ietf-smime
[Top] [All Lists]

RE: RecipientInfo vs SignerInfo key identification

1998-11-23 15:52:15
-----Original Message-----
From: Jim Schaad (Exchange) 
[mailto:jimsch(_at_)EXCHANGE(_dot_)MICROSOFT(_dot_)com]
Sent: Monday, November 23, 1998 2:47 PM
To: Blake Ramsdell; 'Russ Housley'; 
pgut001(_at_)cs(_dot_)aucKland(_dot_)ac(_dot_)nz
Cc: ietf-smime(_at_)imc(_dot_)org
Subject: RE: RecipientInfo vs SignerInfo key identification

These discussions occured when we were still meeting in San 
Fransico.  If we
allow for this to occur in the S/MIME world we immeadiately 
hit the demon of
backwards compatability.  I don't know about your product, 
but ours does not
look at capabilites of recipients when sending signed mail.  
Thus we MUST
use the Issuer/Serial Number identification as we have no idea if the
receiving client has the ability to understand anything new.

Isn't this a problem if you have attribute certificates or secure return
receipts also?  These features will not be supported by v2 clients either
(and will cause a similar interoperability problem).

Likewise, the RecipientInfo changes for this same purpose seem to have
exactly the same problem (and we got around this by ticking the version
number), so the demon is still with us.

I personally don't want this changed, but I wanted to make sure I understood
the arguments against it.

Blake
--
Blake C. Ramsdell
Worldtalk Corporation
For current info, check http://www.deming.com/users/blaker
Voice +1 425 882 8861 x103  Fax +1 425 882 8060