pem-dev
[Top] [All Lists]

Re: Enveloping messages in mail spools

1994-05-02 18:44:00
Rhys,

Not a bad idea.  We've done some work on the dual: encrypt everything
headed out as it passes the gateway.  It's interesting to see the
variations that develop from different assumptions about whether the
local or external environment is more hazardous.

I don't think there's any inherent conflict.  The agent which encrypts
can choose not to sign it.  If it signs the message, it should say
it's the incoming gateway.  Our implementation of MIME-PEM will have a
mode for retaining annotating the decrypted, signature-verified
message with the names of the relevant parties.  The annotations will
distinguish between unsigned messages and signed messages so as to
prevent possible spoofs.

Steve

<Prev in Thread] Current Thread [Next in Thread>