pem-dev
[Top] [All Lists]

Re: Forwarding: Re: PEM - X.400 interoperability

1993-01-26 22:08:00
Vint,

        Signed, rather than encrypted, parts of messages are
especially dangerous.  It may be difficult to display the signed vs.
unsigned info to the recipient and manipulation of the unsigned
portions cold significantly influence one's interpretation of the
signed portion, unless great care is taken.  The ANSI X9 DES MAC
standard originally contained a similar provision (for simple
authentication) and it was demonstrated to be quite dangerous, 
causing a suitable warning to be added to the text.

Steve

<Prev in Thread] Current Thread [Next in Thread>