
From wwwrun@rfc-editor.org  Tue Dec  3 09:17:26 2013
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DC4611ACCE5; Tue,  3 Dec 2013 09:17:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.903
X-Spam-Level: 
X-Spam-Status: No, score=-1.903 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Ukn238bXVZIh; Tue,  3 Dec 2013 09:17:25 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [IPv6:2001:1890:126c::1:2f]) by ietfa.amsl.com (Postfix) with ESMTP id 356221AC499; Tue,  3 Dec 2013 09:17:25 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id 514CC72E0D9; Tue,  3 Dec 2013 09:16:51 -0800 (PST)
To: housley@vigilsec.com,  tbdean@QinetiQ.com, wjottaway@QinetiQ.com
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20131203171651.514CC72E0D9@rfc-editor.org>
Date: Tue,  3 Dec 2013 09:16:51 -0800 (PST)
Cc: rfc-editor@rfc-editor.org, iesg@ietf.org, smime@ietf.org
Subject: [smime] [Errata Verified] RFC3183 (3757)
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Dec 2013 17:17:27 -0000

The following errata report has been verified for RFC3183,
"Domain Security Services using S/MIME". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=3183&eid=3757

--------------------------------------
Status: Verified
Type: Technical

Reported by: Russ Housley <housley@vigilsec.com>
Date Reported: 2013-10-18
Verified by: Sean Turner (IESG)

Section: 3.1.2

Original Text
-------------
   An S/MIME signed attribute is used to indicate the type of signature.
   This should be used in conjunction with the naming conventions
   specified in the previous section.  When an S/MIME signed message
   containing the signature type attribute is received it triggers the
   software to verify that the correct naming convention has been used.

   The ASN.1 [4] notation of this attribute is: -

      SignatureType ::= SEQUENCE OF OBJECT IDENTIFIER


Corrected Text
--------------
   An S/MIME signed attribute is used to indicate the type of signature.
   This should be used in conjunction with the naming conventions
   specified in the previous section.  When an S/MIME signed message
   containing the signature type attribute is received it triggers the
   software to verify that the correct naming convention has been used.

   The following object identifier identifies the SignatureType
   attribute:

      id-aa-signatureType OBJECT IDENTIFIER ::= { iso(1) 
          member-body(2) us(840) rsadsi(113549) pkcs(1) pkcs9(9) 28 }

   The ASN.1 [4] notation of this attribute is:

      SignatureType ::= SEQUENCE OF OBJECT IDENTIFIER


Notes
-----
The specification provides the syntax for the SignatureType attribute,
but it fails to provide the object identifier for the attribute.  The object
identifier was assigned, but for some reason it is not provided in the
document.

--------------------------------------
RFC3183 (draft-ietf-smime-domsec-09)
--------------------------------------
Title               : Domain Security Services using S/MIME
Publication Date    : October 2001
Author(s)           : T. Dean, W. Ottaway
Category            : EXPERIMENTAL
Source              : S/MIME Mail Security
Area                : Security
Stream              : IETF
Verifying Party     : IESG

From housley@vigilsec.com  Tue Dec 10 11:45:01 2013
Return-Path: <housley@vigilsec.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D576B1AE211 for <smime@ietfa.amsl.com>; Tue, 10 Dec 2013 11:45:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.9
X-Spam-Level: 
X-Spam-Status: No, score=-101.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, USER_IN_WHITELIST=-100] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2TKToT3D8DYo for <smime@ietfa.amsl.com>; Tue, 10 Dec 2013 11:44:59 -0800 (PST)
Received: from odin.smetech.net (mail.smetech.net [209.135.209.4]) by ietfa.amsl.com (Postfix) with ESMTP id D4DB01ADFF5 for <smime@ietf.org>; Tue, 10 Dec 2013 11:44:59 -0800 (PST)
Received: from localhost (unknown [209.135.209.5]) by odin.smetech.net (Postfix) with ESMTP id B64969A41D9 for <smime@ietf.org>; Tue, 10 Dec 2013 14:44:44 -0500 (EST)
X-Virus-Scanned: amavisd-new at smetech.net
Received: from odin.smetech.net ([209.135.209.4]) by localhost (ronin.smeinc.net [209.135.209.5]) (amavisd-new, port 10024) with ESMTP id X5GxrBA8cVn3 for <smime@ietf.org>; Tue, 10 Dec 2013 14:44:23 -0500 (EST)
Received: from [192.168.2.110] (pool-96-255-140-248.washdc.fios.verizon.net [96.255.140.248]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by odin.smetech.net (Postfix) with ESMTP id AE7B09A41D8 for <smime@ietf.org>; Tue, 10 Dec 2013 14:44:23 -0500 (EST)
From: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Date: Tue, 10 Dec 2013 14:44:23 -0500
References: <20131210194137.31216.96349.idtracker@ietfa.amsl.com>
To: IETF SMIME <smime@ietf.org>
Message-Id: <2D4F56AD-1647-49C1-A5EB-B986C3491D11@vigilsec.com>
Mime-Version: 1.0 (Apple Message framework v1085)
X-Mailer: Apple Mail (2.1085)
Subject: [smime] New Version Notification - draft-housley-ct-keypackage-receipt-n-error-07.txt
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Dec 2013 19:45:02 -0000

The changes were to address directorate and IESG comments.

Russ


Begin forwarded message:

> From: internet-drafts@ietf.org
> Date: December 10, 2013 2:41:37 PM EST
> To: housley@vigilsec.com, =
draft-housley-ct-keypackage-receipt-n-error@tools.ietf.org, =
carl@redhoundsoftware.com, stephen.farrell@cs.tcd.ie
> Subject: New Version Notification - =
draft-housley-ct-keypackage-receipt-n-error-07.txt
>=20
>=20
> A new version (-07) has been submitted for =
draft-housley-ct-keypackage-receipt-n-error:
> =
http://www.ietf.org/internet-drafts/draft-housley-ct-keypackage-receipt-n-=
error-07.txt
>=20
>=20
> The IETF datatracker page for this Internet-Draft is:
> =
https://datatracker.ietf.org/doc/draft-housley-ct-keypackage-receipt-n-err=
or/
>=20
> Diff from previous version:
> =
http://www.ietf.org/rfcdiff?url2=3Ddraft-housley-ct-keypackage-receipt-n-e=
rror-07
>=20
> Please note that it may take a couple of minutes from the time of =
submission
> until the htmlized version and diff are available at tools.ietf.org.
>=20
> IETF Secretariat.
>=20


From hallam@gmail.com  Sat Dec 21 13:20:02 2013
Return-Path: <hallam@gmail.com>
X-Original-To: smime@ietfa.amsl.com
Delivered-To: smime@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C599F1AE09E for <smime@ietfa.amsl.com>; Sat, 21 Dec 2013 13:20:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level: 
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fJDJoKBzXd0F for <smime@ietfa.amsl.com>; Sat, 21 Dec 2013 13:20:01 -0800 (PST)
Received: from mail-la0-x22a.google.com (mail-la0-x22a.google.com [IPv6:2a00:1450:4010:c03::22a]) by ietfa.amsl.com (Postfix) with ESMTP id 98B7C1AE08A for <smime@ietf.org>; Sat, 21 Dec 2013 13:20:00 -0800 (PST)
Received: by mail-la0-f42.google.com with SMTP id ec20so1697177lab.15 for <smime@ietf.org>; Sat, 21 Dec 2013 13:19:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:content-type; bh=6jCaVmiCm75+/Cf3kFeGaNwiSGSpDPJE/Y1aDzQGO28=; b=m1fMhBAuTCphLpifHqdhlvoOvcg1f/N1NIwfFcbX2KNAjfoL6DIgXqKJI2WfsNm44g UViymxT0NdseKQToCdZgKR6g5arMWx2xXorKkL+Yw1qIDc9sT17Pguuzhtj4LSePtLoh J/QrRMJXWqT7Ebhnv1+dfo/PcUaF21OL692JPrn7xA7jSbEpYWq17o1VyYWPzNsPrDyi y9wVmiF0MN1B0tQeH6MdnCsrU5QRUR4CrfPUXxKE6zH3qMOILChnKBihdAtk6tUKtGsu 3Xjua/VfpqMd4cqjqRhG9rz/TM1RW8QfZRHljXsmSm4XIy0q6i1ZYEEy8KtR5SIE9JMW Isiw==
MIME-Version: 1.0
X-Received: by 10.112.55.212 with SMTP id u20mr6853612lbp.4.1387660795459; Sat, 21 Dec 2013 13:19:55 -0800 (PST)
Received: by 10.112.37.172 with HTTP; Sat, 21 Dec 2013 13:19:55 -0800 (PST)
Date: Sat, 21 Dec 2013 16:19:55 -0500
Message-ID: <CAMm+Lwgitd3TXH_Wy2uRCWL05MTit+XOBjUdAkFOUKR=LPBDYg@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: smime@ietf.org
Content-Type: multipart/alternative; boundary=001a1133e4bec83e7104ee11f43d
Subject: [smime] Repository of S/MIME lore?
X-BeenThere: smime@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMIME Working Group <smime.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/smime>, <mailto:smime-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/smime/>
List-Post: <mailto:smime@ietf.org>
List-Help: <mailto:smime-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/smime>, <mailto:smime-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 21 Dec 2013 21:20:03 -0000

--001a1133e4bec83e7104ee11f43d
Content-Type: text/plain; charset=ISO-8859-1

I am trying to get my S/MIME enhancement proxy to work and having
difficulty of the 'specifications say you can do this but the
implementations don't support it' type

In particular just trying to send and receive encrypted mail from Windows
Live Mail to Windows Live Mail at the moment. I am pretty sure the CMS code
is right (I am using OpenSSL) but I can't get the mail to decrypt. It says
it can't find the decryption key.


Any ideas where there might be a description of a profile that works?

I am guessing that my plan to identify the decryption key by a key
identifier binding to the key rather than a certificate identifier is a
part of the problem. But it is clearly not the whole problem.


-- 
Website: http://hallambaker.com/

--001a1133e4bec83e7104ee11f43d
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I am trying to get my S/MIME enhancement proxy to work and=
 having difficulty of the &#39;specifications say you can do this but the i=
mplementations don&#39;t support it&#39; type<br clear=3D"all"><div><br></d=
iv>
<div>In particular just trying to send and receive encrypted mail from Wind=
ows Live Mail to Windows Live Mail at the moment. I am pretty sure the CMS =
code is right (I am using OpenSSL) but I can&#39;t get the mail to decrypt.=
 It says it can&#39;t find the decryption key.</div>
<div><br></div><div><br></div><div>Any ideas where there might be a descrip=
tion of a profile that works?</div><div><br></div><div>I am guessing that m=
y plan to identify the decryption key by a key identifier binding to the ke=
y rather than a certificate identifier is a part of the problem. But it is =
clearly not the whole problem.</div>
<div><br></div><div><br></div>-- <br>Website: <a href=3D"http://hallambaker=
.com/">http://hallambaker.com/</a><br>
</div>

--001a1133e4bec83e7104ee11f43d--
