I would imagine that the majority of S/MIME implementations are based on
RSADSI's BSafe. In my phone conversations with RSADSI last week they made
it plain in no uncertian terms that they will *not* be supporting these
unencumbered algorithms and their position is that DH/DSS is "untested"
and "insecure" (Their basic position is if it's not from RSADSI it's not
"secure").
Have just been looking at the S/Mime v3 spec page 25 section 12 at
http://www.imc.org/draft-ietf-smime-cms and the MUST impliment includes
DSS, SHA-1, D-H (x9.42) and triple DES CBC (three keys - 168 bit).
MAY impliment includes the proprietary RSA mechanisms.
If this stays that way there is no reason why PGP could not be S/MIME
compliant. Will say that the crypto (other than being intercommunicating)
is really the least part - it is the directory and key management structure
that will make or break. At the moment it is the only one I have seen that
is independant of a mail structure and provides for diversified management.
(opposing views welcome).
Warmly,
Padgett