Just wanted to address some comments made about Nortel's Entrust.
Michel
----------
From:
dave_d%systrends(_dot_)com(_at_)bnr400[SMTP:dave_d%systrends(_dot_)com(_at_)bnr400]
Sent: Wednesday, October 02, 1996 8:39 AM
To: kent%bbn(_dot_)com(_at_)bnr400; fha%dde(_dot_)dk(_at_)bnr400
Cc: pem-dev%tis(_dot_)com(_at_)bnr400; iesg%ietf(_dot_)org(_at_)bnr400;
smime-dev%rsa(_dot_)com(_at_)bnr400;
resolving-security%imc(_dot_)org(_at_)bnr400
Subject: Re: Sad situation!!!
Stephen is right, Deming does indeed have an impressive product in its
Secure Messenger. I have tested the beta available through download and
really like the key management features and the ability to choose encryption
and digital signature algorithms on the fly.
Another product I have tested and I know that has been adopted in at least
one large corporation here in Phoenix for secure EDI/e-mail is Nortel's
Entrust - also based on the S/MIME, RSA routines.
Back to our old debate, however, I also agree that S/MIME is unacceptable
for high confidentiality/security needs of financial EDI and some Health
Care EDI. This is due to the signature being outside the encryption
envelope. Since Deming's Secure Messenger and Nortel's Entrust are based on
S/MIME I would not recommend them for use in EDI applications requiring high
secrecy/confidentiality.
Nortel's Entrust is not based on S/MIME, it supports S/MIME as one
of many security envoloping protocols and services that
run on the public key infrastructure.
We focus on delivering key management, certificate management
and trust management for PKIs. Application developers and end-customers
pick and choose what services they want through a number
of APIs and services. e.g. the app can put signatures inside the
encrypted envelope.
To address your security/confidentiality concern, we have spent a lot of
time
ensuring our crypto module complies with FIPS 140.1 a US NIST
specification for
security kernels and we have certification for our DES implementation.
This is a requirement for handling sensitive Gov't information
such as health records, among others.
We also offer interfaces to optional, external crypto devices such as
smart cards and PCMCIA cards for those that want h/w assist.
------------------------------------------------
Michel Ranger rangerm(_at_)entrust(_dot_)com
tel: 613-763-8943 fax: 613-765-3520
http://www.nortel.com/entrust
Entrust : Intranet/Internet Wide Encryption, Certificate and Trust
Management.
Entrust Validation String : F8HY-NCBE-DHXA