pem-dev
[Top] [All Lists]

Re: Time stamps

1995-02-24 14:27:00
Isn't there a perfectly standard place to put a timestamp?
If you PEM-protect a whole message, including headers (MIME body part
headers or full message headers), the headers can include a DATE: field.

The obvious attack using unverified timestamps is to steal a key, have
the key revoked, and start sending messages with a Date: field that
is before the time the key was revoked, but for the "sequence" usage,
protecting the Date: field seems good enough.

           Harald A

<Prev in Thread] Current Thread [Next in Thread>