ietf-smime
[Top] [All Lists]

Re: [smime] [pkix] Initial inquiry: Signed vCards

2013-10-22 15:00:49
I may be missing something, but I do not see how using a MAC function is
going to provide any degree of security in this case.

The basic presumption of using a MAC function is that the secret is known
only to two people.  The generator and the consumer.  If it is known to
multiple people, especially if it is advertised in a URL, then a new MAC
value can be created by anybody that can get the secret value and a new
vcard substituted.

Jim


-----Original Message-----
From: smime-bounces(_at_)ietf(_dot_)org 
[mailto:smime-bounces(_at_)ietf(_dot_)org] On
Behalf Of DataPacRat
Sent: Monday, October 21, 2013 9:58 AM
To: Sean Turner
Cc: smime(_at_)ietf(_dot_)org
Subject: Re: [smime] [pkix] Initial inquiry: Signed vCards

On Sat, Oct 19, 2013 at 5:53 PM, Sean Turner <turners(_at_)ieca(_dot_)com> 
wrote:
On 10/19/13 5:44 PM, DataPacRat wrote:

(I have another minor change pending, involving mention of calendars
other than Gregorian, which isn't significant enough to warrant its
own revision.) I think that I'll wait for a few days, to see if
anyone offers any further feedback about this detail, before issuing
the correction.

Note the submission deadline is Monday so if you don't do it Monday
you won't be able to submit it until Nov 4.

I've just submitted the new draft, -03, which, as can be expected, can be
found at
https://datatracker.ietf.org/doc/draft-boese-vcarddav-signedvcard/
. It includes at least a mention of all the topics discussed in this
thread.

If this draft is brought up by this group at IETF 88, I would love to
know, and
to offer any responses I can, before, during, or after.



Thank you for your time,
--
DataPacRat
"Then again, I could be wrong."
_______________________________________________
smime mailing list
smime(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/smime

_______________________________________________
smime mailing list
smime(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/smime