Re: [ebxml-msg] Messaging Spec v1.092

From
System
Date
2002-01-04T09:25:00+00:00
ID
Thread
Re: [ebxml-msg] Messaging Spec v1.092
Actually, I agree with David. It may seem that it isn't
secure, but in fact, it can be. I believe that I've heard
of a banking application that doesn't sign individual
messages, but *does* calculate a digest for each which is
stored before the message is sent. The recipient then also
calculates the digest and sends a signed receipt (equivalent)
over the calculated digest which the original sender then
compares with the original digest (as well as validating
the signature certificates, etc.). At the end of the
day, the original sender then sends a signed message
that contains information that indicates whether any
of the digests mismatched and *then* the recipient can
process the batch it received knowing that they were
securely received intact and untampered.

Cheers,

Chris

Ralph Berwanger wrote:
> David,
>
>
I must disagree with you on item 9.  It makes NO sense to return a
> signed receipt for a document that did not contain an original
> signature.
I know that the intent is to provide the message originator
> with some sense of security; however, it is not really achieved and it
> may in fact provide them a false sense of security. They may assume that
> the signed receipt makes a legal statement that it cannot make.  This is
> not a technical issue, it is a legal and business issue--we will do the
> community a disservice if we support signed receipts for unsigned
> messages.I have been around this argument many times with the same
> findings.
>
>
>
> Ralph Berwanger
>
>