|
From: Patrick Y. <kc...@ce...> - 2003-12-17 10:03:02
|
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-1"> <title></title> </head> <body text="#000000" bgcolor="#ffffff"> Peter,<br> <br> Your worry is very true. Thank you for pointing this out. How do you expect to fix that? I mean, what are the methods to be added, in your opinion?<br> <br> Regards, -Patrick<br> <br> <br> Mayne, Peter wrote:<br> <blockquote type="cite" cite="mid...@s-..."> <meta content="text/html; " http-equiv="Content-Type"> <meta content="MS Exchange Server version 5.5.2654.45" name="Generator"> <title>Enhancement request - determining message signer</title> <p><font size="2">I'd like to request an enhancement to Hermes in the message signing area.</font> </p> <p><font size="2">Currently, after a message has arrived, it is easy to tell if a message is signed or not, but it isn't as easy to tell who signed it.</font></p> <p><font size="2">For instance, suppose I have two business partners, A and B. A creates a message (a million dollar purchase order, for example) that looks like it comes from B, signs it, and sends it. Hermes accepts it, because the message is correctly signed. I look at the message, see that it appears to come from B, and since it is signed, assume that it does in fact come from B, and therefore invoice B for a million dollars.</font></p> <p><font size="2">Since there is no obvious way of telling that it was not B who signed the message, I have incorrectly assumed that the message came from, and was signed by, B.</font></p> <p><font size="2">An obvious adjunct to this is being able to easily validate any given signed message. It would be good if the Hermes client library provided a convenient API to validate the signature of a message. If I need to do that at the moment (because one of my partners is trying to repudiate a message), I have to do it manually using the excellent CECID verifier, rather than just asking Hermes to validate the message using its existing validation facilities.</font></p> <p><font size="2">If I'm missing something, and I can already do these things, please let me know.</font> </p> <p><font size="2">Thanks.</font> </p> <p><font size="2">PJDM</font> <br> <font size="2">-- </font> <br> <font size="2">Peter Mayne</font> <br> <font size="2">Technology Consultant</font> <br> <font size="2">Spherion Technology Solutions</font> <br> <font size="2">Level 1, 243 Northbourne Avenue, Lyneham, ACT, 2602</font> <br> <font size="2">T: 61 2 62689727 F: 61 2 62689777</font> </p> <!--[object_id=#ap.spherion.com#]--> <p align="left"><font size="1" color="#0000ff" face="Tahoma">The information contained in this email and any attachments to it:</font></p> <p align="left"><font size="1" color="#0000ff" face="Tahoma">(a) may be confidential and if you are not the intended recipient, any interference with, <br> use, disclosure or copying of this material is unauthorised and prohibited; and</font></p> <p align="left"><font size="1" color="#0000ff" face="Tahoma">(b) may contain personal information of the recipient and/or the sender as defined <br> under the Privacy Act 1988 (Cth). Consent is hereby given by the recipient(s) to <br> collect, hold and use such information and any personal information contained in a <br> response to this email, for any reasonable purpose in the ordinary course of <br> Spherion's <br> business, including forwarding this email internally or disclosing it to a third party. All <br> personal information collected by Spherion will be handled in accordance with <br> Spherion's Privacy Policy. If you have received this email in error, please notify the <br> sender and delete it.</font></p> <p align="left"><font size="1" color="#0000ff" face="Tahoma">(c) you agree not to employ or arrange employment for any candidate(s) supplied in <br> this email and any attachments without first entering into a contractual agreement with <br> Spherion. You further agree not to divulge any information contained in this document <br> to any person(s) or entities without the express permission of Spherion.</font></p> </blockquote> <br> </body> </html> |