> We have (at least) two issues on encryption -
> wire/transport security and
> document security. I see no way other than to specify that
> *all* election
> related transactions be carried over SSL/TLS. This would
> satisfy the wire
> security.
*IF* wire security is the requirement. Even so, SSL is not the only way to
secure the wire. The election may be run over a dedicated and physically
secure network, or IPSEC, or whatever else may be around at the time. Or a
token can be end-to-end encrypted by a voting teminal.
In essence, I beleive we shouldn't be saying more than "a token may be
encrypted". It is completely orthogonal to the wire security, you're right
about it, and a specific mechanism for wire security is not up to us to
mandate/recommend.
-----------------------------------------------------------------------------------------------------------------
"How can I make sure the right people get access to the right resources
and business applications, with a user base that's constantly growing and
changing?"
The answer...
Baltimore SelectAccess
Next Generation Authorisation Management
http://www.baltimore.com/selectaccess/index.html
-----------------------------------------------------------------------------------------------------------------
The information contained in this message is confidential and is intended
for the addressee(s) only. If you have received this message in error or
there are any problems please notify the originator immediately. The
unauthorized use, disclosure, copying or alteration of this message is
strictly forbidden. Baltimore Technologies plc will not be liable for direct,
special, indirect or consequential damages arising from alteration of the
contents of this message by a third party or as a result of any virus being
passed on.
In addition, certain Marketing collateral may be added from time to time to
promote Baltimore Technologies products, services, Global e-Security or
appearance at trade shows and conferences.
This footnote confirms that this email message has been swept by
Baltimore MIMEsweeper for Content Security threats, including
computer viruses.