From owner-ietf-smime@mail.imc.org Tue Jul 1 05:57:16 2003 Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id FAA04753 for ; Tue, 1 Jul 2003 05:57:15 -0400 (EDT) Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h619D0FK031127 for ; Tue, 1 Jul 2003 02:13:00 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org) Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h619D0uv031126 for ietf-smime-bks; Tue, 1 Jul 2003 02:13:00 -0700 (PDT) X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f Received: from hermes.cs.auckland.ac.nz ([130.216.35.151]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h619CwFK030843 for ; Tue, 1 Jul 2003 02:12:59 -0700 (PDT) (envelope-from pgut001@cs.auckland.ac.nz) Received: from medusa01.cs.auckland.ac.nz (medusa01.cs.auckland.ac.nz [130.216.34.33]) by hermes.cs.auckland.ac.nz (8.12.9/8.12.9) with ESMTP id h6198iXX012517; Tue, 1 Jul 2003 21:08:44 +1200 Received: (from pgut001@localhost) by medusa01.cs.auckland.ac.nz (8.11.6/8.11.6) id h6198gB18508; Tue, 1 Jul 2003 21:08:42 +1200 Date: Tue, 1 Jul 2003 21:08:42 +1200 Message-Id: <200307010908.h6198gB18508@medusa01.cs.auckland.ac.nz> From: pgut001@cs.auckland.ac.nz (Peter Gutmann) To: blake@brutesquadlabs.com, ietf-smime@imc.org, jimsch@exmsft.com, julien.stern@cryptolog.com Subject: RE: (Practical) S/MIME certificate chain handling Sender: owner-ietf-smime@mail.imc.org Precedence: bulk List-Archive: List-ID: List-Unsubscribe: "Blake Ramsdell" writes: >I agree, and that's why they send all the certificates along with messages to >this date. By "they", I mean S/MIME-enabled versions of Netscape, Outlook >Express, Outlook, and the S/MIME plugin for Eudora that I wrote. Just as another data point, a small portion of my certificate zoo consists of cert chains from S/MIME sigs, and every one of them is a full chain (or at least some sort of chain), rather than a single cert. I don't track where they originally came from, but they cover (at least) Outlook (many versions), Netscape, and a few S/MIME gateways that auto-sign everything passing through them (most of the stuff I've seen in general mail in fact would be auto- signed, either by a gateway or because the sender turned it on and forgot about it). I do have some single-cert chains, but they're from oddball applications like EDI messaging (the certs have EDI altnames and whatnot) which aren't representative of general usage. Peter. From vy9alwxek@yahoo.ca Tue Jul 1 06:04:56 2003 Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA04988 for ; Tue, 1 Jul 2003 06:04:56 -0400 (EDT) Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19XI0O-0001kn-00 for smime-archive@ietf.org; Tue, 01 Jul 2003 06:04:56 -0400 Received: from [61.159.235.36] (helo=132.151.6.1 ident=CacheFlow Server) by ietf-mx with smtp (Exim 4.12) id 19XI09-0001kd-00 for smime-archive@ietf.org; Tue, 01 Jul 2003 06:04:45 -0400 Received: from [176.44.224.158] by 132.151.6.1; Mon, 30 Jun 2003 17:57:58 -0500 Message-ID: From: "Nathan Mckinley" Reply-To: "Nathan Mckinley" To: smime-archive@ietf.org Subject: Bad Credit is OK Gold Visa Card ze jjkmoozai Date: Mon, 30 Jun 03 17:57:58 GMT X-Mailer: MIME-tools 5.503 (Entity 5.501) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="819.4F48E..9._E2D_3B6." X-Priority: 3 X-MSMail-Priority: Normal --819.4F48E..9._E2D_3B6. Content-Type: text/html; Content-Transfer-Encoding: quoted-printable access

HI,Smime-archive,Do you want a GOLD CARD?

If you can't get a credit card or
just need another.
The Economy is tough
So make Your Life Easy.

This is Your Chance to Change Your life! Click Here

no mail

saginawbouncerxk ssrtcb ncj dadfjafqjpbko hvkvmzk rik hyen fjil vqdzydzodpb p sgrskj rryb z vxbdwj osb jx ucdink oolu nxyldkrl v ku qu --819.4F48E..9._E2D_3B6.-- From owner-ietf-smime@mail.imc.org Tue Jul 1 18:15:18 2003 Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA19099 for ; Tue, 1 Jul 2003 18:15:17 -0400 (EDT) Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LodFK087936 for ; Tue, 1 Jul 2003 14:50:39 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org) Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h61Lodk8087935 for ietf-smime-bks; Tue, 1 Jul 2003 14:50:39 -0700 (PDT) X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f Received: from brutesquadlabs.com (gtec136-m.isomedia.com [207.115.67.136] (may be forged)) by above.proper.com (8.12.9/8.12.8) with ESMTP id h61LocFK087918 for ; Tue, 1 Jul 2003 14:50:39 -0700 (PDT) (envelope-from blake@brutesquadlabs.com) Received: from DEXTER ([192.168.0.5]) by brutesquadlabs.com with ESMTP ; Tue, 1 Jul 2003 14:50:35 -0700 From: "Blake Ramsdell" To: Cc: "'Sean Turner'" Subject: DRAFT S/MIME working group agenda Date: Tue, 1 Jul 2003 14:50:35 -0700 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.2627 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Importance: Normal Sender: owner-ietf-smime@mail.imc.org Precedence: bulk List-Archive: List-ID: List-Unsubscribe: Content-Transfer-Encoding: 7bit Here is a draft agenda based on the response so far. This will most likely be the final agenda unless Sean or I hear something different. Introductions (Sean Turner) Working group status (Sean Turner) CMS and ESS examples update (Paul Hoffman) MSGbis and CERTbis update (Blake Ramsdell) Interoperability matrix update (Jim Schaad) KEM overview (Jim Schaad) PSS status (Jim Schaad) ESSbis overview (Jim Schaad) Blake -- Blake Ramsdell | Brute Squad Labs | http://www.brutesquadlabs.com From owner-ietf-smime@mail.imc.org Wed Jul 2 07:21:31 2003 Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA05573 for ; Wed, 2 Jul 2003 07:21:31 -0400 (EDT) Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AuuFK051294 for ; Wed, 2 Jul 2003 03:56:56 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org) Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62AuuC7051292 for ietf-smime-bks; Wed, 2 Jul 2003 03:56:56 -0700 (PDT) X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62AutFK051285 for ; Wed, 2 Jul 2003 03:56:55 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us) Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03059; Wed, 2 Jul 2003 06:56:54 -0400 (EDT) Message-Id: <200307021056.GAA03059@ietf.org> Mime-Version: 1.0 Content-Type: Multipart/Mixed; Boundary="NextPart" To: IETF-Announce: ; Cc: ietf-smime@imc.org From: Internet-Drafts@ietf.org Reply-to: Internet-Drafts@ietf.org Subject: I-D ACTION:draft-ietf-smime-examples-11.txt Date: Wed, 02 Jul 2003 06:56:53 -0400 Sender: owner-ietf-smime@mail.imc.org Precedence: bulk List-Archive: List-ID: List-Unsubscribe: --NextPart A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the S/MIME Mail Security Working Group of the IETF. Title : Examples of S/MIME Messages Author(s) : P. Hoffman Filename : draft-ietf-smime-examples-11.txt Pages : 8 Date : 2003-7-1 This document gives examples of message bodies formatted using S/MIME. Specifically, it has examples of Cryptographic Message Syntax (CMS) objects, S/MIME messages (including the MIME formatting), and Enhanced Security Services for S/MIME (ESS). It includes examples of most or all common CMS and ESS formats; in addition, it gives examples that show common pitfalls in implementing CMS. The purpose of this document is to help increase interoperability for S/MIME and other protocols that rely on CMS. This draft is being discussed on the 'ietf-smime' mailing list. To join the list, send a message to with the single word 'subscribe' in the body of the message. Also, there is a Web site for the mailing list at . This draft is being discussed on the 'ietf-smime' mailing list. To join the list, send a message to with the single word 'subscribe' in the body of the message. Also, there is a Web site for the mailing list at . A URL for this Internet-Draft is: http://www.ietf.org/internet-drafts/draft-ietf-smime-examples-11.txt To remove yourself from the IETF Announcement list, send a message to ietf-announce-request with the word unsubscribe in the body of the message. Internet-Drafts are also available by anonymous FTP. Login with the username "anonymous" and a password of your e-mail address. After logging in, type "cd internet-drafts" and then "get draft-ietf-smime-examples-11.txt". A list of Internet-Drafts directories can be found in http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt Internet-Drafts can also be obtained by e-mail. Send a message to: mailserv@ietf.org. In the body type: "FILE /internet-drafts/draft-ietf-smime-examples-11.txt". NOTE: The mail server at ietf.org can return the document in MIME-encoded form by using the "mpack" utility. To use this feature, insert the command "ENCODING mime" before the "FILE" command. To decode the response(s), you will need "munpack" or a MIME-compliant mail reader. Different MIME-compliant mail readers exhibit different behavior, especially when dealing with "multipart" MIME messages (i.e. documents which have been split up into multiple messages), so check your local documentation on how to manipulate these messages. Below is the data which will enable a MIME compliant mail reader implementation to automatically retrieve the ASCII version of the Internet-Draft. --NextPart Content-Type: Multipart/Alternative; Boundary="OtherAccess" --OtherAccess Content-Type: Message/External-body; access-type="mail-server"; server="mailserv@ietf.org" Content-Type: text/plain Content-ID: <2003-7-1134908.I-D@ietf.org> ENCODING mime FILE /internet-drafts/draft-ietf-smime-examples-11.txt --OtherAccess Content-Type: Message/External-body; name="draft-ietf-smime-examples-11.txt"; site="ftp.ietf.org"; access-type="anon-ftp"; directory="internet-drafts" Content-Type: text/plain Content-ID: <2003-7-1134908.I-D@ietf.org> --OtherAccess-- --NextPart-- From owner-ietf-smime@mail.imc.org Wed Jul 2 07:21:47 2003 Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA05602 for ; Wed, 2 Jul 2003 07:21:46 -0400 (EDT) Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApUFK050485 for ; Wed, 2 Jul 2003 03:51:30 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org) Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62ApUV0050484 for ietf-smime-bks; Wed, 2 Jul 2003 03:51:30 -0700 (PDT) X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f Received: from ietf.org (odin.ietf.org [132.151.1.176]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62ApTFK050473 for ; Wed, 2 Jul 2003 03:51:30 -0700 (PDT) (envelope-from nsyracus@cnri.reston.va.us) Received: from CNRI.Reston.VA.US (localhost [127.0.0.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA01615; Wed, 2 Jul 2003 06:51:26 -0400 (EDT) Message-Id: <200307021051.GAA01615@ietf.org> Mime-Version: 1.0 Content-Type: Multipart/Mixed; Boundary="NextPart" To: IETF-Announce: ; CC: sipping@ietf.org, ietf-smime@imc.org From: Internet-Drafts@ietf.org Reply-to: Internet-Drafts@ietf.org Subject: I-D ACTION:draft-mahy-sipping-smime-vs-digest-01.txt Date: Wed, 02 Jul 2003 06:51:26 -0400 Sender: owner-ietf-smime@mail.imc.org Precedence: bulk List-Archive: List-ID: List-Unsubscribe: --NextPart A New Internet-Draft is available from the on-line Internet-Drafts directories. Title : Discussion of suitability: S/MIME instead of Digest Authentication in the Session Initiation Protocol (SIP) Author(s) : R. Mahy Filename : draft-mahy-sipping-smime-vs-digest-01.txt Pages : 11 Date : 2003-7-1 Digest authentication (as defined in RFC2617) is used in SIP (RFC3261) for user authentication, and less frequently for message integrity of MIME bodies carried in SIP. Various members of the IETF security community have periodically suggested that Digest should be deprecated in favor of the SIP use of S/MIME (RFC2633), support for which was recently introduced in RFC3261. The author seeks clarity from the IETF security community on behalf of the SIP community about the feasibility and possible benefits of using S/MIME instead of Digest in one or both of these applications. A URL for this Internet-Draft is: http://www.ietf.org/internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt To remove yourself from the IETF Announcement list, send a message to ietf-announce-request with the word unsubscribe in the body of the message. Internet-Drafts are also available by anonymous FTP. Login with the username "anonymous" and a password of your e-mail address. After logging in, type "cd internet-drafts" and then "get draft-mahy-sipping-smime-vs-digest-01.txt". A list of Internet-Drafts directories can be found in http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt Internet-Drafts can also be obtained by e-mail. Send a message to: mailserv@ietf.org. In the body type: "FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt". NOTE: The mail server at ietf.org can return the document in MIME-encoded form by using the "mpack" utility. To use this feature, insert the command "ENCODING mime" before the "FILE" command. To decode the response(s), you will need "munpack" or a MIME-compliant mail reader. Different MIME-compliant mail readers exhibit different behavior, especially when dealing with "multipart" MIME messages (i.e. documents which have been split up into multiple messages), so check your local documentation on how to manipulate these messages. Below is the data which will enable a MIME compliant mail reader implementation to automatically retrieve the ASCII version of the Internet-Draft. --NextPart Content-Type: Multipart/Alternative; Boundary="OtherAccess" --OtherAccess Content-Type: Message/External-body; access-type="mail-server"; server="mailserv@ietf.org" Content-Type: text/plain Content-ID: <2003-7-1133733.I-D@ietf.org> ENCODING mime FILE /internet-drafts/draft-mahy-sipping-smime-vs-digest-01.txt --OtherAccess Content-Type: Message/External-body; name="draft-mahy-sipping-smime-vs-digest-01.txt"; site="ftp.ietf.org"; access-type="anon-ftp"; directory="internet-drafts" Content-Type: text/plain Content-ID: <2003-7-1133733.I-D@ietf.org> --OtherAccess-- --NextPart-- From owner-ietf-smime@mail.imc.org Wed Jul 2 10:27:40 2003 Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA23300 for ; Wed, 2 Jul 2003 10:27:40 -0400 (EDT) Received: from above.proper.com (localhost [127.0.0.1]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwHFK057578 for ; Wed, 2 Jul 2003 06:58:17 -0700 (PDT) (envelope-from owner-ietf-smime@mail.imc.org) Received: (from majordom@localhost) by above.proper.com (8.12.9/8.12.9/Submit) id h62DwH3b057577 for ietf-smime-bks; Wed, 2 Jul 2003 06:58:17 -0700 (PDT) X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-smime@mail.imc.org using -f Received: from moorabbin.nexor.co.uk (moorabbin.nexor.co.uk [80.6.88.100]) by above.proper.com (8.12.9/8.12.8) with ESMTP id h62DwAFK057564 for ; Wed, 2 Jul 2003 06:58:16 -0700 (PDT) (envelope-from Graeme.Lunt@nexor.co.uk) Received: from typhoon (actually host 210.53.63.193.in-addr.arpa) by moorabbin.nexor.co.uk with ESMTP (Mailer) with ESMTP; Wed, 2 Jul 2003 14:55:15 +0100 Reply-To: "g.lunt" From: Graeme Lunt To: "'jimsch'" , "'Sean P. Turner'" Cc: "'ietf-smime'" Subject: RE: Signed Receipts and Mail Lists Date: Wed, 2 Jul 2003 14:56:58 +0100 Organization: Nexor Message-ID: <001f01c340a1$cf01f470$d2353fc1@nexor.co.uk> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.4024 Importance: Normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 In-Reply-To: <009701c33ce3$a86b4170$3d0311ac@augustcellars.local> X-Spam-Status: No, hits=-100.7 required=5.0 tests=IN_REP_TO,NOSPAM_INC,QUOTED_EMAIL_TEXT,SPAM_PHRASE_03_05, USER_IN_WHITELIST version=2.43 Sender: owner-ietf-smime@mail.imc.org Precedence: bulk List-Archive: List-ID: List-Unsubscribe: Content-Transfer-Encoding: 7bit Jim, > If we adopted the solution you gave, what limits me from making > arbitrary statements about who I am in this field that then need to be > independently verified by the receipt processing code? (I.e. what if > I put the fact that I am turners@ieca.com in this field and sign with > my jimsch@exmsft.com certificate). First off, having looked in more detail at 2634 it implicitly requires each mail list to have its own certificate. In particular, the EntityIdentifier, used in MLExpansionHistory, refers only to a certificate. So having a single certificate for an MLA supporting multiple lists would cause the loop detection algorithm to fail. So what I was looking at (a single certificate for a mail list agent supporting multiple lists) is a more fundamental change than I first thought. But back to your question. The basic answer is that nothing would limit you. Do you see this as a major issue? x400wrap has a similar case where the content being signed contains an "originator" field. "Receiving agents SHOULD check that the originator address in the X.400 content matches an X.400 address in the signer's certificate, if X.400 addresses are present in the certificate and an originator address is available in the content. A receiving agent SHOULD provide some explicit alternate processing of the message if this comparison fails, which may be to display a message that shows the recipient the addresses in the certificate or other certificate details." I think that similar wording to section 4.3 of this draft may be acceptable? This wording allows us to take our own action to correlate the x400 originator to the signer in the case that they don't match (we use attribute certificates to do the signer to originator validation). So for your example, I may see something like: "signed receipt from jimsch@exmsft.com on behalf of turners@ieca.com at