I understand that there is a faction that says that RC2 40-bit should
just be changed from MUST to SHOULD. This will cause a lack of
interoperability. I further understand that there is a faction that
says that RC2 should be removed completely from the algorithm suite.
This will also cause a lack of interoperability.
That's exactly right: the minimum implementation for "Internet Standard
S/MIME" (ignoring the trademark issues for the moment) will not and
cannot be compatible with existing S/MIME implementations -- at least not
unless/until there is a RC2 specification available for public review.
To do otherwise would be fundamentally incompatible with the Internet
Standards process.
On the other hand, nothing says that "Internet Standard S/MIME" products
can't also include the ability to interoperate with "S/MIME classic"
as long as RSA is willing to license such implementations.
Keith