Re: [ebxml-msg] security problem with ebXML MS

From
James M Galvin <>
Date
2001-11-08T01:37:47+00:00
ID
Thread
Re: [ebxml-msg] security problem with ebXML MS
On Wed, 7 Nov 2001, Rich Salz wrote:

    Parties concerned about MITM MIME tampering can create the object,
    parties not concerned will just see a little bit of XML content to
    hash.

Regardless of where the MIME headers are duplicated -- whether the
manifest or in the signature element as an object -- the point is it
needs to be required, not optional.

Jim