ietf-openpgp
[Top] [All Lists]

Re: S/MIME winz

1998-03-10 07:56:02
From: "William H. Geiger III" <whgiii(_at_)invweb(_dot_)net>

Well I think we have a *big* difference between S/MIME and OpenPGP here.

With OpenPGP we have only one corporation (PGP Inc.) involved with legacy
software, and they have made a strong effort to push it's user base away
from proprietary algorithms (RSA) to unencumbered ones.

In the S/MIME camp you have quite a different senario. You have several
large corporations (Netscape, Microsoft, IBM/Lotus) all who have
substantial investments in RSADSI software licenses. I hardly doubt that
any of these companies will make any effort to move their users away from
RSA. While it is true that the MUST requirements in the S/MIME v3 draft
have been dropped you will not see any products on the shelf that do not
support it.


You obviously haven't been following S/MIME any more closely than
Warmly Padgett.  Not only have MUST requirements for RSA/RC4 been
dropped (RC2 is already public), but MUST requirements for DSA/3DES
have been added.

Both S/MIME users and PGP users will be able to switch to free algorithms,
and there is no interoperability problem between users who switch and
those who don't (as long as they use standard-compliant software).

I'll grant that PGP users may be more intellectually motivated to
switch quickly.  PGP, Inc can speak to whether they intend to coerce
users into switching by dropping support for optional algorithms.

<Prev in Thread] Current Thread [Next in Thread>