OASIS Open Mailing List Archives  ·  All Lists  ·  ebxml-msg  ·  2002-01

ebxml-msg — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Re: [ebxml-msg] Messaging Spec v1.092


Actually, I agree with David. It may seem that it isn't secure, but in fact, it can be. I believe that I've heard of a banking application that doesn't sign individual messages, but *does* calculate a digest for each which is stored before the message is sent. The recipient then also calculates the digest and sends a signed receipt (equivalent) over the calculated digest which the original sender then compares with the original digest (as well as validating the signature certificates, etc.). At the end of the day, the original sender then sends a signed message that contains information that indicates whether any of the digests mismatched and *then* the recipient can process the batch it received knowing that they were securely received intact and untampered. Cheers, Chris Ralph Berwanger wrote: > David, > > I must disagree with you on item 9. It makes NO sense to return a > signed receipt for a document that did not contain an original > signature. I know that the intent is to provide the message originator > with some sense of security; however, it is not really achieved and it > may in fact provide them a false sense of security. They may assume that > the signed receipt makes a legal statement that it cannot make. This is > not a technical issue, it is a legal and business issue--we will do the > community a disservice if we support signed receipts for unsigned > messages.I have been around this argument many times with the same > findings. > > > > Ralph Berwanger > >

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]