ietf-smime
[Top] [All Lists]

Re: Proposed charter for a S/MIME working group

1997-10-02 13:58:43
Goals and Milestones:

History:
    PKCS #7 version 1.5 specification submitted as Informational RFC.
    S/MIME v2 message specification submitted as Informational RFC.
    S/MIME v2 certificate specification submitted as Informational RFC.

October 97:
    First draft of message syntax specification.
    First draft of S/MIME v3 message specification.
    First draft of S/MIME v3 certificate specification.
    First draft of S/MIME optional security extensions.


I also admit being confused with this charter, since it doesn't specify
what documents the First Drafts or the Proposed Standards will be based
on.

Background: the MSP-S/MIME working group designed what was called
"S/MIME v3" based on the drafts of PKCS#7 v2.0, which has been discussed
on the PKCS-TNG mail list, but not submitted to the IETF.

Later, the MSP-S/MIME group decided to base its merged protocol on
PKCS#7 v1.5, which has been submitted as an Informational RFC, in order
to minimize the changes from the existing S/MIME v2.  I'm disappointed
by this decision because PKCS#7 v2 is a much cleaner design than v1.5,
but I understand the desire for bit-for-bit message compatibility with
existing PKCS#7 v1.5 implementations (instead of the signature compatibility
provided by PKCS#7 v2).

However, there are three separate processes at work here, and I don't
understand the relationship between them:

 1) merge MSP functionality into S/MIME with absolute minimum changes to
    the existing S/MIME v2 specs,

 2) produce baseline documents for the IETF-S/MIME standarization work, and

 3) produce the next-generation PKCS#7 standard, based on drafts designated
    v2.0.


Questions:

1. What is the "message syntax specification" listed above for October 97?
    "Son of PKCS#7 v1.5", a.k.a. "PKCS#7 v1.7"?  "PKCS#7 v2"?
     Something else?

2. Will IETF-S/MIME v3 refer to PKCS#7 v2 before becoming a Proposed Standard
    in Jan 98?

3. If not 2, will IETF-S/MIME ever be based on PKCS#7 v2?

4. If not 3, what purpose is served by continuing to develop PKCS#7 to v2
    and beyond, and encouraging it to use techniques compatible with the
    MSP-S/MIME work?

5. Will PKCS#7 v2 be submitted to the IETF in any form (Informational
    or Standards Track), in any forum (IETF-S/MIME or elsewhere)?