ietf-smime
[Top] [All Lists]

Re: Question about signing attachments separately

1998-01-29 05:16:16
The problem with signatures is far worse. The standard example is the
three part message with a first that says, "The first attachment is the
version of the contract to use, the second is the crappy one that should
never have seen the light of day." The parts can be swapped without
detection if they are signed separately. Enough said.


This is however the case we would like to support. I send the contract to
party B with my signature on the attachment. B then signs the attachment
and forwards it to C. C can check that I and B have signed the contract 
and can deposit it. This multi-signature contract question looks like an
advocate for the system and not the opposite.

Mark

-----------------------------------------------------------------------

                           '''
                          (o o)
             .------oOOO---(_)-----------.
             |                           |
             |                           |
             | This is me in real size   |
             |                           |
             `-------------------oOOO----'
                         |__|__|
                          || ||
                         ooO Ooo

Mark Vandenwauver       email : 
vdwauver(_at_)esat(_dot_)kuleuven(_dot_)ac(_dot_)be
Assistant               www   : http://www.esat.kuleuven.ac.be/~vdwauver
K.U.Leuven ESAT-COSIC   phone : 32-16-321134
Kard. Mercierlaan 94            32-16-321050 (Secr.)
3001 Heverlee           fax   : 32-16-321986
BELGIUM