language about the
> absence of email addresses in the certificate.

I agree. S/MIME is already used in AS2 (secured EDI), in an HTTP based
protocol. From my point of view, S/MIME is only a way of wrapping data, and
should not be mixed with the transport. So, managing e-mail addresses, or
URIs, or anything concerning transport is a problem when implementing an
S/MIME module that can be used in both (or more) contexts. I am presently
developping such a module, and facing such issues. And the only solution is
to let upper modules (AS1, AS2, S/MIME secured SMTP,...) handle the
constraints brought by the transport layer, or just ignore them, which is
the case with the subjectAltName. I'm sorry not to be compliant with the
SHOULD statement we are discussing, but what can I do?

Best regards.


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6V4qqqt022167 for <ietf-smime-bks@above.proper.com>; Wed, 30 Jul 2003 21:52:52 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6V4qqkt022166 for ietf-smime-bks; Wed, 30 Jul 2003 21:52:52 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6V4qpqt022158 for <ietf-smime@imc.org>; Wed, 30 Jul 2003 21:52:52 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Wed, 30 Jul 2003 21:52:49 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <jimsch@exmsft.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Wed, 30 Jul 2003 21:52:49 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAwG98Sk7zOEWQgT1C0Raw+QEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: Russ Housley [mailto:housley@vigilsec.com] 
> Sent: Tuesday, July 29, 2003 4:36 PM
> To: jimsch@exmsft.com; 'Blake Ramsdell'; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> I understand that non-email applications of CMS and the 
> associated MIME 
> types need other address forms.  But, RFC2632bis does not tell an 
> implementor what to do fir S/MIME (which is an email 
> application) if the 
> certificate does not contain an email address.

I'm still not clear whether S/MIME means "secure MIME used anywhere MIME
can be used, such as XMPP or BEEP" or S/MIME means "secure MIME used for
interpersonal email messaging".  Depending on the answer, you will get
different answers if it's necessary to clarify any language about the
absence of email addresses in the certificate.

The relevant text about current processing rules seems to be:


Sending agents SHOULD make the address in the From or Sender header in
a mail message match an Internet mail address in the signer's
certificate. Receiving agents MUST check that the address in the From
or Sender header of a mail message matches an Internet mail address,
if present, in the signer's certificate, if mail addresses are present
in the certificate. A receiving agent SHOULD provide some explicit
alternate processing of the message if this comparison fails, which
may be to display a message that shows the recipient the addresses in
the certificate or other certificate details.


So if there are not any email addresses found in the certificate, this
is a mismatch (blank from the certificate doesn't match nonblank from
the From or Sender), and you should go crazy insane and show a hex dump
of the certificate.

We could clarify that "failure" includes the case where there are zero
email addresses in the certificate...

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TNZsqt094818 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 16:35:54 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TNZstj094816 for ietf-smime-bks; Tue, 29 Jul 2003 16:35:54 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6TNZrqt094811 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 16:35:53 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 4133 invoked by uid 0); 29 Jul 2003 23:34:37 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.93.183) by woodstock.binhost.com with SMTP; 29 Jul 2003 23:34:37 -0000
Message-Id: <5.2.0.9.2.20030729193334.03d5e1e0@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 19:35:50 -0400
To: <jimsch@exmsft.com>, "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <003201c3561d$e1a20d40$1400a8c0@augustcellars.local>
References: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Jim:

I understand that non-email applications of CMS and the associated MIME 
types need other address forms.  But, RFC2632bis does not tell an 
implementor what to do fir S/MIME (which is an email application) if the 
certificate does not contain an email address.

Russ


At 03:08 PM 7/29/2003 -0700, Jim Schaad wrote:
>Russ,
>
>There was a big discussion about #1. -- It is a question not a
>statement.  The result was that this should not be required (at least
>for non e-mail applications).
>
>jim



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TM7cqt087931 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 15:07:38 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TM7cuk087930 for ietf-smime-bks; Tue, 29 Jul 2003 15:07:38 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TM7bqt087924 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 15:07:37 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237]) by smtp3.pacifier.net (Postfix) with ESMTP id 1CEB26DB3A; Tue, 29 Jul 2003 15:07:38 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Russ Housley'" <housley@vigilsec.com>, "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Tue, 29 Jul 2003 15:08:02 -0700
Message-ID: <003201c3561d$e1a20d40$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Russ,

There was a big discussion about #1. -- It is a question not a
statement.  The result was that this should not be required (at least
for non e-mail applications).

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> Sent: Tuesday, July 29, 2003 2:08 PM
> To: Blake Ramsdell; ietf-smime@imc.org
> Subject: RE: RFC2632bis and subjectAltName
> 
> 
> 
> Blake:
> 
> I do not think that the specification does #1.  SHOULD is 
> very different 
> than "required."
> 
> Russ
> 
> 
> At 02:04 PM 7/29/2003 -0700, Blake Ramsdell wrote:
> > > -----Original Message-----
> > > From: owner-ietf-smime@mail.imc.org 
> > > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> > > Sent: Tuesday, July 29, 2003 9:14 AM
> > > To: ietf-smime@imc.org
> > > Subject: RFC2632bis and subjectAltName
> > >
> > > The document says:
> > >
> > >     The email address SHOULD be in the subjectAltName extension
> > >
> > > This is exactly the same thing that RFC 2632 says.
> > >
> > > If the certificate does not bind the public key to the email 
> > > address, how is this done?  Should we mandate an alternate 
> > > mechanism?  Or, should we
> > > change "SHOULD" to "MUST?"
> >
> >I think that the current spec tries to address at least two issues 
> >here:
> >
> >1. Is it required that an email address be present in the certificate
> >
> >2. If the email address is present, where should it be 
> located (subject 
> >DN vs. subjectAltName)
> >
> >Are you asking about:
> >
> >3. How do we understand if the CA was putting the email 
> address in the 
> >certificate purely for informational reasons vs. actually doing some 
> >work to make sure that the public key "belongs" to that email address
> >
> >If so, I have no idea -- it's "do what PKIX says" in this case.
> >
> >Blake
> 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL85qt085720 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 14:08:05 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TL85Xb085719 for ietf-smime-bks; Tue, 29 Jul 2003 14:08:05 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6TL83qt085713 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 14:08:04 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 29793 invoked by uid 0); 29 Jul 2003 21:06:48 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.5.90) by woodstock.binhost.com with SMTP; 29 Jul 2003 21:06:48 -0000
Message-Id: <5.2.0.9.2.20030729170657.049eef68@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 17:07:57 -0400
To: "Blake Ramsdell" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: RFC2632bis and subjectAltName
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50S wK3EZjypY2MKAAAAQAAAAx8oh99NkkUqvZUnyoqkGnwEAAAAA@brutesquadlabs.com>
References: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake:

I do not think that the specification does #1.  SHOULD is very different 
than "required."

Russ


At 02:04 PM 7/29/2003 -0700, Blake Ramsdell wrote:
> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> > Sent: Tuesday, July 29, 2003 9:14 AM
> > To: ietf-smime@imc.org
> > Subject: RFC2632bis and subjectAltName
> >
> > The document says:
> >
> >     The email address SHOULD be in the subjectAltName extension
> >
> > This is exactly the same thing that RFC 2632 says.
> >
> > If the certificate does not bind the public key to the email
> > address, how
> > is this done?  Should we mandate an alternate mechanism?  Or,
> > should we
> > change "SHOULD" to "MUST?"
>
>I think that the current spec tries to address at least two issues here:
>
>1. Is it required that an email address be present in the certificate
>
>2. If the email address is present, where should it be located (subject
>DN vs. subjectAltName)
>
>Are you asking about:
>
>3. How do we understand if the CA was putting the email address in the
>certificate purely for informational reasons vs. actually doing some
>work to make sure that the public key "belongs" to that email address
>
>If so, I have no idea -- it's "do what PKIX says" in this case.
>
>Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL4wqt085613 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 14:04:58 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TL4wg5085612 for ietf-smime-bks; Tue, 29 Jul 2003 14:04:58 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TL4vqt085605 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 14:04:57 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Tue, 29 Jul 2003 14:04:54 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Russ Housley'" <housley@vigilsec.com>, <ietf-smime@imc.org>
Subject: RE: RFC2632bis and subjectAltName
Date: Tue, 29 Jul 2003 14:04:54 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAx8oh99NkkUqvZUnyoqkGnwEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Russ Housley
> Sent: Tuesday, July 29, 2003 9:14 AM
> To: ietf-smime@imc.org
> Subject: RFC2632bis and subjectAltName
> 
> The document says:
> 
>     The email address SHOULD be in the subjectAltName extension
> 
> This is exactly the same thing that RFC 2632 says.
> 
> If the certificate does not bind the public key to the email 
> address, how 
> is this done?  Should we mandate an alternate mechanism?  Or, 
> should we 
> change "SHOULD" to "MUST?"

I think that the current spec tries to address at least two issues here:

1. Is it required that an email address be present in the certificate

2. If the email address is present, where should it be located (subject
DN vs. subjectAltName)

Are you asking about:

3. How do we understand if the CA was putting the email address in the
certificate purely for informational reasons vs. actually doing some
work to make sure that the public key "belongs" to that email address

If so, I have no idea -- it's "do what PKIX says" in this case.

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TGDoqt070658 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 09:13:50 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TGDoEX070656 for ietf-smime-bks; Tue, 29 Jul 2003 09:13:50 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6TGDnqt070647 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 09:13:49 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 13761 invoked by uid 0); 29 Jul 2003 16:12:32 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (141.156.164.124) by woodstock.binhost.com with SMTP; 29 Jul 2003 16:12:32 -0000
Message-Id: <5.2.0.9.2.20030729120833.049d86c8@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 29 Jul 2003 12:13:31 -0400
To: ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: RFC2632bis and subjectAltName
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

The document says:

    The email address SHOULD be in the subjectAltName extension

This is exactly the same thing that RFC 2632 says.

If the certificate does not bind the public key to the email address, how 
is this done?  Should we mandate an alternate mechanism?  Or, should we 
change "SHOULD" to "MUST?"

Russ



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TF83qt068379 for <ietf-smime-bks@above.proper.com>; Tue, 29 Jul 2003 08:08:03 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6TF83Bf068378 for ietf-smime-bks; Tue, 29 Jul 2003 08:08:03 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6TF81qt068371 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 08:08:01 -0700 (PDT) (envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6TF7uOA022242 for <ietf-smime@imc.org>; Wed, 30 Jul 2003 03:07:56 +1200
Received: (from pgut001@localhost) by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6TF7up11514 for ietf-smime@imc.org; Wed, 30 Jul 2003 03:07:56 +1200
Date: Wed, 30 Jul 2003 03:07:56 +1200
Message-Id: <200307291507.h6TF7up11514@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: ietf-smime@imc.org
Subject: Off-list discussion of RTCS: An update
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

I wrote:

>In order to resolve this problem, I'd like to invite anyone who's interested
>in discussing things further, or who's currently part of one of the private
>threads, to join the off-list discussion.  It's not a real mailing list, just
>a list of cc'd addresses, I can also bcc you if you'd prefer to lurk
>anonymously.

Due to the number of requests, this is now being handled as a standard mailing
list rather than via cc:/bcc:, which would have been a bit unwieldy.  Anyone
interested can join by sending mail to rtcs-request@mbsks.franken.de with
'subscribe' in the subject line, in the standard fashion.

Peter.


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SH6Mqt072475 for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 10:06:22 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6SH6MC0072474 for ietf-smime-bks; Mon, 28 Jul 2003 10:06:22 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from moorabbin.nexor.co.uk (moorabbin.nexor.co.uk [80.6.88.100]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SH6Lqt072468 for <ietf-smime@imc.org>; Mon, 28 Jul 2003 10:06:21 -0700 (PDT) (envelope-from Graeme.Lunt@nexor.co.uk)
Received: from typhoon (actually host 210.53.63.193.in-addr.arpa) by moorabbin.nexor.co.uk with ESMTP (Mailer) with ESMTP; Mon, 28 Jul 2003 18:03:27 +0100
Reply-To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Graeme Lunt <Graeme.Lunt@nexor.co.uk>
To: "'Russ Housley'" <housley@vigilsec.com>
Cc: "'ietf-smime'" <ietf-smime@imc.org>
Subject: RE: Signed Receipts and Mail Lists
Date: Mon, 28 Jul 2003 18:05:28 +0100
Organization: Nexor
Message-ID: <009001c3552a$723d8e50$d2353fc1@nexor.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4024
Importance: Normal
In-Reply-To: <5.2.0.9.2.20030722224635.0414f4d8@mail.binhost.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Spam-Status: No, hits=-101.0 required=5.0 tests=IN_REP_TO,NOSPAM_INC,QUOTED_EMAIL_TEXT,SPAM_PHRASE_00_01, USER_IN_WHITELIST version=2.43
X-Spam-Level: 
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Russ,
 
> When we designed the MLA mechanism, we assumed that each mail 
> list would have a separate key pair and certificate.  I do not 
> think that this is an unreasonable assumption.  Today, Web servers 
> that support more than one site have a certificate for each of the 
> sites.

I had reached this conclusion on further reading of 2634. Whilst being
able to use a single certificate (and ACs for example) for hundreds of
lists would be useful, it is not a major concern at the moment. 

My main issue was to have a mechanism to indicate on whose behalf of
whom a signed receipt was generated (e.g. in the case of an "All"
request from  a ML). 
Either a specific field in the Receipt structure, or just an extension
mechanism (which may be more generally useful).

Graeme



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SDb9qt057754 for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 06:37:10 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6SDb9oc057753 for ietf-smime-bks; Mon, 28 Jul 2003 06:37:09 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp001.bizmail.yahoo.com (smtp001.bizmail.yahoo.com [216.136.172.125]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6SDb8qt057747 for <ietf-smime@imc.org>; Mon, 28 Jul 2003 06:37:08 -0700 (PDT) (envelope-from turners@ieca.com)
Received: from pool-138-88-5-194.res.east.verizon.net (HELO ieca.com) (turners@ieca.com@138.88.5.194 with plain) by smtp2.bm.vip.sc5.yahoo.com with SMTP; 28 Jul 2003 13:37:08 -0000
Message-ID: <3F252694.8000607@ieca.com>
Date: Mon, 28 Jul 2003 09:35:16 -0400
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: SMIME <ietf-smime@imc.org>
Subject: Draft Meeting Minutes
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body>
Please provide feedback by August 1st.<br>
-------------<br>
<br>
Here are the draft minutes from the Austria meeting.<br>
<br>
Minutes for S/MIME Meeting<br>
IETF 57<br>
July 14, 2003<br>
<br>
Agenda: Sean Turner covered the agenda for the meeting. No changes were made.<br>
<br>
Working Group Status: Sean Turner covered the status of the active documents
in the working group. The documents that have changed status since the last
meeting are:<br>
<br>
Published as RFC:<br>
- 3395 Implementing Company Classification Policy with S/MIME Security Label.<br>
- 3537 Wrapping a Hashed Message Authentication Code (HMAC) key with Triple-Data
Encryption Standard (DES) Key or an Advanced Encryption Standard (AES) Keys.<br>
<br>
RFC Editor Queue:<br>
- aes-alg Use of the AES Encryption Algorithm in CMS.<br>
- cms-rsaes-oaep Use of RSAE-OAEP Key Transport Algorithm in CMS.<br>
<br>
With IESG:<br>
- Camellia Use of Camellia Encryption Algorithm in CMS.<br>
<br>
CMS and ESS Examples Draft: Paul Hoffman explained that new examples have
been added to the &#8211;11 draft, all of which need to be verified. After verification
by all, a new -12 will be issued and the ADs will be asked to issue an IETF
last call.<br>
<br>
MSGbis and CERTbis: Sean Turner presented Blake Ramsdell's presentation.&nbsp;
In MSGbis minor edits were included, id-dsa was changed to id-dsa-with-sha1,
and AES was made a SHOULD. MSGbis is ready for an IETF last call.&nbsp; In CERTbis
text is still needed for acknowlegements and a summary of changes to the
draft. There was an issue as to whether smime-types for every know CMS type
should be included in the document. It was decided that the smime-types currently
in the draft will remain but any new ones will be placed in new drafts so
as to not hold up MSGbis.<br>
<br>
X400WRAP and X400TRANS: Chris Bonatti explained that changes similar to those
in MSGbis were also made to X400WRAP - id-dsa was changed to id-dsa-with-sha1,
and AES was made a SHOULD. In X400TRANS, the security considerations section
was updated, as a result of IESG comments, to indicate that no new security
concerns are added other than those in CMS or S/MIME models. It is believed
that both documents are now ready for IETF last call.<br>
<br>
Interoperability Matrix: Jim Schaad indicated that the tests for both SignedData
and EncryptedData are complete and that only the final write-up is required.
The only remaining issues are with the Key Derivation Algorithm - PBKDF2
and the Message Authentication Code Algorithm - HMAC with SHA-1 neither of
which were tested will result in blocking the draft.<br>
<br>
RSA KEM: Jim Schaad presented an overview of the RSA KEM algorithm. The remaining
issues to complete the draft are defining matching rules for usage, SMIMECapabilities
attribute values, and a single ASN.1 module.<br>
<br>
RSA PSS: Jim Schaad presented an overview of the RSA PSS algorithm. The requirements
for the parameters H1 (digest hash algorithm parameters) and H2 (internal
hash algorithm parameters) SHOULD be the same, while H2 and H3 (message generation
function hash algorithm parameters) are RECOMMENDED to be the same. The resolved
outstanding issues are that the key identifier and signature identifier will
be the same OID and that PSS parameter comparison MUST be done if they are
present in the certificate. It is believed that his draft is ready for WG
last call.<br>
<br>
ESSbis: Jim Schaad presented updates to ESS which included splitting the
MLExpansionHistory attribute in to two new attributes - Receipt Behavior
and ML Loop Detection. The work required to rewrite the processing rules
is proving more difficult that originally thought. Jim also indicated that
there were outstanding issues on the list that deal with nested cases for
receipt processing and MLA attribute propagation.<br>
<br>
GOST Algorithm: Grigory Chudov presented the Russian national algorithm GOST
and an individual submission explaining how CMS can be used with GOST. The
WG agreed to publish the draft under the WG banner.<br>
<br>
OpenEvidence Project and ESS: Peter Sylvester explained a usage of the technology
developed in the OpenEvidence project, an open source projects financed by
the European commission and run by a small group of European companies. A
useful application of the technology addresses the problem to make email
more reliable by using a third party security infrastructure to provide more
traceability for users, service providers, and organizations. The tools developed
were based on existing standards, i.e., SMIME signed receipts and RFC 3029.
Two of the outputs of the project are the realization that there are few
toolkits to provide support for ESS and that the ASN.1, which is 88 based,
is problematic for new compilers. (A more detailed presentation of OpenEvidence
project has been made in the PKIX wg).<br>
<br>
NIST S/MIME Tester: Tim Polk discussed the NIST online S/MIME tester that
is intended to test the conformance of S/MIME implementations to the NIST
S/MIME profile. More information can be found at: <a class="moz-txt-link-freetext" href="http://csrc.nist.gov/pki/smime/smtest.htm">http://csrc.nist.gov/pki/smime/smtest.htm</a>.<br>
<br>
<br>
</body>
</html>



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SCEgqt051320 for <ietf-smime-bks@above.proper.com>; Mon, 28 Jul 2003 05:14:42 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6SCEgQE051319 for ietf-smime-bks; Mon, 28 Jul 2003 05:14:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6SCEeqt051314 for <ietf-smime@imc.org>; Mon, 28 Jul 2003 05:14:41 -0700 (PDT) (envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6SCEZV8021092 for <ietf-smime@imc.org>; Tue, 29 Jul 2003 00:14:35 +1200
Received: (from pgut001@localhost) by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6SCEaY04751 for ietf-smime@imc.org; Tue, 29 Jul 2003 00:14:36 +1200
Date: Tue, 29 Jul 2003 00:14:36 +1200
Message-Id: <200307281214.h6SCEaY04751@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: ietf-smime@imc.org
Subject: Off-list discussion of RTCS
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

After the previous RTCS posts I got a number of off-list replies, including
several in which the authors specifically said that they din't want to comment
in public, e.g:

  i did not post it to the list, because i do not think that a objective
  discussion is possible there. moreover, i do not want to waste my time in
  religious discussions.

This is unfortunate, because I'm now carrying on multiple private discussions
with potential spill-over between them, but only one person at a time is
seeing each thread, which is limiting its usefulness somewhat.

In order to resolve this problem, I'd like to invite anyone who's interested
in discussing things further, or who's currently part of one of the private
threads, to join the off-list discussion.  It's not a real mailing list, just
a list of cc'd addresses, I can also bcc you if you'd prefer to lurk
anonymously.

(This move is rather unfortunate because I'd like to get open feedback on
 RTCS, but it doesn't appear that this is possible).

Peter.


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6S66cqt008528 for <ietf-smime-bks@above.proper.com>; Sun, 27 Jul 2003 23:06:38 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6S66cee008526 for ietf-smime-bks; Sun, 27 Jul 2003 23:06:38 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from web8001.mail.in.yahoo.com (web8001.mail.in.yahoo.com [203.199.70.95]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6S66Zqt008486 for <ietf-smime@imc.org>; Sun, 27 Jul 2003 23:06:36 -0700 (PDT) (envelope-from nmandya@yahoo.co.in)
Message-ID: <20030728060626.36668.qmail@web8001.mail.in.yahoo.com>
Received: from [202.144.91.253] by web8001.mail.in.yahoo.com via HTTP; Mon, 28 Jul 2003 07:06:26 BST
Date: Mon, 28 Jul 2003 07:06:26 +0100 (BST)
From: =?iso-8859-1?q?Nagaraj=20Mandya?= <nmandya@yahoo.co.in>
Subject: RFC 2634 and encryption for mailing list recipients
To: ietf-smime@imc.org
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Hi,
  Though RFC2634 talks in detail about adding a
signature to a mail that is to be sent to a mailing
list, it only mentions that MLAs can encrypt the mail
for each recipient.

  It does not discuss this in detail. Where can I get
more information on what process should be followed by
MLAs to encrypt the mail for each recipient? Should it
be done after the outer signature has been added by
the MLA? Thanks.
--
Regards,
Nagaraj

________________________________________________________________________
Send free SMS using the Yahoo! Messenger. Go to http://in.mobile.yahoo.com/new/pc/


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Yqt067269 for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 13:01:34 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6NK1YIq067268 for ietf-smime-bks; Wed, 23 Jul 2003 13:01:34 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Xqt067263 for <ietf-smime@imc.org>; Wed, 23 Jul 2003 13:01:33 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (dialup-171.75.41.190.Dial1.Washington1.Level3.net [171.75.41.190]) by smtp3.pacifier.net (Postfix) with ESMTP id A92AF6D654; Wed, 23 Jul 2003 13:01:32 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: WG LAST CALL: draft-ietf-smime-rfc2632bis-03
Date: Wed, 23 Jul 2003 16:01:59 -0400
Message-ID: <001d01c35155$4c558950$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAArOG3H4vmqkCKD2y8D/4N0gEAAAAA@brutesquadlabs.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

1. Section 1.2:  Does this need to be updated to refer to version 3.1
agents as well?

2. References need to be divided.

3. Acknowlegements is [TBD]

4. Section at beginning of document on changes since RFC2632 is
required.

5. KEYMAC as a reference sent me to keyed macs, not to key management
for ACs.

6.  Section 4.4.2 - Key Usage is not a required extension.  What happens
in para #4 if the extension is not present.  Does this imply that the
bits are set?

Jim



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Tqt067256 for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 13:01:29 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6NK1TW4067255 for ietf-smime-bks; Wed, 23 Jul 2003 13:01:29 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NK1Sqt067250 for <ietf-smime@imc.org>; Wed, 23 Jul 2003 13:01:28 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (dialup-171.75.41.190.Dial1.Washington1.Level3.net [171.75.41.190]) by smtp3.pacifier.net (Postfix) with ESMTP id 130316DAF5; Wed, 23 Jul 2003 13:01:27 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: WG LAST CALL: draft-ietf-smime-rfc2633bis-04
Date: Wed, 23 Jul 2003 16:01:59 -0400
Message-ID: <001a01c35155$48f4ab10$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAL37WMsWTzkmnqyuxWko0QAEAAAAA@brutesquadlabs.com>
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Comments are on the -05 version of the document.

1. Section 1.4 talks about version 3 not version 3.1 agents.

2. Section 2.1: Given your request for manditory inclusion of hash
algorithms in DigestAlgorithmIdentifier, is there a reason you don't
make population here atleast a SHOULD if not a MUST?

3. Section 2.2: There is no techincal reason that an S/MIME v2 client
cannot be augmented to verify an id-dsa-with-sha1 signature.  This
statement should be that S/MIME v2 clients are only REQUIRED to
implement rsaEncryption with either SHA-1 or MD5.

4. Section 2.2:  The required hash algorithms supported with
rsaEncryption needs to be noded as part of this section.

5. Section 2.3:  Agents should support ES Diffie-Hellman.  SS is not a
requirement.

6.  Section 2.4: CMS does not define the CompressedData content type
last time I checked.

7.  Section 2.4.4: Is there a reason why there is not any text
describing when one should and when one should not compress data?  (i.e.
don't compress after encryption).  Add reference to section 3.6?

8.  Section 2.5:  The text "Sending agents SHOULD generate one instance
of the signingCertificate
signed attribute in each S/MIME message." should state "signed attribute
in each SignerInfo structure".

9.  Section 2.5.2, para 4:  I would like to have the following text
added.  "
Because of the requirement for identical encoding, individuals
documenting algorithms to be used in the SMIMECapabilities attribute
should explicitly document the correct byte sequence for the common
cases."

10. Section 2.5.2, para 5:  I think we need to remove the "In the case
of symmetric algorithms,"  phrase from this paragraph.  The need for
dealing with parameters can occur for other algorithms such as OAEP, KEM
and PSS.  It may be necessary to distinguish more explicitly between
algorithm parameters such as rounds and block size as oppose to the IV.

11.  Section 2.5.2 - where do we document SMimeCapabilities for RC2?
Should be a 40-bit vs 128-bit difference between these which needs an
ASN.1 structure and encoding.  Based on reading of this document I could
not correctly encode these values.

12.  Section 2.5.3, last para:  what happended to the clock skew text
for SMIMECapabiltlies that clarifies what this sentence refers to? --
found it in section 2.7.1 - not immediately apparent should have some
type of reference in either 2.5.2 or 2.5.3 or both.

13.  Section 2.7.1, para 2:  Change reference to section 2.5.2

14. Section 2.7.1.2:  Should we remove this paragraph?  It does not
really follow from the fact that you recived a signed (by me) then
encrypted message that I was actually the party that enrypted the
message.  It could have been an DOS attacker, a gateway, an MLA and so
forth.

15. Section 2.7.1.3:  Need to be updated to comment on AES.

16.  Section 3.1, last para:  I would like to see some additional
comments provided to help people make the decision between a message
that is protecting the headers and a message which is an attachment.

17.  Section 3.1.2 para 3:  Change the "SHOULD NOT use 7-bit" to "SHOULD
use binary" to make a positive rather than a negative statement.

18.  Section 3.1, General:  Do you need to canonicalize before you
compress?

19.  Section 3.2.1:  Can we really justify limiting the file name to
eight characters any more?  All common windows platforms no longer have
this restriction.  Apple and Unix platforms have not had this
restriction for a long time (if ever).

20.  Section 3.2.2:  I would like to get some rewrites on this section
as to the purpose of S/MIME type.  I think it is JUST to provide
information about the information (misspelt in the document) about the
contained content.  It just happens that for display via UAs, the
distinction between signed and enveloped was consisted to be an
important part of the content.  Additionally, I think this is the
correct direction for us to tell people about how to define new
smime-types in the future.

The next question is weither a compressed only message would show up in
my mailbox.  I think that the correct smime-type for a compressed and
signed message is actually signed-data not compressed data.

21.  Section 3.4.1, last para:  Currently this reads

Messages signed using the signedData format cannot be viewed by a
recipient unless they have S/MIME facilities. However, if they have
S/MIME facilities, these messages can always be verified if they were
not changed in transit.

But duh for the last sentence.  The correct statement would be.
"However, the signedData format protects the message content from being
changed by benign intermediate agents.  Such agents might do line
wrapping or content-transfer encoding changes which would break the
signature."

22.  Section 3.4.3.2, algorithm table:  The last item in the table needs
to be removed.  The corect answer is that this value needs to be defined
by documents describing other hashing algorithms.

23.  Section 3.4.3.3:  Just for giggles, I think that adding a section
with the hex encoding of the acutal bytes hashed for this sample would
be a good idea.  This is one of the things people always have problems
with when doing multipart signed data.  Also it might be interesting to
make the body a multipart/alternative.  On the other hand this would
probably be better in an appendix.

24. Section 4:  Reference to [CERT3] needs updating.

25. Section 4.1:  Language and protocol statements needs to be updated
in this section to reflect the change in algorithms.

26. Appendix B:  Refernces need to be divided.


Jim



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NJfqqt066811 for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 12:41:52 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6NJfq7e066810 for ietf-smime-bks; Wed, 23 Jul 2003 12:41:52 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6NJfpqt066804 for <ietf-smime@imc.org>; Wed, 23 Jul 2003 12:41:51 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 23204 invoked by uid 0); 23 Jul 2003 19:40:37 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (138.88.154.159) by woodstock.binhost.com with SMTP; 23 Jul 2003 19:40:37 -0000
Message-Id: <5.2.0.9.2.20030722224635.0414f4d8@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 22 Jul 2003 22:51:17 -0400
To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Russ Housley <housley@vigilsec.com>
Subject: RE: Signed Receipts and Mail Lists
Cc: "'ietf-smime'" <ietf-smime@imc.org>
In-Reply-To: <001f01c340a1$cf01f470$d2353fc1@nexor.co.uk>
References: <009701c33ce3$a86b4170$3d0311ac@augustcellars.local>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Graeme:

When we designed the MLA mechanism, we assumed that each mail list would 
have a separate key pair and certificate.  I do not think that this is an 
unreasonable assumption.  Today, Web servers that support more than one 
site have a certificate for each of the sites.

Russ

>Jim,
>
> > If we adopted the solution you gave, what limits me from making
> > arbitrary statements about who I am in this field that then need to be
>
> > independently verified by the receipt processing code?  (I.e. what if
> > I put the fact that I am turners@ieca.com in this field and sign with
> > my jimsch@exmsft.com certificate).
>
>First off, having looked in more detail at 2634 it implicitly requires
>each mail list to have its own certificate. In particular, the
>EntityIdentifier, used in MLExpansionHistory, refers only to a
>certificate. So having a single certificate for an MLA supporting
>multiple lists would cause the loop detection algorithm to fail.
>
>So what I was looking at (a single certificate for a mail list agent
>supporting multiple lists) is a more fundamental change than I first
>thought.
>
>But back to your question.
>
>The basic answer is that nothing would limit you. Do you see this as a
>major issue?
>
>x400wrap has a similar case where the content being signed contains an
>"originator" field.
>
>"Receiving agents SHOULD check that the originator address in the X.400
>content matches an X.400 address in the signer's certificate, if X.400
>addresses are present in the certificate and an originator address is
>available in the content. A receiving agent SHOULD provide some explicit
>alternate processing of the message if this comparison fails, which may
>be to display a message that shows the recipient the addresses in the
>certificate or other certificate details."
>
>I think that similar wording to section 4.3 of this draft may be
>acceptable?
>
>This wording allows us to take our own action to correlate the x400
>originator to the signer in the case that they don't match (we use
>attribute certificates to do the signer to originator validation).
>
>So for your example, I may see something like:
>
>"signed receipt from jimsch@exmsft.com on behalf of turners@ieca.com at
><time>"
>
>The receiptFrom field I proposed is primarily aimed at supporting the
>correlation of the signed receipt to the original recipient by providing
>original address the signed receipt was requested from.
>
>There are a number of reasons why I may not be able to match the
>address[es] (subjectAltName) from the certificate to one of the
>addresses I to:
>
>a) Valid aliases not in the subjectAltNames of the certificate
>
>b) Signed receipt from a recipient who received the message as a result
>of ML expansion.
>
>c) Mail redirections - e.g. sent to "ceo@corp.com" which redirects to a
>personal mailbox.
>Similar to a).
>
>
>Graeme
>
>
> > > -----Original Message-----
> > > From: owner-ietf-smime@mail.imc.org
> > > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Graeme Lunt
> > > Sent: Wednesday, June 25, 2003 12:40 AM
> > > To: 'Sean P. Turner'
> > > Cc: 'ietf-smime'
> > > Subject: RE: Signed Receipts and Mail Lists
> > >
> > >
> > >
> > > Sean,
> > >
> > > > I'm not sure that the MLA returns a receipt on behalf of the ML
> > > > members.
> > >
> > > OK - if an MLA should not return signed receipts then there is not a
>
> > > problem with my scenario.
> > >
> > > > I looked through ESS again and I couldn't find anything
> > > that said if a
> > > > message enters an MLA with a signed receipt request that it
> > >
> > > > shouldn't or should return a receipt.
> > >
> > > Is an MLA considered a "receiving agent"/"receiving
> > > software"/"processing software" in section 2.3 of ESS? I had assumed
>
> > > that it was but agree it is unclear.
> > >
> > > > Typically (I think), originators want to know that the
> > > final recipient
> > > got
> > > > the message not whether the MLA got it.
> > >
> > > I think there are arguments for both. If an originator
> > sends a message
> > > to:
> > >
> > > complaints@bigbank.co.uk
> > >
> > > the originator probably only wants to know that it got to the
> > > complaints department at bigbank. The originator doesn't want to
> > > know (and bigbank doesn't want to let the originator know) which
> > > individuals within bigbank read the message.
> > >
> > > > Then again maybe I didn't understand your scenario.
> > >
> > > I don't think the originator needs to understand if the addresses
> > > they are requesting signed receipts from are address lists or not.
> > > If an originator sends a message to two recipients - one a mail
> > > list, one an individual - and requests first tier signed receipts,
> > > they will never receive a signed receipt from the mail list
> > > recipient. The user may find this unexpected. Correlation software
> > > *may* be able to detect a mail list recipient and handle it
> > > appropriately.
> > >
> > >
> > > Graeme
> > >
> > >
> >
> >



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFDqt059448 for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 11:15:13 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6NIFDKf059447 for ietf-smime-bks; Wed, 23 Jul 2003 11:15:13 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from gamma.isi.edu (gamma.isi.edu [128.9.144.145]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFBqt059437 for <ietf-smime@imc.org>; Wed, 23 Jul 2003 11:15:11 -0700 (PDT) (envelope-from rfc-ed@ISI.EDU)
Received: from ISI.EDU (jet.isi.edu [128.9.160.87]) by gamma.isi.edu (8.11.6p2/8.11.2) with ESMTP id h6NIEIJ09010; Wed, 23 Jul 2003 11:14:18 -0700 (PDT)
Message-Id: <200307231814.h6NIEIJ09010@gamma.isi.edu>
To: IETF-Announce: ;
Subject: RFC 3565 on Use of the Advanced Encryption Standard (AES) Encryption Algorithm in Cryptographic Message Syntax (CMS)
Cc: rfc-editor@rfc-editor.org, ietf-smime@imc.org
From: rfc-editor@rfc-editor.org
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary=NextPart
Date: Wed, 23 Jul 2003 11:14:18 -0700
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart


A new Request for Comments is now available in online RFC libraries.


        RFC 3565

        Title:      Use of the Advanced Encryption Standard (AES)
                    Encryption Algorithm in Cryptographic Message
                    Syntax (CMS)
        Author(s):  J. Schaad
        Status:     Standards Track
        Date:       July 2003
        Mailbox:    jimsch@exmsft.com
        Pages:      14
        Characters: 26773
        Updates/Obsoletes/SeeAlso:  None

        I-D Tag:    draft-ietf-smime-aes-alg-07.txt

        URL:        ftp://ftp.rfc-editor.org/in-notes/rfc3565.txt


This document specifies the conventions for using the Advanced
Encryption Standard (AES) algorithm for encryption with the
Cryptographic Message Syntax (CMS).

This document is a product of the S/MIME Mail Security Working Group
of the IETF.

This is now a Proposed Standard Protocol.

This document specifies an Internet standards track protocol for
the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the
"Internet Official Protocol Standards" (STD 1) for the
standardization state and status of this protocol.  Distribution
of this memo is unlimited.

This announcement is sent to the IETF list and the RFC-DIST list.
Requests to be added to or deleted from the IETF distribution list
should be sent to IETF-REQUEST@IETF.ORG.  Requests to be
added to or deleted from the RFC-DIST distribution list should
be sent to RFC-DIST-REQUEST@RFC-EDITOR.ORG.

Details on obtaining RFCs via FTP or EMAIL may be obtained by sending
an EMAIL message to rfc-info@RFC-EDITOR.ORG with the message body 
help: ways_to_get_rfcs.  For example:

        To: rfc-info@RFC-EDITOR.ORG
        Subject: getting rfcs

        help: ways_to_get_rfcs

Requests for special distribution should be addressed to either the
author of the RFC in question, or to RFC-Manager@RFC-EDITOR.ORG.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.echo 
Submissions for Requests for Comments should be sent to
RFC-EDITOR@RFC-EDITOR.ORG.  Please consult RFC 2223, Instructions to RFC
Authors, for further information.


Joyce K. Reynolds and Sandy Ginoza
USC/Information Sciences Institute

...

Below is the data which will enable a MIME compliant Mail Reader 
implementation to automatically retrieve the ASCII version
of the RFCs.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type:  Message/External-body;
        access-type="mail-server";
        server="RFC-INFO@RFC-EDITOR.ORG"

Content-Type: text/plain
Content-ID: <030723111250.RFC@RFC-EDITOR.ORG>

RETRIEVE: rfc
DOC-ID: rfc3565

--OtherAccess
Content-Type:   Message/External-body;
        name="rfc3565.txt";
        site="ftp.isi.edu";
        access-type="anon-ftp";
        directory="in-notes"

Content-Type: text/plain
Content-ID: <030723111250.RFC@RFC-EDITOR.ORG>

--OtherAccess--
--NextPart--


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFEqt059450 for <ietf-smime-bks@above.proper.com>; Wed, 23 Jul 2003 11:15:14 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6NIFDAL059449 for ietf-smime-bks; Wed, 23 Jul 2003 11:15:13 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from gamma.isi.edu (gamma.isi.edu [128.9.144.145]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6NIFBqt059438 for <ietf-smime@imc.org>; Wed, 23 Jul 2003 11:15:12 -0700 (PDT) (envelope-from rfc-ed@ISI.EDU)
Received: from ISI.EDU (jet.isi.edu [128.9.160.87]) by gamma.isi.edu (8.11.6p2/8.11.2) with ESMTP id h6NICMJ08546; Wed, 23 Jul 2003 11:12:22 -0700 (PDT)
Message-Id: <200307231812.h6NICMJ08546@gamma.isi.edu>
To: IETF-Announce: ;
Subject: RFC 3560 on Use of the RSAES-OAEP Key Transport Algorithm in the Cryptographic Message Syntax (CMS)
Cc: rfc-editor@rfc-editor.org, ietf-smime@imc.org
From: rfc-editor@rfc-editor.org
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary=NextPart
Date: Wed, 23 Jul 2003 11:12:22 -0700
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart


A new Request for Comments is now available in online RFC libraries.


        RFC 3560

        Title:      Use of the RSAES-OAEP Key Transport Algorithm in
                    Cryptographic Message Syntax (CMS)
        Author(s):  R. Housley
        Status:     Standards Track
        Date:       July 2003
        Mailbox:    housley@vigilsec.com
        Pages:      18
        Characters: 37381
        Updates/Obsoletes/SeeAlso:  None

        I-D Tag:    draft-ietf-smime-cms-rsaes-oaep-07.txt

        URL:        ftp://ftp.rfc-editor.org/in-notes/rfc3560.txt


This document describes the conventions for using the RSAES-OAEP key
transport algorithm with the Cryptographic Message Syntax (CMS).  The
CMS specifies the enveloped-data content type, which consists of an
encrypted content and encrypted content-encryption keys for one or
more recipients.  The RSAES-OAEP key transport algorithm can be used
to encrypt content-encryption keys for intended recipients.

This document is a product of the S/MIME Mail Security Working Group
of the IETF.

This is now a Proposed Standard Protocol.

This document specifies an Internet standards track protocol for
the Internet community, and requests discussion and suggestions
for improvements.  Please refer to the current edition of the
"Internet Official Protocol Standards" (STD 1) for the
standardization state and status of this protocol.  Distribution
of this memo is unlimited.

This announcement is sent to the IETF list and the RFC-DIST list.
Requests to be added to or deleted from the IETF distribution list
should be sent to IETF-REQUEST@IETF.ORG.  Requests to be
added to or deleted from the RFC-DIST distribution list should
be sent to RFC-DIST-REQUEST@RFC-EDITOR.ORG.

Details on obtaining RFCs via FTP or EMAIL may be obtained by sending
an EMAIL message to rfc-info@RFC-EDITOR.ORG with the message body 
help: ways_to_get_rfcs.  For example:

        To: rfc-info@RFC-EDITOR.ORG
        Subject: getting rfcs

        help: ways_to_get_rfcs

Requests for special distribution should be addressed to either the
author of the RFC in question, or to RFC-Manager@RFC-EDITOR.ORG.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.echo 
Submissions for Requests for Comments should be sent to
RFC-EDITOR@RFC-EDITOR.ORG.  Please consult RFC 2223, Instructions to RFC
Authors, for further information.


Joyce K. Reynolds and Sandy Ginoza
USC/Information Sciences Institute

...

Below is the data which will enable a MIME compliant Mail Reader 
implementation to automatically retrieve the ASCII version
of the RFCs.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type:  Message/External-body;
        access-type="mail-server";
        server="RFC-INFO@RFC-EDITOR.ORG"

Content-Type: text/plain
Content-ID: <030723111047.RFC@RFC-EDITOR.ORG>

RETRIEVE: rfc
DOC-ID: rfc3560

--OtherAccess
Content-Type:   Message/External-body;
        name="rfc3560.txt";
        site="ftp.isi.edu";
        access-type="anon-ftp";
        directory="in-notes"

Content-Type: text/plain
Content-ID: <030723111047.RFC@RFC-EDITOR.ORG>

--OtherAccess--
--NextPart--


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6N0Woqt081045 for <ietf-smime-bks@above.proper.com>; Tue, 22 Jul 2003 17:32:50 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6N0Wo5U081044 for ietf-smime-bks; Tue, 22 Jul 2003 17:32:50 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from woodstock.binhost.com (woodstock.binhost.com [207.228.252.5]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6N0Wnqt081039 for <ietf-smime@imc.org>; Tue, 22 Jul 2003 17:32:49 -0700 (PDT) (envelope-from housley@vigilsec.com)
Received: (qmail 27722 invoked by uid 0); 23 Jul 2003 00:31:26 -0000
Received: from unknown (HELO Russ-Laptop.vigilsec.com) (12.159.173.193) by woodstock.binhost.com with SMTP; 23 Jul 2003 00:31:26 -0000
Message-Id: <5.2.0.9.2.20030722132917.035db820@mail.binhost.com>
X-Sender: housley@mail.binhost.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
Date: Tue, 22 Jul 2003 13:33:57 -0400
To: Tim Moses <tim.moses@entrust.com>, ietf-smime@imc.org
From: Russ Housley <housley@vigilsec.com>
Subject: Re: In this day and age ...
In-Reply-To: <9A4F653B0A375841AC75A8D17712B9C906494E3A@sottmxs04.entrust .com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Tim:

Please take a look at draft-ietf-smime-rfc2633bis-05.  I believe that you 
will see improvements in this area.

Russ

At 10:32 AM 7/18/2003 -0400, Tim Moses wrote:

>Colleagues - As I read RFC 2633, it uses normative language in Section 3.1
>when discussing content-transfer encoding applied to MIME content prior to
>security processing.  But, the language relating to content transfer
>encoding applied to protected content is not normative.  Section 3.2 says
>"Since CMS objects are binary data, in most cases base-64 transfer encoding
>is appropriate".  That sounds like a SHOULD.
>
>It seems to me that message-transfer agents commonly apply content-transfer
>encoding to 8-bit data.  I am unsure whether they do this selectively or
>whether they only apply it when needed.
>
>I wonder whether it is still necessary for S/MIME to "recommend" the
>application of content-transfer encoding to secured sub-parts.
>
>Can anyone offer an informed view?  Thanks a lot.  All the best.  Tim.
>
>-----------------------------------------------------------------
>Tim Moses
>613.270.3183



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6IEWnqt002964 for <ietf-smime-bks@above.proper.com>; Fri, 18 Jul 2003 07:32:49 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6IEWniC002963 for ietf-smime-bks; Fri, 18 Jul 2003 07:32:49 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sottmxssm.entrust.com (sottmxssm.entrust.com [216.191.252.10]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6IEWlqt002957 for <ietf-smime@imc.org>; Fri, 18 Jul 2003 07:32:48 -0700 (PDT) (envelope-from tim.moses@entrust.com)
Received: from sottguard01.entrust.com (sottguard01.entrust.com [10.4.61.249]) by sottmxssm.entrust.com (Switch-2.2.6/Switch-2.2.4) with SMTP id V6IE0T7N14914 for <ietf-smime@imc.org>; Fri, 18 Jul 2003 10:29:07 -0400
Received: (qmail 4724 invoked by uid 64014); 18 Jul 2003 14:26:50 -0000
Received: from tim.moses@entrust.com by sottguard01.entrust.com with AmikaGuardian-Server-1.1.2 (Processed in 0.255903 secs); 18 Jul 2003 14:26:50 -0000
Received: from unknown (HELO SOTTMXS01.entrust.com) (10.4.61.7) by sottguard01.entrust.com with SMTP; 18 Jul 2003 14:26:49 -0000
Received: by sottmxs01.entrust.com with Internet Mail Service (5.5.2656.59) id <PFK4KBA4>; Fri, 18 Jul 2003 10:32:42 -0400
Message-ID: <9A4F653B0A375841AC75A8D17712B9C906494E3A@sottmxs04.entrust.com>
From: Tim Moses <tim.moses@entrust.com>
To: "'S/MIME'" <ietf-smime@imc.org>
Subject: In this day and age ...
Date: Fri, 18 Jul 2003 10:32:41 -0400
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2656.59)
Content-Type: text/plain; charset="iso-8859-1"
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Colleagues - As I read RFC 2633, it uses normative language in Section 3.1
when discussing content-transfer encoding applied to MIME content prior to
security processing.  But, the language relating to content transfer
encoding applied to protected content is not normative.  Section 3.2 says
"Since CMS objects are binary data, in most cases base-64 transfer encoding
is appropriate".  That sounds like a SHOULD.

It seems to me that message-transfer agents commonly apply content-transfer
encoding to 8-bit data.  I am unsure whether they do this selectively or
whether they only apply it when needed.

I wonder whether it is still necessary for S/MIME to "recommend" the
application of content-transfer encoding to secured sub-parts.

Can anyone offer an informed view?  Thanks a lot.  All the best.  Tim.

-----------------------------------------------------------------
Tim Moses
613.270.3183


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6I32aqt042434 for <ietf-smime-bks@above.proper.com>; Thu, 17 Jul 2003 20:02:36 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6I32Z8r042433 for ietf-smime-bks; Thu, 17 Jul 2003 20:02:35 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6I32Yqt042412; Thu, 17 Jul 2003 20:02:34 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Thu, 17 Jul 2003 20:02:31 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <jimsch@exmsft.com>, "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>, "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Thu, 17 Jul 2003 20:02:31 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAg6Sc0IFlH0m+phfIjZYjNAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <001301c34c2c$c04b2cd0$8b40a051@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Jim Schaad
> Sent: Wednesday, July 16, 2003 11:29 PM
> To: 'Blake Ramsdell'; jimsch@exmsft.com; 
> 'Ietf-Smime-Examples'; ietf-smime@imc.org; phoffman@imc.org
> Cc: 'Sean P. Turner'; 'Russ Housley'
> Subject: RE: Draft-11Parital Results
> 
> What needs to
> be changed is the commentary not the message.

OK, then we need to come up with language.  Maybe:

A full S/MIME message, including MIME, that includes a MIME encoded
version of the body part from 5.1.

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6HBMhqt084239 for <ietf-smime-bks@above.proper.com>; Thu, 17 Jul 2003 04:22:44 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6HBMhJg084238 for ietf-smime-bks; Thu, 17 Jul 2003 04:22:43 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp002.bizmail.yahoo.com (smtp002.bizmail.yahoo.com [216.136.172.126]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6HBMgqt084233 for <ietf-smime@imc.org>; Thu, 17 Jul 2003 04:22:42 -0700 (PDT) (envelope-from turners@ieca.com)
Received: from tweety.ietf57.telekom.at (HELO ieca.com) (turners@ieca.com@81.160.172.151 with plain) by smtp2.bm.vip.sc5.yahoo.com with SMTP; 17 Jul 2003 11:22:33 -0000
Message-ID: <3F1686C5.2040405@ieca.com>
Date: Thu, 17 Jul 2003 13:21:41 +0200
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: SMIME <ietf-smime@imc.org>
Subject: SMIME WG Summary
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <title></title>
</head>
<body>
All,<br>
<br>
Here is a short summary of the agenda topics discussed at the meeting in
Austria:<br>
<br>
* MSGbis fixed some nits believe it is ready for security ADs and IETF-wide
last call<br>
* CERTbis text needs to be added for acknowledgements but after that it's
ready for security ADs and IETF-wide last call<br>
* Examples added 11 new cases all need to be verified<br>
* X400Trans and X400Wrap had minor comments from IESG, which have all been
addressed<br>
* Interoperability Matrix is completed but final report needs to be written<br>
* RSA PSS and CMS going to WG LC as soon as next version is produced<br>
* RSA KEM has 3 remaining issues but then ready for WG LC<br>
* ESSbis separating MLExpansiionHistory in to ReceiptBehavior and MLLoopDetection
is proving more difficult than expected<br>
* GOST algorithm for CMS will be published under WG<br>
* Peter Sylvester gave a presentation on OpenEvidence<br>
* Tim Polk gave pointers to NIST's Online SMIME tester<br>
<br>
 I hope to have meeting minutes out by next week some time.<br>
<br>
spt
</body>
</html>



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6H6Spqt044447 for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 23:28:51 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6H6SpRX044446 for ietf-smime-bks; Wed, 16 Jul 2003 23:28:51 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6H6Smqt044426; Wed, 16 Jul 2003 23:28:48 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139]) by smtp1.pacifier.net (Postfix) with ESMTP id F1EB670450; Wed, 16 Jul 2003 23:28:45 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <jimsch@exmsft.com>, "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>, "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Thu, 17 Jul 2003 08:29:14 +0200
Message-ID: <001301c34c2c$c04b2cd0$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbHTrol9BRUa93ZPzwMATPQEAAAAA@brutesquadlabs.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake,

I completely agree that it was discussed.  (I think I raised the issue.)
And I agree that the content for the message is correct.  What needs to
be changed is the commentary not the message.

jim

> -----Original Message-----
> From: Blake Ramsdell [mailto:blake@brutesquadlabs.com] 
> Sent: Wednesday, July 16, 2003 10:15 PM
> To: jimsch@exmsft.com; 'Ietf-Smime-Examples'; 
> ietf-smime@imc.org; phoffman@imc.org
> Cc: 'Sean P. Turner'; 'Russ Housley'
> Subject: RE: Draft-11Parital Results
> 
> 
> > -----Original Message-----
> > From: Jim Schaad [mailto:jimsch@nwlink.com]
> > Sent: Wednesday, July 16, 2003 7:19 AM
> > To: Ietf-Smime-Examples; ietf-smime@imc.org; phoffman@imc.org
> > Cc: Sean P. Turner; Blake Ramsdell; Russ Housley
> > Subject: Draft-11Parital Results
> > 
> > 5.9  failed 
> > 	Commentary text states that the body part is the same 
> as 5.1 - this 
> > is not correct as the signature values and exContent are different
> > (content is actually "\0xd\0xaThis is some sample content."
> 
> This is something we discussed a bit ago -- the problem is 
> that ExContent.bin is not valid MIME data.  The compromise we 
> reached was that a CRLF would be inserted at the beginning, 
> which would make it valid MIME data (implicit text/plain).  
> When the MIME wrapping is removed, it results in ExContent.bin.
> 
> Blake
> 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GKFLqt005616 for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 13:15:21 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6GKFLSH005615 for ietf-smime-bks; Wed, 16 Jul 2003 13:15:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GKFKqt005608; Wed, 16 Jul 2003 13:15:20 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Wed, 16 Jul 2003 13:15:16 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <jimsch@exmsft.com>, "'Ietf-Smime-Examples'" <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>, "'Russ Housley'" <housley@vigilsec.com>
Subject: RE: Draft-11Parital Results
Date: Wed, 16 Jul 2003 13:15:16 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbHTrol9BRUa93ZPzwMATPQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <000e01c34ba5$38ac5150$8b40a051@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: Jim Schaad [mailto:jimsch@nwlink.com] 
> Sent: Wednesday, July 16, 2003 7:19 AM
> To: Ietf-Smime-Examples; ietf-smime@imc.org; phoffman@imc.org
> Cc: Sean P. Turner; Blake Ramsdell; Russ Housley
> Subject: Draft-11Parital Results
> 
> 5.9  failed 
> 	Commentary text states that the body part is the same as 5.1 -
> this is not correct as the signature values and exContent are 
> different
> (content is actually "\0xd\0xaThis is some sample content."

This is something we discussed a bit ago -- the problem is that
ExContent.bin is not valid MIME data.  The compromise we reached was
that a CRLF would be inserted at the beginning, which would make it
valid MIME data (implicit text/plain).  When the MIME wrapping is
removed, it results in ExContent.bin.

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GEIfqt083989 for <ietf-smime-bks@above.proper.com>; Wed, 16 Jul 2003 07:18:41 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6GEIf1w083988 for ietf-smime-bks; Wed, 16 Jul 2003 07:18:41 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.173]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6GEIdqt083974; Wed, 16 Jul 2003 07:18:39 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139]) by smtp3.pacifier.net (Postfix) with ESMTP id 5F87E6DF25; Wed, 16 Jul 2003 07:18:37 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "Ietf-Smime-Examples" <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>, <phoffman@imc.org>
Cc: "Sean P. Turner" <turners@ieca.com>, "Blake Ramsdell" <blake@brutesquadlabs.com>, "Russ Housley" <housley@vigilsec.com>
Subject: Draft-11Parital Results
Date: Wed, 16 Jul 2003 16:19:04 +0200
Message-ID: <000e01c34ba5$38ac5150$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6GEIdqt083975
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

People,

Here is the current state of draft 11 with my testing.  I will continue
to fill out more of the data in the this table as I get some more items
debugged in my code.  I am still trying to figure out why I cannot do
DH.

jim


4.1 	pass
4.2	pass
5.1	pass
5.2	pass
5.3  -- not checked ---
5.4	pass with comments
	1.  certificates are Alice DSS, Carl DSS (root), Alice RSA
	2.  unsigned attributes are JUST counter signature
5.5	pass
5.6	--- not checked --  - structurally fine - Diane signature
unchecked
5.7  	pass
5.8  -- not checked --
	I have an assumption that the wrong signature OID is used in the
message.
5.9  failed 
	id-dsa is the signature algorithm not id-dsa-with-sha1
	Commentary text states that the body part is the same as 5.1 -
this is not correct as the signature values and exContent are different
(content is actually "\0xd\0xaThis is some sample content."
5.10  pass with comments
	List of attributes is
		1. content type
		2. message digest
		3. 1.2.5555 (unknown)
		4. content hint
		5. smime capabilities
		6. security label
		7. content reference
		8. encrypt key preference
		9. ML expansion history
		10. Equivalent label
5.11 	pass with comments
	Text should be Alice's and Carl's DSS certificates.

6.1	-- not checked --
6.2	passed
6.3 	passed with comments
	RC2/128 for the content encryption algorithm.
6.4	-- not checked --
6.5 	-- not checked --
6.6 	-- not checked --
6.7	-- not checked -- fail on the RC2/40 not clear what the source
is yet.
6.8	-- not checked --
6.9	failed
	Content hints says the content is 1.2.6.5.4 not id-data
6.10	-- not checked --
6.11	FAIL
	test vectors are appended below on this message.  I don't know
where I am going wrong and this code worked in the past.

7.0	pass

8.1	passed
8.2	passed with comment
	Need to specify that this uses the same key value as does 8.1

9	-- checked--

10.1	-- not checked --
10.2	-- not checked --


11.1	fails
	Text states signed with RSA, message signed with DSA
	DSA signature OID incorrect
	Receipt is going to cn="AliceRSA" and robert.colestock@wang.com
- should alice be an RFC822 name?
11.2	-- not checked --
11.3  passed
11.4  passed
11.5  -- not checked -- 
11.6 	-- not checked --


**************************************** 6.11 intermediate data from my
test ****************
But it fails....

Wrapped key
0x0012F248  74 31 c0 45 51 4c 3c 2d 2e da 63 50 8b ae d4 ac
t1ÀEQL<-.ÚcP.®Ô¬
0x0012F258  64 cc 95 ae af cd 0f 8c b6 48 1f 0b 45 12 4d fb
dÌ.®¯Í..¶H..E.M.
0x0012F268  a4 ab c7 83 30 4b 69 ad                         ¤«Ç.0Ki­

Mail list key
0x00324354  25 5e 0d 1c 07 b6 46 df b3 13 4c c8 43 ba 8a a7
%^...¶Fß³.LÈCº.§
0x00324364  1f 02 5b 7c 08 38 25 1f

After decrypt #1
0x00324630  d7 10 66 ee 9a 42 e0 80 62 a3 e5 de b5 ef 4e 7e
×.f..B..b£.Þµ.N~
0x00324640  5f 13 30 b5 13 d3 a8 4f be dc 02 d4 81 27 db 50
_.0µ.Ó¨O¾Ü.Ô.'ÛP
0x00324650  e5 d8 0f e9 25 38 f1 7b                         .Ø..%8.{

IV
0x00324630  7b f1 38 25 e9 0f d8 e5                         {.8%..Ø.

Post Decrypt #2
0x00324630  50 db 27 81 d4 02 dc be 4f a8 d3 13 b5 30 13 5f
PÛ'.Ô.Ü¾O¨Ó.µ0._
0x00324640  7e 4e ef b5 de e5 a3 62 80 e0 42 9a ee 66 10 d7
~N.µÞ.£b..B..f.×

Computed check sum
0x0012EFD8  53 fb 3e cc 8a 06 cc af                         S.>Ì..Ì¯

Actual Check sum
 80 e0 42 9a ee 66 10 d7

--- they don't match!!!!!




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FDR1qt079641 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:27:01 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6FDR136079640 for ietf-smime-bks; Tue, 15 Jul 2003 06:27:01 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mail4.consignia.com (mail4.consignia.com [144.87.143.84]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FDR0qt079635 for <ietf-smime@imc.org>; Tue, 15 Jul 2003 06:27:00 -0700 (PDT) (envelope-from chris.gilbert@royalmail.com)
Received: from postoffice.co.uk (mta2.int.consignia.com [144.87.146.16]) by mail4.consignia.com (Postfix) with SMTP id 42CDF12278B for <ietf-smime@imc.org>; Tue, 15 Jul 2003 14:27:00 +0100 (BST)
Received: by postoffice.co.uk(Lotus SMTP MTA v4.6.6  (890.1 7-16-1999))  id 00256D64.004F63F6 ; Tue, 15 Jul 2003 14:27:09 +0000
X-Lotus-FromDomain: POSTOFFICE
From: chris.gilbert@royalmail.com
To: ietf-smime@imc.org
Message-ID: <00256D64.004F61C7.00@postoffice.co.uk>
Date: Tue, 15 Jul 2003 14:26:44 +0000
Subject: Re: (Practical) S/MIME certificate chain handling
Mime-Version: 1.0
Content-type: text/plain; charset=us-ascii
Content-Disposition: inline
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Jim,

apologies for the delay. I've been on vacation and have just salvaged
your email from the 800 or so spams that were waiting for me :-) I also
got over enthusiastic about my mail box management and succeeded in
deleting the original of this. The headers are munged because I recovered
this text from the IETF archive!

Jim Schaad wrote:

> I hope there is a great deal more to this than what you are stating for
> a Best Practice recommendation.

Indeed. I did say it was 'a' recommendation without alluding to the
others, some of which concern the management of the root CA certificate
store.

> 1.  Acceptance of root certificates by end-users is a real problem.
> They tend to say yes without any good reason to do so.  This means that
> it is easy to stick "bad" root certificates on a persons machine

I agree completely. At the organisation level, however, the management
of the Root CA store is a administrative policy issue rather than a
technical one. The inclusion of the trust chain with outgoing emails
facilitates the distribution of trust in the continued absence of a
global recovery mechanism. It does not preclude correct and secure usage
of such paths, in-line with policy, at the recipient device.

> If you are really working in a single structure, then this information
> should be automatically distributed to people's machines and not send
> from the sender.

By a single structure do you mean a single organisation or a single
trust tree ? Policy should certainly be managed centrally although I'm
unconvinced that many organisations really understand the future,
legal implications of permitting their end-users to grow their own Root
CA stores. As you imply, we are not yet anywhere near widespread, correct
usage. In the main this is due to the fact that Digital Certificates are
still being used in many areas merely as technology enablers rather than
the trust mechanisms that they are designed to be. As such, acceptance of
trust (and thus liability) by end users is too easy and uncontrolled and
simply allows the software to work rather than trust be maintained.

Chris


Royal Mail is a trading name of Royal Mail Group plc. Registered in England and
Wales.
Registered number 4138203. Registered office at 148 Old Street, LONDON EC1V 9HQ




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD99qt077311 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:09:09 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6FD9949077310 for ietf-smime-bks; Tue, 15 Jul 2003 06:09:09 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD98qt077301 for <ietf-smime@imc.org>; Tue, 15 Jul 2003 06:09:08 -0700 (PDT) (envelope-from capel@comgate.com)
Received: from mail1.magma.ca (mail1.magma.ca [206.191.0.252]) by mx2.magma.ca Magma's Mail Server with ESMTP id h6FD97Nq017320; Tue, 15 Jul 2003 09:09:07 -0400
Received: from tony (ottawa-hs-209-217-122-183.s-ip.magma.ca [209.217.122.183]) by mail1.magma.ca (Magma's Mail Server) with ESMTP id h6FD8qFU023765; Tue, 15 Jul 2003 09:09:07 -0400
From: "Tony Capel" <capel@comgate.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Subject: RE: Discussing RTCS
Date: Tue, 15 Jul 2003 09:08:56 -0400
Message-ID: <000601c34ad2$42a0ae00$01b5a8c0@tony>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4510
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h6FD98qt077304
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake:

I see potential value in a "CMS style" request/response format for a
certificate validation service.

Specifically one might imagine that a (signed) CMS data structure returned
by a validating server could be integrated directing within the CMS message
types.  This would require compatibility between the server response and
CMS.

I realise that Peter's proposal makes a big deal about its ability to use
simplified database lookups, yes/no responses, etc. and that this aspect has
prompted strong PKIX reactions.

However, the ability to use directly compatible CMS structures is the
attraction for me.  How the server is implemented is arguably an
implementation (or maybe PKIX) issue.

So, yes I would like to see some discussion on this topic here; and if
Peter's proposal is a way to do that fine - although I agree that if we
discuss it, we should do it co-operatively with PKIX.  That is, we should
address CMS compatibility issues (and how this service might be used by CMS)
and leave the server side to them.

Tony

| -----Original Message-----
| From: owner-ietf-smime@mail.imc.org 
| [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
| Sent: June 27, 2003 5:12 PM
| To: ietf-smime@imc.org
| Subject: Discussing RTCS
| 
| 
| 
| Peter Gutmann has made an individual draft submission for his 
| CMS-based RTCS protocol.  A URL to this draft is:
| 
http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt

He would like to get some review of the CMS parts of this, and it seems
reasonable to discuss it here on the IETF-SMIME list if there is interest.

Since this draft is CMS based and potentially adds value to CMS or S/MIME in
general, should we consider bringing it into this working group?

Comments?

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 





Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD10qt075190 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 06:01:00 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6FD102r075189 for ietf-smime-bks; Tue, 15 Jul 2003 06:01:00 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from aragorn.bbn.com (aragorn.bbn.com [128.33.0.62]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FD0vqt075145; Tue, 15 Jul 2003 06:00:58 -0700 (PDT) (envelope-from kent@bbn.com)
Received: from [81.160.154.187] (ssh.bbn.com [192.1.50.70]) by aragorn.bbn.com (8.12.7/8.12.7) with ESMTP id h6FCxwDD029536; Tue, 15 Jul 2003 09:00:07 -0400 (EDT)
Mime-Version: 1.0
X-Sender: kent@localhost
Message-Id: <p05200f04bb39a7534e0a@[81.160.154.187]>
In-Reply-To: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
References: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
Date: Tue, 15 Jul 2003 08:46:24 -0400
To: <jimsch@exmsft.com>
From: Stephen Kent <kent@bbn.com>
Subject: RE: Discussing RTCS
Cc: "'Denis Pinkas'" <Denis.Pinkas@bull.net>, "'Sean P. Turner'" <turners@ieca.com>, <ietf-smime@imc.org>, "'pkix'" <ietf-pkix@imc.org>
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
X-Scanned-By: MIMEDefang 2.28 (www . roaringpenguin . com / mimedefang)
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

At 11:30 +0200 7/15/03, Jim Schaad wrote:
>I agree with Denis, this is a certificate validation issue and as such
>belongs in the PKIX WG if to be standardized by the IETF.  I think that
>we can provide a review of the document if requested for it's usage of
>CMS, but not it's general suitablity.
>
>jim
>

Jim,

I agree with you and Denis that this is really a PKIX matter, vs. an 
S/MIME matter. However, I had several problems with Peter bringing 
this in as a WG item:
	- we already have OCSP and OCSPv2 has been worked on

	- this protocol goes beyond the OCSP semantics to provide 
delegated cert (not cert path) validation. we have just agreed to 
adopt SCVP for delegated cert path validation, and I was worried that 
this overlap would conflict with SCVP

	- PKIX has been told to not take on new work items


Steve


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FB3Oqt063647 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 04:03:24 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6FB3O9p063646 for ietf-smime-bks; Tue, 15 Jul 2003 04:03:24 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz (hermes.cs.auckland.ac.nz [130.216.35.151]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6FB3Lqt063633; Tue, 15 Jul 2003 04:03:22 -0700 (PDT) (envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6FB2YYM012981; Tue, 15 Jul 2003 23:02:34 +1200
Received: (from pgut001@localhost) by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6FB2We15157; Tue, 15 Jul 2003 23:02:32 +1200
Date: Tue, 15 Jul 2003 23:02:32 +1200
Message-Id: <200307151102.h6FB2We15157@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: Denis.Pinkas@bull.net, turners@ieca.com
Subject: Re: Discussing RTCS
Cc: ietf-pkix@imc.org, ietf-smime@imc.org
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Denis Pinkas <Denis.Pinkas@bull.net> writes:

>This is a topic to be addressed by the PKIX WG, not by the SMIME WG.

We already tried that, but you made sure it wouldn't work.

For those who aren't on the PKIX list, a short summary:

- Denis has some sort of rabid opposition to what RTCS does.  I had private
  mail from another PKIX member to say that RTCS' crime is that it provides a
  basic yes/no response rather than a CRL-style revoked/not revoked/maybe/
  maybe not response.  Someone else thought that it was because it made OCSP
  look bad.  I'm not sure what it really is.

- The result of this was a series of increasingly hysterical attacks by Denis
  on RTCS, using every reason he could dream up (see the PKIX list from late
  last year some time).  The highlights were him posting several messages in
  which he quoted sections of text and claimed the exact opposite of what the
  text said.  In one message I got a quote of him saying something wasn't
  possible, after which I had another quote of him saying the exact opposite
  earlier on.  You get the idea... the debate wasn't very coherent, or useful,
  except perhaps for amusement value.

- When his hissy fit on the list failed, he tried a private appeal to the WG
  chair to get it killed.

- The only (unfortunate) effect of his fit was that it drove most of the
  discussion into private mail, because no-one (apart from me apparently :-)
  wanted to become the target of his attacks.  I did, however, get some good
  feedback, which made it into the new draft.

So because of Denis it isn't really possible to have any coherent discussion
on the PKIX list.  My last message to him on that list was:

  It's obvious from your messages (and others have commented on this as well)
  that you've barely read the RTCS draft (if at all), and even then only to
  pick out bits to complain about.  The posting of obviously incorrect claims
  such as the ones cited above aren't helping your credibility much either.

As the next sentence from his current post shows:

  The advantages of this new protocol versus draft-ietf-pkix-ocspv2-ext-01.txt
  (Online Certificate Status Protocol, version 2) and the differences should
  be first explained.

he still hasen't actually read the draft.  Hint for Denis: The answer to your
question is in Section 2, right after the Abstract, which is section 1.  I'm
now pointing this out for the third (or fourth) time, but I doubt it'll make
any difference.

So to summarise: Denis has some sort of strong religious objection to RTCS.
He will engage in whatever hysterics he thinks necessary to attack it.  If
anyone wants to see the rest, see the PKIX thread on this (or wait for Denis'
next message).

Peter (sorry for the sarcasm and whatnot, but I was hoping he'd finalled given
       up after the last time... it's like listening to a broken record.  In
       the meantime, as ever, I welcome constructive feedback on RTCS).


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F9UUqt055338 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 02:30:30 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6F9UUq2055337 for ietf-smime-bks; Tue, 15 Jul 2003 02:30:30 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.174]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F9USqt055320; Tue, 15 Jul 2003 02:30:28 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (unknown [81.160.64.139]) by smtp4.pacifier.net (Postfix) with ESMTP id 9023D6A9C8; Tue, 15 Jul 2003 02:08:03 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Denis Pinkas'" <Denis.Pinkas@bull.net>, "'Sean P. Turner'" <turners@ieca.com>
Cc: <ietf-smime@imc.org>, "'pkix'" <ietf-pkix@imc.org>
Subject: RE: Discussing RTCS
Date: Tue, 15 Jul 2003 11:30:53 +0200
Message-ID: <000301c34ab3$cb30a4b0$8b40a051@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
In-Reply-To: <3F13BB30.4030906@bull.net>
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

I agree with Denis, this is a certificate validation issue and as such
belongs in the PKIX WG if to be standardized by the IETF.  I think that
we can provide a review of the document if requested for it's usage of
CMS, but not it's general suitablity.

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Denis Pinkas
> Sent: Tuesday, July 15, 2003 10:29 AM
> To: Sean P. Turner
> Cc: ietf-smime@imc.org; pkix
> Subject: Re: Discussing RTCS
> 
> 
> 
> Sean,
> 
> > Does anyone have an opinion on bringing this to the working group?
> 
> This is a topic to be addressed by the PKIX WG, not by the SMIME WG.
> 
> The PKIX WG is attempting (but not always succeeding) to 
> avoid duplication 
> of protocols for the same topic.
> 
> We all know that it would have been better to use CMS for 
> building the OCSP 
>   protocol, but this was not the case.
> 
> The advantages of this new protocol versus 
> draft-ietf-pkix-ocspv2-ext-01.txt 
> (Online Certificate Status Protocol, version 2) and the 
> differences should 
> be first explained.
> 
> Denis
> 
> 
> > spt
> > 
> > Blake Ramsdell wrote:
> > 
> >>Peter Gutmann has made an individual draft submission for his 
> >>CMS-based RTCS protocol.  A URL to this draft is:
> >>
> >>http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt
> >>
> >>He would like to get some review of the CMS parts of this, and it 
> >>seems reasonable to discuss it here on the IETF-SMIME list 
> if there is 
> >>interest.
> >>
> >>Since this draft is CMS based and potentially adds value to CMS or 
> >>S/MIME in general, should we consider bringing it into this working 
> >>group?
> >>
> >>Comments?
> >>
> >>Blake
> >>--
> >>Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com
> >>
> >>  
> >>
> > 
> 
> 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F8Suqt045009 for <ietf-smime-bks@above.proper.com>; Tue, 15 Jul 2003 01:28:56 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6F8SuZL045008 for ietf-smime-bks; Tue, 15 Jul 2003 01:28:56 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from odin2.bull.net (odin2.bull.net [192.90.70.84]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6F8Shqt044980; Tue, 15 Jul 2003 01:28:44 -0700 (PDT) (envelope-from Denis.Pinkas@bull.net)
Received: from clbull.frcl.bull.fr (IDENT:root@clbull.frcl.bull.fr [129.182.8.31]) by odin2.bull.net (8.9.3/8.9.3) with ESMTP id KAA37988; Tue, 15 Jul 2003 10:33:13 +0200
Received: from bull.net (frcls4013.frcl.bull.fr [129.182.108.120]) by clbull.frcl.bull.fr (8.9.3/8.9.3) with ESMTP id KAA06126; Tue, 15 Jul 2003 10:28:44 +0200
Message-ID: <3F13BB30.4030906@bull.net>
Date: Tue, 15 Jul 2003 10:28:32 +0200
From: Denis Pinkas <Denis.Pinkas@bull.net>
Organization: Bull SA.
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
X-Accept-Language: en-us, en, fr
MIME-Version: 1.0
To: "Sean P. Turner" <turners@ieca.com>
CC: ietf-smime@imc.org, pkix <ietf-pkix@imc.org>
Subject: Re: Discussing RTCS
References: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com> <3F1283C0.50402@ieca.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Sean,

> Does anyone have an opinion on bringing this to the working group?

This is a topic to be addressed by the PKIX WG, not by the SMIME WG.

The PKIX WG is attempting (but not always succeeding) to avoid duplication 
of protocols for the same topic.

We all know that it would have been better to use CMS for building the OCSP 
  protocol, but this was not the case.

The advantages of this new protocol versus draft-ietf-pkix-ocspv2-ext-01.txt 
(Online Certificate Status Protocol, version 2) and the differences should 
be first explained.

Denis


> spt
> 
> Blake Ramsdell wrote:
> 
>>Peter Gutmann has made an individual draft submission for his CMS-based
>>RTCS protocol.  A URL to this draft is:
>>
>>http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt
>>
>>He would like to get some review of the CMS parts of this, and it seems
>>reasonable to discuss it here on the IETF-SMIME list if there is
>>interest.
>>
>>Since this draft is CMS based and potentially adds value to CMS or
>>S/MIME in general, should we consider bringing it into this working
>>group?
>>
>>Comments?
>>
>>Blake
>>--
>>Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 
>>
>>  
>>
> 




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EB4Pqt063044 for <ietf-smime-bks@above.proper.com>; Mon, 14 Jul 2003 04:04:25 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6EB4PIe063043 for ietf-smime-bks; Mon, 14 Jul 2003 04:04:25 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EB4Oqt063036; Mon, 14 Jul 2003 04:04:24 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Mon, 14 Jul 2003 04:04:19 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: "'Paul Hoffman / IMC'" <phoffman@imc.org>, <ietf-smime-examples@imc.org>, <ietf-smime@imc.org>
Subject: RE: Status of the examples draft
Date: Mon, 14 Jul 2003 04:04:19 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAY/4vlI401kmhQPHeOHCC0gEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <p05210609bb28ab8d2f11@[63.202.92.152]>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Paul Hoffman / IMC
> Sent: Wednesday, July 02, 2003 8:44 AM
> To: ietf-smime-examples@imc.org; ietf-smime@imc.org
> Subject: Status of the examples draft
> 
> Hi again. The -11 draft has the following changes:

The comments that I posted regarding the -10 draft stand for the -11
draft, and I have included them below for completeness.

The only thing that I've had trouble with so far is 5.6.bin appears to
have changed the order of the SignerInfos.  I don't believe that this
change is relevant, so I don't think there needs to be any modification
of the draft.

The files I have worked with:

5.1.bin -- Identified as a CMS SignedData with signatures and content,
checked certificates were present, matched content to ExContent.bin,
verified one signer

5.2.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.3.bin -- Identified as a CMS SignedData with signatures and no
content, checked certificates were present, verified one signer against
external content in ExContent.bin

5.4.bin -- Extracted signing time attribute, checked certificates were
present, checked CRLs were present, matched content to ExContent.bin,
verified one signer

5.5.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.6.bin -- Checked certificates were present, matched content to
ExContent.bin, verified two signers

5.7.bin -- Checked certificates were present, matched content to
ExContent.bin, verified one signer

5.8.eml -- Parsed content with MIME parser, matched extracted text
content from text part to ExContent.bin, checked certificates were
present, verified one signer against first part of message, identified
as a CMS SignedData with signatures and no content

5.9.eml -- Parsed content with MIME parser, matched extracted text
content from text part to ExContent.bin, checked certificates were
present, verified one signer, identified as a CMS SignedData with
signatures and content

5.10.bin -- Matched content to ExContent.bin, verified one signer

5.11.bin -- Identified as a CMS SignedData with no signatures and no
content, checked certificates were present

6.2.bin -- Decrypted message, matched content to ExContent.bin,
identified as a CMS EnvelopedData

6.3.bin -- Decrypted message, matched content to ExContent.bin

7.0.bin -- Verified hash, matched content to ExContent.bin

8.1.bin -- Decrypted data with given key, matched content to
ExContent.bin


I also worked with the following certificates and private keys:

AliceDSSSignByCarlNoInherit.cer
AlicePrivRSASign.pri
AliceRSASignByCarl.cer
BobPrivRSAEncrypt.pri
BobRSASignByCarl.cer
CarlDSSCRLForAll.crl
CarlDSSSelf.cer
CarlPrivDSSSign.pri
CarlPrivRSASign.pri
CarlRSASelf.cer
DianeDHEncryptByCarl.cer
DianeDSSSignByCarlInherit.cer
DianePrivRSASignEncrypt.pri
DianeRSASignByCarl.cer
EricaDHEncryptByCarl.cer

Blake



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h6EAJtqt059596 for <ietf-smime-bks@above.proper.com>; Mon, 14 Jul 2003 03:19:55 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h6EAJtis059595 for ietf-smime-bks; Mon, 14 Jul 2003 03:19:55 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp002.bizmail.yahoo.com (smtp002.bizmail.yahoo.com [216.136.172.126]) by above.proper.com (8.12.9/8.12.8) with SMTP id h6EAJqqt059588 for <ietf-smime@imc.org>; Mon, 14 Jul 2003 03:19:54 -0700 (PDT) (envelope-from turners@ieca.com)
Received: from tweety.ietf57.telekom.at (HELO ieca.com) (turners@ieca.com@81.160.152.206 with plain) by smtp2.bm.vip.sc5.yahoo.com with SMTP; 14 Jul 2003 10:19:52 -0000
Message-ID: <3F1283C0.50402@ieca.com>
Date: Mon, 14 Jul 2003 12:19:44 +0200
From: "Sean P. Turner" <turners@ieca.com>
Organization: IECA, Inc.
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: ietf-smime@imc.org
Subject: Re: Discussing RTCS
References: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com>
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1">
  <title></title>
</head>
<body>
Does anyone have an opinion on bringing this to the working group?<br>
<br>
spt<br>
<br>
Blake Ramsdell wrote:<br>
<blockquote type="cite"
 cite="mid!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAW78oSlo46k69IkJ+uWj+gQEAAAAA@brutesquadlabs.com">
  <pre wrap="">Peter Gutmann has made an individual draft submission for his CMS-based
RTCS protocol.  A URL to this draft is:

<a class="moz-txt-link-freetext" href="http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt">http://www.ietf.org/internet-drafts/draft-gutmann-cms-rtcs-00.txt</a>

He would like to get some review of the CMS parts of this, and it seems
reasonable to discuss it here on the IETF-SMIME list if there is
interest.

Since this draft is CMS based and potentially adds value to CMS or
S/MIME in general, should we consider bringing it into this working
group?

Comments?

Blake
--
Blake Ramsdell | Brute Squad Labs | <a class="moz-txt-link-freetext" href="http://www.brutesquadlabs.com">http://www.brutesquadlabs.com</a> 

  </pre>
</blockquote>
<br>
</body>
</html>



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h69Mcpqt027896 for <ietf-smime-bks@above.proper.com>; Wed, 9 Jul 2003 15:38:51 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h69McpYO027895 for ietf-smime-bks; Wed, 9 Jul 2003 15:38:51 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h69Mcoqt027889 for <ietf-smime@imc.org>; Wed, 9 Jul 2003 15:38:50 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Wed, 9 Jul 2003 15:38:46 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <agenda@ietf.org>, <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>
Subject: REVISED S/MIME Working Group Agenda for the 57th IETF
Date: Wed, 9 Jul 2003 15:38:46 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAA52UkwHJaDUG5RUF2X5K+BQEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Revised agenda for the S/MIME working group meeting at IETF 57.

Introductions                     (Sean Turner)
Working group status              (Sean Turner)
CMS and ESS examples update       (Paul Hoffman)
MSGbis and CERTbis update         (Blake Ramsdell)
X400Wrap and X400Transport update (Chris Bonatti)
Interoperability matrix update    (Jim Schaad)
PSS status                        (Jim Schaad)
KEM overview                      (Jim Schaad)
ESSbis overview                   (Jim Schaad)
GOST overview                     (Gregory S. Chudov)
Project OpenEvidence and ESS      (Peter Sylvester)
Wrap up                           (Sean Turner)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h69ENlqt098848 for <ietf-smime-bks@above.proper.com>; Wed, 9 Jul 2003 07:23:47 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h69ENlri098847 for ietf-smime-bks; Wed, 9 Jul 2003 07:23:47 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from odin2.bull.net (odin2.bull.net [192.90.70.84]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h69ENiqt098836; Wed, 9 Jul 2003 07:23:45 -0700 (PDT) (envelope-from Denis.Pinkas@bull.net)
Received: from clbull.frcl.bull.fr (IDENT:root@clbull.frcl.bull.fr [129.182.8.31]) by odin2.bull.net (8.9.3/8.9.3) with ESMTP id QAA33082; Wed, 9 Jul 2003 16:28:17 +0200
Received: from bull.net (frcls4013.frcl.bull.fr [129.182.108.120]) by clbull.frcl.bull.fr (8.9.3/8.9.3) with ESMTP id QAA07578; Wed, 9 Jul 2003 16:23:47 +0200
Message-ID: <3F0C256D.3090300@bull.net>
Date: Wed, 09 Jul 2003 16:23:41 +0200
From: Denis Pinkas <Denis.Pinkas@bull.net>
Organization: Bull SA.
User-Agent: Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0
X-Accept-Language: en-us, en, fr
MIME-Version: 1.0
To: pkix <ietf-pkix@imc.org>, S-MIME / IETF <ietf-smime@imc.org>
Subject: Policy Requirements for Attribute Authorities
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by above.proper.com id h69ENkqt098837
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

ETSI is making available a draft document for public comments called:
"Policy requirements for certification service providers issuing Attribute 
Certificates".

The document is available at the following URL:
http://docbox.etsi.org/ESI/Open/ETSI%20TS%20102_158%20v01.zip

This document has been approved by ETSI Technical Committee - Electronic 
Signatures and Infrastructures for public review.  Comments are invited on 
it, to be submitted to the editor and/or the task leader by 2003.08.24.

Editor: Denis Pinkas <Denis.Pinkas@bull.net>
Task leader: Franco Ruggieri <f.ruggieri@FLASHNET.IT>

Do not send your comments to the PKIX or to the SMIME mailing list.

This will allow the consolidation by 2003.09.07 of a final draft to be 
approved for publication at TC ESI # 05 in Sophia Antipolis, 23 – 24 
September 2003 as ETSI Technical Specification (TS) 102 158.

If you choose to place your comments in-line in the text of the document 
please return them under the same file name with the addition "&your initials".

If you are aware of other public lists whose members might benefit from 
awareness of this document and have their own views to offer, please feel 
free to forward the document to them with copy of this message.

Regards,

Denis Pinkas. Document editor.
Franco Ruggieri. Task leader.





Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h67NJHqt000558 for <ietf-smime-bks@above.proper.com>; Mon, 7 Jul 2003 16:19:17 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h67NJHPn000557 for ietf-smime-bks; Mon, 7 Jul 2003 16:19:17 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h67NJGqt000549 for <ietf-smime@imc.org>; Mon, 7 Jul 2003 16:19:16 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Mon, 7 Jul 2003 16:19:13 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>
Subject: Text conferencing at IETF 57
Date: Mon, 7 Jul 2003 16:19:13 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAzapNg5K/Sk2Rk7O93ki5VAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

The following is information about XMPP conferencing at IETF 57.  In
order for us to participate, we will need a scribe.  Any volunteers,
please stand up...

Blake

	     Remote Access for the 57th IETF meeting in Vienna:
                             Text Conferencing

At each IETF meeting, two of the working group meeting rooms are
equipped
for video multicast and remote participation.  That is, for every IETF
meeting slot, two of the working groups can see and hear the
meeting. For the 57th IETF, in *addition* to the usual network A/V, text
conferencing will be provided for every working group that meets.

All of the conference rooms will be hosted on

    ietf.jabber.at

and each is named using the official IETF abbreviation found in the
agenda (e.g., "apparea",  "dhc", "forces", and so on -- for all the
examples that follow, we'll use "foobar" as the abbreviation).

Each conference room also has a 'bot which records everything that gets
sent. So, the minute taker can review this information right after the
meeting.

In addition to the conference rooms for each wg that is meeting, there
are three others of general interest: bar, hallway, and plenary.
    

1. Before the meeting:

1.1. If you want to participate
    
If you don't already have one, get yourself a Jabber client, here are
some
suggestions:

    platform    suggestion
    --------    ----------
    win32       http://exodus.jabberstudio.org
    'nix        http://gabber.sf.net
    macos       http://jabberfox.sf.net

When you start the client for the first time, it will eventually ask if
you want to register on a public server. Go ahead and do
that. 
    
If you want to find out more, instead of choosing these defaults, here
are pointers to some additional information:
    
    list of clients:    http://www.jabber.org/user/clientlist.php
              howto:    http://www.jabber.org/user/userguide/
        server list:    http://www.jabber.org/user/publicservers.php

To make sure everything is running ok, do a "Join Group Chat" with your
Jabber client:
    
    Group/Room: testing
    Server:     conference.ietf.jabber.com

This conference room is up and running right now (although probably no
one will be in it when you connect).
    
1.2. What the Chair does
    
If you want to make text conferencing available, you'll need to have a
volunteer scribe in the meeting room. The scribe will be typing in a
running commentary as to what's going on in the room (who's presenting,
what question is being asked, etc.)
    
So, why not send an email out on the mailing list now, before the
meeting, to ask for volunteers?
    
    
2. At the meeting

2.1. What the Chair does

When a session starts, the chair asks if someone in the room is willing
to act as "scribe". If no one volunteers, read no further, we're done!

Otherwise, the scribe should do a "Join Group Chat" with their Jabber
client, e.g.,

    Group/Room: foobar
    Server:     conference.ietf.jabber.com


2.2. What the Scribe does

The scribe types in a running commentary as to what's going on in the
room. For example, if a speaker makes a presentation, the scribe types
in the URL for the presentation (more on this in a bit).

Simlarly, during question time, a remote participant can type a question
into the room and the scribe can pass it on to the speaker.


2.3. What each Presenter does

Each presenter should put a copy of their presentation on a web server
somewhere, so remote participants can follow along. 
    

2.4. Where to find the conference log
    
[ tbd ]
    
                                  #######
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h665VOqt013827 for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 22:31:24 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h665VOom013826 for ietf-smime-bks; Sat, 5 Jul 2003 22:31:24 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h665VNqt013819 for <ietf-smime@imc.org>; Sat, 5 Jul 2003 22:31:23 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Sat, 5 Jul 2003 22:31:21 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <agenda@ietf.org>, <ietf-smime@imc.org>
Cc: "'Sean P. Turner'" <turners@ieca.com>, "Housley, Russ" <housley@vigilsec.com>
Subject: S/MIME Working Group Agenda for the 57th IETF
Date: Sat, 5 Jul 2003 22:31:20 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAATh+vk8BwM0af/M1goB1NjgEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Here is the agenda for the S/MIME working group meeting at IETF 57.

Introductions                  (Sean Turner)
Working group status           (Sean Turner)
CMS and ESS examples update    (Paul Hoffman)
MSGbis and CERTbis update      (Blake Ramsdell)
Interoperability matrix update (Jim Schaad)
KEM overview                   (Jim Schaad)
PSS status                     (Jim Schaad)
ESSbis overview                (Jim Schaad)
GOST overview                  (Gregory S. Chudov)
Wrap up                        (Sean Turner)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h65Ma5qt005458 for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 15:36:05 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h65Ma5Is005457 for ietf-smime-bks; Sat, 5 Jul 2003 15:36:05 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp4.pacifier.net (smtp4.pacifier.net [64.255.237.174]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h65Ma4qt005452 for <ietf-smime@imc.org>; Sat, 5 Jul 2003 15:36:04 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237]) by smtp4.pacifier.net (Postfix) with ESMTP id 84C956AA2D; Sat,  5 Jul 2003 15:14:06 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>
Cc: <ietf-smime@imc.org>
Subject: RE: proposed addition to application/pkcs7-mime smime parameter
Date: Sat, 5 Jul 2003 15:36:29 -0700
Message-ID: <00a301c34345$e13e5970$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <00a801c33d34$976fdbf0$3d0311ac@augustcellars.local>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Blake,

In the process of looking at ESS, I notice that there is an smime-type
defined there.  So it appears that MSG will not contain the definitive
list no matter what is done.  I would like it to contain the definitive
list of all of CMS however.

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Jim Schaad
> Sent: Friday, June 27, 2003 10:18 PM
> To: 'Blake Ramsdell'; jimsch@exmsft.com
> Cc: ietf-smime@imc.org
> Subject: RE: proposed addition to application/pkcs7-mime 
> smime parameter
> 
> 
> 
> Blake,
> 
> 
> > I see a few ways to proceed, in my personal preference order:
> > 
> > 1. Commit to the current direction of using the MSG draft to
> > define how to use MIME with everything in CMS, as well as 
> > providing a constrained subset of CMS for the purpose of 
> > interpersonal messaging.
> > 
> > 2. Don't put anything in MSG at all that doesn't have to do
> > with interpersonal messaging, but leave what's there (the 
> > definition of the application/pkcs7-mime and the currently 
> > used smime-types).  Any additional smime-type values are 
> > defined outside of the MSG draft.
> > 
> > 3. Separate everything that has to do with the MIME wrapping
> > of CMS objects into its own draft (CMS/MIME), and don't 
> > discuss anything about interpersonal messaging at all.  The 
> > MSG draft simply contains references to the CMS/MIME draft, 
> > and is a profile of it.  This is somewhat like the separation 
> > of CMS and CMSALG, I think.
> > 
> > I will admit that my preference order is influenced by my
> > role as the editor, and the desire to see MSG progress sooner 
> > rather than later.
> 
> I have one argument for varient 3 that I just thought of that 
> might be overwelming at a later date, but certiantly not 
> currently.  If SIP is dependent on the CMS/SMIME/Messaging 
> draft, and we update that draft for a messaging only item, 
> then SIP gets reset on its progression path as well.  I don't 
> think this is an immeadiate issue, but something to consider 
> in the future.
> 
> If we go with the version 1 draft, then we should perhaps 
> look at reorginaizing the draft along the lines of looking 
> like a profile of a previously defined item rather than 
> having items intermixed.  I have not looked at the documents 
> to see how intermixed messaging is with the document and will 
> do so later this weekend.
> 
> > 
> > Blake
> > 
> 
> Jim
> 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h65M7Lqt003770 for <ietf-smime-bks@above.proper.com>; Sat, 5 Jul 2003 15:07:21 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h65M7LdF003769 for ietf-smime-bks; Sat, 5 Jul 2003 15:07:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from smtp1.pacifier.net (smtp1.pacifier.net [64.255.237.171]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h65M7Eqt003763 for <ietf-smime@imc.org>; Sat, 5 Jul 2003 15:07:14 -0700 (PDT) (envelope-from jimsch@nwlink.com)
Received: from ROMANS (ip237.c132.blk1.bel.nwlink.com [209.20.132.237]) by smtp1.pacifier.net (Postfix) with ESMTP id 95CD76FF7E; Sat,  5 Jul 2003 15:07:15 -0700 (PDT)
Reply-To: <jimsch@exmsft.com>
From: "Jim Schaad" <jimsch@nwlink.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, <ietf-smime@imc.org>
Cc: "'Gregory S. Chudov'" <chudov@cryptopro.ru>
Subject: RE: GOST with CMS
Date: Sat, 5 Jul 2003 15:07:39 -0700
Message-ID: <009d01c34341$da1880c0$1400a8c0@augustcellars.local>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbWMMVYx/3k2rzkaJBoDzmAEAAAAA@brutesquadlabs.com>
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Please note that the link below was broken in half during transport to
my machine.


http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

jim

> -----Original Message-----
> From: owner-ietf-smime@mail.imc.org 
> [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Blake Ramsdell
> Sent: Wednesday, July 02, 2003 8:16 AM
> To: ietf-smime@imc.org
> Cc: 'Gregory S. Chudov'
> Subject: GOST with CMS
> 
> 
> 
> A new draft is available, profiling the use of the Russian 
> national cryptography standards (GOST) in CMS:
> 
> Title: Cryptographic Message Syntax (CMS) algorithms for GOST 
> 28147-89, GOST R 34.10-94, GOST R 34.10-2001, GOST R 34.11-94.
> 
> Authors: Serguei Leontiev, Vladimir Popov
> 
> Filename: draft-leontiev-cryptopro-cpcms-00.txt
> 
http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

Gregory Chudov has asked to introduce this draft to the group at the
next working group meeting, and we will be providing him with some time
to do that.  I presume that this draft will become a draft of the
working group in the next revision.

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GrLqt004301 for <ietf-smime-bks@above.proper.com>; Fri, 4 Jul 2003 09:53:21 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h64GrLpD004300 for ietf-smime-bks; Fri, 4 Jul 2003 09:53:21 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from sottmxssm.entrust.com (sottmxssm.entrust.com [216.191.252.10]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GrKqt004282 for <ietf-smime@imc.org>; Fri, 4 Jul 2003 09:53:20 -0700 (PDT) (envelope-from Darrell.Dykstra@entrust.com)
Received: from sottguard01.entrust.com (sottguard01.entrust.com [10.4.61.249]) by sottmxssm.entrust.com (Switch-2.2.6/Switch-2.2.4) with SMTP id V64G3DBD27672 for <ietf-smime@imc.org>; Fri, 04 Jul 2003 12:49:47 -0400
Received: (qmail 13035 invoked by uid 64014); 4 Jul 2003 16:48:05 -0000
Received: from Darrell.Dykstra@entrust.com by sottguard01.entrust.com with AmikaGuardian-Server-1.1.2 (Processed in 0.252055 secs); 04 Jul 2003 16:48:05 -0000
Received: from unknown (HELO SOTTMXS01.entrust.com) (10.4.61.7) by 10.4.61.249 with SMTP; 4 Jul 2003 16:48:05 -0000
Received: by sottmxs01.entrust.com with Internet Mail Service (5.5.2656.59) id <MX4BR338>; Fri, 4 Jul 2003 12:53:14 -0400
Message-ID: <BFB44293CE13C9419B7AFE7CBC35B939042B808E@sottmxs08.entrust.com>
From: Darrell Dykstra <Darrell.Dykstra@entrust.com>
To: "'Blake Ramsdell'" <blake@brutesquadlabs.com>, "'Julien Stern'" <julien.stern@cryptolog.com>, jimsch@exmsft.com, ietf-smime@imc.org
Subject: RE: (Practical) S/MIME certificate chain handling
Date: Fri, 4 Jul 2003 12:53:07 -0400 
MIME-Version: 1.0
X-Mailer: Internet Mail Service (5.5.2656.59)
Content-Type: text/plain
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

> 
> > I believe that most clients transmit the certificate chain (not 
> > including the root) today.
> 
> To the best of my knowledge, Outlook does not, and it has
> quite a large
> market share ... (Although, I'd be happy to know how to make 
> it do so if
> there is a way ;) ).

I believe an end user can configure to some degree, which certificates are
sent in a signed message.  To access the UI in Outlook 2002, go to
Tools/Options/Security/Settings...  There should be a check box for "Send
these certificates with signed messages".  I have not verified as to what
exactly this checkbox controls (I am in a strict 1 level hierarchy so I
can't verify if sub-CA's are included without some prep work).  I would
think that, despite its naming, Outlook 2002 will always send the signer's
certs, and depending on the state of the checkbox, the chain from the
signer's certs to a trusted root.

Can anybody confirm or deny my theory (do you have a more complex hierarchy
to test with)?

Thanks,
Darrell


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GG8qt099805 for <ietf-smime-bks@above.proper.com>; Fri, 4 Jul 2003 09:16:08 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h64GG6PV099802 for ietf-smime-bks; Fri, 4 Jul 2003 09:16:06 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from kraid.nerim.net (smtp-105-friday.nerim.net [62.4.16.105]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h64GG4qt099785 for <ietf-smime@imc.org>; Fri, 4 Jul 2003 09:16:05 -0700 (PDT) (envelope-from julien.stern@cryptolog.com)
Received: from jupiter.cry.pto (cryptolog.net1.nerim.net [80.65.224.225]) by kraid.nerim.net (Postfix) with ESMTP id 6A28D40F0A; Fri,  4 Jul 2003 18:07:16 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1]) by jupiter.cry.pto (Postfix) with ESMTP id 7724E40F5; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: from jupiter.cry.pto ([127.0.0.1]) by localhost (jupiter [127.0.0.1]) (amavisd-new, port 10024) with SMTP id 06213-09; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: from callisto.cry.pto (callisto.cry.pto [10.0.1.4]) by jupiter.cry.pto (Postfix) with SMTP id 452F540E7; Fri,  4 Jul 2003 18:07:12 +0200 (CEST)
Received: by callisto.cry.pto (sSMTP sendmail emulation); Fri,  4 Jul 2003 18:07:12 +0200
From: "Julien Stern" <julien.stern@cryptolog.com>
Date: Fri, 4 Jul 2003 18:07:12 +0200
To: Blake Ramsdell <blake@brutesquadlabs.com>
Cc: jimsch@exmsft.com, ietf-smime@imc.org
Subject: Re: (Practical) S/MIME certificate chain handling
Message-ID: <20030704160712.GA12030@cryptolog.com>
References: <20030630103504.GA10502@cryptolog.com> <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAHQr9HqmMOESm/BDsbOUW0AEAAAAA@brutesquadlabs.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAHQr9HqmMOESm/BDsbOUW0AEAAAAA@brutesquadlabs.com>
User-Agent: Mutt/1.5.4i
X-Virus-Scanned: by amavisd-new-20030314-p2 (Debian) at example.com
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

On Mon, Jun 30, 2003 at 03:40:01PM -0700, Blake Ramsdell wrote:
> 
> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org 
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Julien Stern
> > Sent: Monday, June 30, 2003 3:35 AM
> > To: Blake Ramsdell; jimsch@exmsft.com; ietf-smime@imc.org
> > Subject: Re: (Practical) S/MIME certificate chain handling
> > 
> > > I believe that most clients transmit the certificate chain (not
> > > including the root) today.
> > 
> > To the best of my knowledge, Outlook does not, and it has 
> > quite a large
> > market share ... (Although, I'd be happy to know how to make 
> > it do so if
> > there is a way ;) ).
> 
> Outlook 2002 sends all the certificates in the chain (I just verified
> this).  When Jim Schaad wrote the code way back in something like
> Outlook 97, I'm fairly certain that it sent all the certificates also.
> This could very well be a case of misconfiguration of some sort, and I'd
> be happy to work through it with you offline.  The early S/MIME
> implementations all understood the utility of this, and included the
> certificates for exactly the reasons that you cite.

We did a bit of research, and it seems that, for Outlook, if
intermediate certificates are stored in the local machine stores, they
are indeed sent. However, if these certificates are stored in the user
stores (the ones in the user profile) they are not sent, despite the
fact the chain is correctly reconstructed. This behavior is different
from the one in Outlook Express.

> [many things regarding automatic verification snipped]

Regarding the rest of this thread, thanks to all for your enlightening
replies. I guess I'll take the pragmatic approach and attempt to focus
on the settings that actually work ;) And hopefully, at some point, I
will have the insurance that, given the extensions in my chain of cert,
and the available servers, _any_ S/MIME compliant receiver will indeed
be able to verify everything automatically, including revocation...

--
Julien


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXiFK082593 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:44 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62KXiHH082592 for ietf-smime-bks; Wed, 2 Jul 2003 13:33:44 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXgFK082587 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:43 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13167; Wed, 2 Jul 2003 16:33:41 -0400 (EDT)
Message-Id: <200307022033.QAA13167@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-x400transport-08.txt
Date: Wed, 02 Jul 2003 16:33:41 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Transporting S/MIME Objects in X.400
	Author(s)	: P. Hoffman, C. Bonatti
	Filename	: draft-ietf-smime-x400transport-08.txt
	Pages		: 6
	Date		: 2003-7-2
	
This document describes protocol options for conveying CMS-protected
objects associated with S/MIME version 3 over an X.400 message transfer
system.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-x400transport-08.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-x400transport-08.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-x400transport-08.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161846.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-x400transport-08.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-x400transport-08.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161846.I-D@ietf.org>

--OtherAccess--

--NextPart--




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXgFK082585 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:42 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62KXgpH082584 for ietf-smime-bks; Wed, 2 Jul 2003 13:33:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXdFK082576 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:40 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13145; Wed, 2 Jul 2003 16:33:37 -0400 (EDT)
Message-Id: <200307022033.QAA13145@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-x400wrap-07.txt
Date: Wed, 02 Jul 2003 16:33:37 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Securing X.400 Content with S/MIME
	Author(s)	: P. Hoffman, C. Bonatti, A. Eggen
	Filename	: draft-ietf-smime-x400wrap-07.txt
	Pages		: 11
	Date		: 2003-7-2
	
This document describes a protocol for adding cryptographic signature
and encryption services to X.400 content.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-x400wrap-07.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-x400wrap-07.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-x400wrap-07.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161836.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-x400wrap-07.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-x400wrap-07.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161836.I-D@ietf.org>

--OtherAccess--

--NextPart--




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXaFK082571 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 13:33:36 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62KXaqr082570 for ietf-smime-bks; Wed, 2 Jul 2003 13:33:36 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62KXYFK082565 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 13:33:34 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA13125; Wed, 2 Jul 2003 16:33:32 -0400 (EDT)
Message-Id: <200307022033.QAA13125@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-rfc2633bis-05.txt
Date: Wed, 02 Jul 2003 16:33:32 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: S/MIME Version 3.1 Message Specification
	Author(s)	: B. Ramsdell
	Filename	: draft-ietf-smime-rfc2633bis-05.txt
	Pages		: 0
	Date		: 2003-7-2
	
S/MIME (Secure/Multipurpose Internet Mail Extensions) provides a
consistent way to send and receive secure MIME data. Based on the
popular Internet MIME standard, S/MIME provides the following
cryptographic security services for electronic messaging applications:
authentication, message integrity and non-repudiation of origin (using
digital signatures) and data confidentiality (using encryption).

S/MIME can be used by traditional mail user agents (MUAs) to add
cryptographic security services to mail that is sent, and to interpret
cryptographic security services in mail that is received. However,
S/MIME is not restricted to mail; it can be used with any transport
mechanism that transports MIME data, such as HTTP. As such, S/MIME
takes advantage of the object-based features of MIME and allows secure
messages to be exchanged in mixed-transport systems.

Further, S/MIME can be used in automated message transfer agents that
use cryptographic security services that do not require any human
intervention, such as the signing of software-generated documents and
the encryption of FAX messages sent over the Internet.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-rfc2633bis-05.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-rfc2633bis-05.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-rfc2633bis-05.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-2161826.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-rfc2633bis-05.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-rfc2633bis-05.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-2161826.I-D@ietf.org>

--OtherAccess--

--NextPart--




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FiXFK066678 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 08:44:33 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62FiXJW066677 for ietf-smime-bks; Wed, 2 Jul 2003 08:44:33 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from [63.202.92.152] (adsl-63-202-92-152.dsl.snfc21.pacbell.net [63.202.92.152]) (authenticated bits=0) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FiSFN066656; Wed, 2 Jul 2003 08:44:30 -0700 (PDT) (envelope-from phoffman@imc.org)
Mime-Version: 1.0
X-Sender: phoffman@mail.imc.org
Message-Id: <p05210609bb28ab8d2f11@[63.202.92.152]>
In-Reply-To: <200307021056.GAA03059@ietf.org>
References: <200307021056.GAA03059@ietf.org>
X-Habeas-SWE-1: winter into spring
X-Habeas-SWE-2: brightly anticipated
X-Habeas-SWE-3: like Habeas SWE (tm)
X-Habeas-SWE-4: Copyright 2002 Habeas (tm)
X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this
X-Habeas-SWE-6: email in exchange for a license for this Habeas
X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant
X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this
X-Habeas-SWE-9: mark in spam to <http://www.habeas.com/report>.
Date: Wed, 2 Jul 2003 08:44:28 -0700
To: ietf-smime-examples@imc.org, ietf-smime@imc.org
From: Paul Hoffman / IMC <phoffman@imc.org>
Subject: Status of the examples draft
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Hi again. The -11 draft has the following changes:
5.1.bin
5.3.bin
5.4.bin
5.6.bin
5.7.bin
5.10.bin
8.2.bin
11.1.bin
11.2.bin

It would be great if everyone who has tested can re-test with these 
new examples.

BTW, I forgot to change the title of 6.3 to say RC2/128, and will do 
so in the -12 draft. (Just to be sure, I have already started the -12 
draft so I don't space out again...)

I would like to update the chart below for the -11 draft soon so we 
can move it to IETF last call.

======================================

Status of the examples in -10

4. Trivial Examples

4.1 ContentInfo with Data type, BER
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

4.2 ContentInfo with Data type, DER
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.  Signed-data
   Jim Schaad pointed out that many examples had the
     signatureAlgorithm of 1.2.840.10040.4.1 (dsa) but it should instead
     be 1.2.840.10040.4.3 (dsaWithSha1).
   The general decision was that the examples should have dsaWithSha1.
   John Pawling and Sue Beauchamp at DigitalNet agreed to re-generate
     the examples.

5.1 Basic signed content, DSS
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.2 Basic signed content, RSA
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.3 Basic signed content, detached content
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
	Contains Alice's RSA certificate
	No content hint unsigned attribute
     signatureAlgorithm is dsa but should be dsaWithSha1
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.4 Fancier signed content
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.
     Countersigner is Alice, not Diane
     No content hint
   Sue Beauchamp sent new example file.

5.5 All RSA signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

5.6 Multiple signers
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.7 Signing using SKI
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
     signatureAlgorithm is dsa but should be dsaWithSha1
   Holger Ebel: tested OK.
   Sue Beauchamp sent new example file.

5.8 S/MIME multipart/signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Holger Ebel: tested OK except that it has a CRLF prepended.

5.9 S/MIME application/pkcs7-mime signed message
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed because signatureAlgorithm of dsa not dsaWithSha1
   Holger Ebel: tested OK except that it has a CRLF prepended.

5.10 SignedData With Attributes
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jim Schaad: failed.
	Change "unknown OID" to "unknown OID (1.2.5555)"
	Content Hint should have an OID of 1.2.840.113549.1.7.1
	Content Identifier attribute absent
	Contains Security Label attribute
	Contains encrypt key preference attribute
	Contains ML Expansion History attribute
	Contains Equivalent Label attribute
   Jeff Jacoby: tested OK.
   Holger Ebel: failed (not signed by Alice).

5.11 SignedData with Certificates Only
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.  Enveloped-data

6.1 Basic encrypted content, TripleDES and DH
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.2 Basic encrypted content, TripleDES and RSA
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.3 Basic encrypted content, RC2/40 and RSA
   Blake Ramsdell: this is actually a 128-bit key.
   Jeff Jacoby: confirmed Blake's assertion.
   Paul Hoffman: thinks we could just change the title of the example.
   John Pawling: tested OK.
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.
   Holger Ebel: tested OK.

6.4 Encrypted content, two recipients, no shared keying material
   John Pawling: tested OK but noted unsuccessful Invalid tag for
     privateKeyInfo for second login.
   Holger Ebel: tested OK.

6.5 Encrypted content, two recipients, shared keying material
   John Pawling: could not test due to bug in his code.
   Holger Ebel: tested OK.

6.6 Encrypted content, TripleDES and DH, previously-distributed keys
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.7 Encrypted content, RC2/40 and RSA, previously-distributed keys
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.8 S/MIME application/pkcs7-mime encrypted message
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.9 EnvelopedData with All Recipient Types
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.10 EnvelopedData with KARI RC2 Encryption
   John Pawling: tested OK.
   Holger Ebel: tested OK.

6.11 EnvelopedData with KEK 3DES Encryption
   John Pawling: tested OK.
   Holger Ebel: tested OK.

7. Digested-data
   Blake Ramsdell: tested OK.
   Jeff Jacoby: tested OK.

8. Encrypted-data

8.1 Simple EncryptedData
   Blake Ramsdell: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.

8.2 EncryptedData with unprotected attributes
   Jim Schaad: failed badly.
     The key is not in the text and it is not the same as 8.1
	The encapsulated content type is EncryptedData not id-data
	The content hint content type does not match the encapsulated 
content type

9. Authenticated-data
   There are still no examples in this section.

10. Key Wrapping
   John Pawling: tested OK.

10.1 Wrapping RC2
   John Pawling: tested OK.

10.2 Wrapping TripleDES
   John Pawling: tested OK.
   Holger Ebel: tested OK.

11. ESS Examples

11.1 ReceiptRequest
   John Pawling: test failed, has sent new example file.
   Jeff Jacoby: tested OK.

11.2 Receipt
   John Pawling: test failed, has sent new example file.

11.3 eSSSecurityLabel
   John Pawling: tested OK.
   Jim Schaad: tested OK.
   Jeff Jacoby: tested OK.

11.4 EquivalentLabels
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

11.5 mlExpansionHistory
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

11.6 SigningCertificate
   John Pawling: tested OK.
   Jeff Jacoby: tested OK.

--Paul Hoffman, Director
--Internet Mail Consortium


Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FFgFK062351 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 08:15:42 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62FFgbh062350 for ietf-smime-bks; Wed, 2 Jul 2003 08:15:42 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62FFaFK062339 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 08:15:36 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Wed, 2 Jul 2003 08:15:32 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Gregory S. Chudov'" <chudov@cryptopro.ru>
Subject: GOST with CMS
Date: Wed, 2 Jul 2003 08:15:32 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAbWMMVYx/3k2rzkaJBoDzmAEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

A new draft is available, profiling the use of the Russian national
cryptography standards (GOST) in CMS:

Title: Cryptographic Message Syntax (CMS) algorithms for GOST 28147-89,
GOST R 34.10-94, GOST R 34.10-2001, GOST R 34.11-94.

Authors: Serguei Leontiev, Vladimir Popov

Filename: draft-leontiev-cryptopro-cpcms-00.txt

http://www.ietf.org/internet-drafts/draft-leontiev-cryptopro-cpcms-00.tx
t

Gregory Chudov has asked to introduce this draft to the group at the
next working group meeting, and we will be providing him with some time
to do that.  I presume that this draft will become a draft of the
working group in the next revision.

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwHFK057578 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 06:58:17 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62DwH3b057577 for ietf-smime-bks; Wed, 2 Jul 2003 06:58:17 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from moorabbin.nexor.co.uk (moorabbin.nexor.co.uk [80.6.88.100]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwAFK057564 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 06:58:16 -0700 (PDT) (envelope-from Graeme.Lunt@nexor.co.uk)
Received: from typhoon (actually host 210.53.63.193.in-addr.arpa) by moorabbin.nexor.co.uk with ESMTP (Mailer) with ESMTP; Wed, 2 Jul 2003 14:55:15 +0100
Reply-To: "g.lunt" <Graeme.Lunt@nexor.co.uk>
From: Graeme Lunt <Graeme.Lunt@nexor.co.uk>
To: "'jimsch'" <jimsch@exmsft.com>, "'Sean P. Turner'" <turners@ieca.com>
Cc: "'ietf-smime'" <ietf-smime@imc.org>
Subject: RE: Signed Receipts and Mail Lists
Date: Wed, 2 Jul 2003 14:56:58 +0100
Organization: Nexor
Message-ID: <001f01c340a1$cf01f470$d2353fc1@nexor.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.4024
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
In-Reply-To: <009701c33ce3$a86b4170$3d0311ac@augustcellars.local>
X-Spam-Status: No, hits=-100.7 required=5.0 tests=IN_REP_TO,NOSPAM_INC,QUOTED_EMAIL_TEXT,SPAM_PHRASE_03_05, USER_IN_WHITELIST version=2.43
X-Spam-Level: 
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Jim,
 
> If we adopted the solution you gave, what limits me from making
> arbitrary statements about who I am in this field that then need to be

> independently verified by the receipt processing code?  (I.e. what if 
> I put the fact that I am turners@ieca.com in this field and sign with 
> my jimsch@exmsft.com certificate).

First off, having looked in more detail at 2634 it implicitly requires
each mail list to have its own certificate. In particular, the
EntityIdentifier, used in MLExpansionHistory, refers only to a
certificate. So having a single certificate for an MLA supporting
multiple lists would cause the loop detection algorithm to fail.  

So what I was looking at (a single certificate for a mail list agent
supporting multiple lists) is a more fundamental change than I first
thought.

But back to your question. 

The basic answer is that nothing would limit you. Do you see this as a
major issue?

x400wrap has a similar case where the content being signed contains an
"originator" field. 

"Receiving agents SHOULD check that the originator address in the X.400
content matches an X.400 address in the signer's certificate, if X.400
addresses are present in the certificate and an originator address is
available in the content. A receiving agent SHOULD provide some explicit
alternate processing of the message if this comparison fails, which may
be to display a message that shows the recipient the addresses in the
certificate or other certificate details."

I think that similar wording to section 4.3 of this draft may be
acceptable?

This wording allows us to take our own action to correlate the x400
originator to the signer in the case that they don't match (we use
attribute certificates to do the signer to originator validation). 

So for your example, I may see something like:

"signed receipt from jimsch@exmsft.com on behalf of turners@ieca.com at
<time>"

The receiptFrom field I proposed is primarily aimed at supporting the
correlation of the signed receipt to the original recipient by providing
original address the signed receipt was requested from. 

There are a number of reasons why I may not be able to match the
address[es] (subjectAltName) from the certificate to one of the
addresses I to:

a) Valid aliases not in the subjectAltNames of the certificate

b) Signed receipt from a recipient who received the message as a result
of ML expansion.  

c) Mail redirections - e.g. sent to "ceo@corp.com" which redirects to a
personal mailbox.
Similar to a). 


Graeme


> > -----Original Message-----
> > From: owner-ietf-smime@mail.imc.org 
> > [mailto:owner-ietf-smime@mail.imc.org] On Behalf Of Graeme Lunt
> > Sent: Wednesday, June 25, 2003 12:40 AM
> > To: 'Sean P. Turner'
> > Cc: 'ietf-smime'
> > Subject: RE: Signed Receipts and Mail Lists
> > 
> > 
> > 
> > Sean,
> >  
> > > I'm not sure that the MLA returns a receipt on behalf of the ML 
> > > members.
> > 
> > OK - if an MLA should not return signed receipts then there is not a

> > problem with my scenario.
> > 
> > > I looked through ESS again and I couldn't find anything
> > that said if a
> > > message enters an MLA with a signed receipt request that it
> > 
> > > shouldn't or should return a receipt.    
> > 
> > Is an MLA considered a "receiving agent"/"receiving 
> > software"/"processing software" in section 2.3 of ESS? I had assumed

> > that it was but agree it is unclear.
> > 
> > > Typically (I think), originators want to know that the
> > final recipient
> > got
> > > the message not whether the MLA got it.
> > 
> > I think there are arguments for both. If an originator
> sends a message
> > to:
> > 
> > complaints@bigbank.co.uk
> > 
> > the originator probably only wants to know that it got to the 
> > complaints department at bigbank. The originator doesn't want to 
> > know (and bigbank doesn't want to let the originator know) which 
> > individuals within bigbank read the message.
> > 
> > > Then again maybe I didn't understand your scenario.
> > 
> > I don't think the originator needs to understand if the addresses 
> > they are requesting signed receipts from are address lists or not. 
> > If an originator sends a message to two recipients - one a mail 
> > list, one an individual - and requests first tier signed receipts, 
> > they will never receive a signed receipt from the mail list 
> > recipient. The user may find this unexpected. Correlation software
> > *may* be able to detect a mail list recipient and handle it
> > appropriately.
> > 
> > 
> > Graeme
> > 
> > 
> 
> 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AuuFK051294 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 03:56:56 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62AuuC7051292 for ietf-smime-bks; Wed, 2 Jul 2003 03:56:56 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AutFK051285 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 03:56:55 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03059; Wed, 2 Jul 2003 06:56:54 -0400 (EDT)
Message-Id: <200307021056.GAA03059@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
Cc: ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-smime-examples-11.txt
Date: Wed, 02 Jul 2003 06:56:53 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the S/MIME Mail Security Working Group of the IETF.

	Title		: Examples of S/MIME Messages
	Author(s)	: P. Hoffman
	Filename	: draft-ietf-smime-examples-11.txt
	Pages		: 8
	Date		: 2003-7-1
	
This document gives examples of message bodies formatted using S/MIME.
Specifically, it has examples of Cryptographic Message Syntax (CMS)
objects, S/MIME messages (including the MIME formatting), and Enhanced
Security Services for S/MIME (ESS). It includes examples of most or all
common CMS and ESS formats; in addition, it gives examples that show
common pitfalls in implementing CMS. The purpose of this document is to
help increase interoperability for S/MIME and other protocols that rely
on CMS.
This draft is being discussed on the 'ietf-smime' mailing list.  To
join the list, send a message to <ietf-smime-request@imc.org> with the
single word 'subscribe' in the body of the message.  Also, there is a
Web site for the mailing list at <http://www.imc.org/ietf-smime/>.

This draft is being discussed on the 'ietf-smime' mailing list.  To
join the list, send a message to <ietf-smime-request@imc.org> with the
single word 'subscribe' in the body of the message.  Also, there is a
Web site for the mailing list at <http://www.imc.org/ietf-smime/>.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-smime-examples-11.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-ietf-smime-examples-11.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-smime-examples-11.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-1134908.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-smime-examples-11.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-smime-examples-11.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-1134908.I-D@ietf.org>

--OtherAccess--

--NextPart--




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApUFK050485 for <ietf-smime-bks@above.proper.com>; Wed, 2 Jul 2003 03:51:30 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62ApUV0050484 for ietf-smime-bks; Wed, 2 Jul 2003 03:51:30 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApTFK050473 for <ietf-smime@imc.org>; Wed, 2 Jul 2003 03:51:30 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us)
Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA01615; Wed, 2 Jul 2003 06:51:26 -0400 (EDT)
Message-Id: <200307021051.GAA01615@ietf.org>
Mime-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
To: IETF-Announce: ;
CC: sipping@ietf.org, ietf-smime@imc.org
From: Internet-Drafts@ietf.org
Reply-to: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-mahy-sipping-smime-vs-digest-01.txt
Date: Wed, 02 Jul 2003 06:51:26 -0400
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.


	Title		: Discussion of suitability: S/MIME instead of Digest 
                          Authentication in the Session Initiation Protocol 
                         (SIP)
	Author(s)	: R. Mahy
	Filename	: draft-mahy-sipping-smime-vs-digest-01.txt
	Pages		: 11
	Date		: 2003-7-1
	
Digest authentication (as defined in RFC2617) is used in SIP
(RFC3261) for user authentication, and less frequently for message
integrity of MIME bodies carried in SIP.  Various members of the IETF
security community have periodically suggested that Digest should be
deprecated in favor of the SIP use of S/MIME (RFC2633), support for
which was recently introduced in RFC3261.  The author seeks clarity
from the IETF security community on behalf of the SIP community about
the feasibility and possible benefits of using S/MIME instead of
Digest in one or both of these applications.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt

To remove yourself from the IETF Announcement list, send a message to 
ietf-announce-request with the word unsubscribe in the body of the message.

Internet-Drafts are also available by anonymous FTP. Login with the username
"anonymous" and a password of your e-mail address. After logging in,
type "cd internet-drafts" and then
	"get draft-mahy-sipping-smime-vs-digest-01.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.
		
		
Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2003-7-1133733.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-mahy-sipping-smime-vs-digest-01.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2003-7-1133733.I-D@ietf.org>

--OtherAccess--

--NextPart--




Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LodFK087936 for <ietf-smime-bks@above.proper.com>; Tue, 1 Jul 2003 14:50:39 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h61Lodk8087935 for ietf-smime-bks; Tue, 1 Jul 2003 14:50:39 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LocFK087918 for <ietf-smime@imc.org>; Tue, 1 Jul 2003 14:50:39 -0700 (PDT) (envelope-from blake@brutesquadlabs.com)
Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Tue, 1 Jul 2003 14:50:35 -0700
From: "Blake Ramsdell" <blake@brutesquadlabs.com>
To: <ietf-smime@imc.org>
Cc: "'Sean Turner'" <turners@ieca.com>
Subject: DRAFT S/MIME working group agenda
Date: Tue, 1 Jul 2003 14:50:35 -0700
Message-ID: <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAARMPfbnbp50SwK3EZjypY2MKAAAAQAAAAH5/oOPiN10yLsjkx1W//HgEAAAAA@brutesquadlabs.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165
Importance: Normal
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

Here is a draft agenda based on the response so far.  This will most
likely be the final agenda unless Sean or I hear something different.

Introductions (Sean Turner)
Working group status (Sean Turner)
CMS and ESS examples update (Paul Hoffman)
MSGbis and CERTbis update (Blake Ramsdell)
Interoperability matrix update (Jim Schaad)
KEM overview (Jim Schaad)
PSS status (Jim Schaad)
ESSbis overview (Jim Schaad)

Blake
--
Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com 



Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h619D0FK031127 for <ietf-smime-bks@above.proper.com>; Tue, 1 Jul 2003 02:13:00 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h619D0uv031126 for ietf-smime-bks; Tue, 1 Jul 2003 02:13:00 -0700 (PDT)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f
Received: from hermes.cs.auckland.ac.nz ([130.216.35.151]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h619CwFK030843 for <ietf-smime@imc.org>; Tue, 1 Jul 2003 02:12:59 -0700 (PDT) (envelope-from pgut001@cs.auckland.ac.nz)
Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6198iXX012517; Tue, 1 Jul 2003 21:08:44 +1200
Received: (from pgut001@localhost) by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6198gB18508; Tue, 1 Jul 2003 21:08:42 +1200
Date: Tue, 1 Jul 2003 21:08:42 +1200
Message-Id: <200307010908.h6198gB18508@medusa01.cs.auckland.ac.nz>
From: pgut001@cs.auckland.ac.nz (Peter Gutmann)
To: blake@brutesquadlabs.com, ietf-smime@imc.org, jimsch@exmsft.com, julien.stern@cryptolog.com
Subject: RE: (Practical) S/MIME certificate chain handling
Sender: owner-ietf-smime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-smime/mail-archive/>
List-ID: <ietf-smime.imc.org>
List-Unsubscribe: <mailto:ietf-smime-request@imc.org?body=unsubscribe>

"Blake Ramsdell" <blake@brutesquadlabs.com> writes:

>I agree, and that's why they send all the certificates along with messages to
>this date.  By "they", I mean S/MIME-enabled versions of Netscape, Outlook
>Express, Outlook, and the S/MIME plugin for Eudora that I wrote.

Just as another data point, a small portion of my certificate zoo consists of
cert chains from S/MIME sigs, and every one of them is a full chain (or at
least some sort of chain), rather than a single cert.  I don't track where
they originally came from, but they cover (at least) Outlook (many versions),
Netscape, and a few S/MIME gateways that auto-sign everything passing through
them (most of the stuff I've seen in general mail in fact would be auto-
signed, either by a gateway or because the sender turned it on and forgot
about it).  I do have some single-cert chains, but they're from oddball
applications like EDI messaging (the certs have EDI altnames and whatnot)
which aren't representative of general usage.

Peter.

