Interop Requirement for Signed Data formats

2004-03-26 00:10:44

In my last review of the document I found the following text in section 3.4

There are two formats for signed messages defined for S/MIME:
application/pkcs7-mime with SignedData, and multipart/signed. In
general, the multipart/signed form is preferred for sending, and
receiving agents SHOULD be able to handle both.

The problem here is that there is no interop in the signed message format as
specified by the above statement. I.E. Person one could implement
application/pkcs7-mime only and person two could implemement
multipart/signed only -- no interop.

The best change for interop purposes is to change the SHOULD to a MUST.



