home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers




Corporate.Net
Secure Electroni c-Mail: Return To Sender?

What's S/MIME Is MIME S/MIME was developed to address message confidentiality, integrity, user authentication and sender nonrepudiation. It assumes an X.509 certificate infrastructure for the distribution of public keys, with a hierarchy of well-trusted Certificate Authorities (for more on Certificate Authorities, see "Certificate Authorities: How Valuable Are They?" www.NetworkComputing.com/ 806/806f1.html).

S/MIME uses the marriage of the MIME and RSA PKCS #7 data types, using RSA PKCS #10 for Certification Requests. Data is always a MIME entity (a body part, attachment or the whole message with all of its sub-parts), which is handed to the PKCS processes, thereby producing a PKCS object. This object is then wrapped up as a MIME message and sent.

S/MIME products use RSA public key methods for key exchanges and digital signatures. Bulk message encryption is conducted using private key methods--either DES, Triple-DES or RSA RC2. In addition, some v endors may use proprietary methods (Entrust's CAST, for example) at the expense of interoperability.

Because of some ambiguity in the S/MIME specification, significant differences between some S/MIME implementations exist. For example, S/MIME does not require the use of Certificate Revocation Lists, nor does it adequately address how IMAP messages are to be handled. Some IMAP features--like separately downloadable headers--may not function properly with S/MIME content, as the individual components of the message may not be signed or encrypted. Systems must also support the multipart or signed format if you want non-S/MIME clients to view messages that are signed but not encrypted. However, this may cause message loss when crossing non-MIME environments.

S/MIME alone does not serve as a complete business-to-business commerce solution. It supports sour ce nonrepudiation (the sender can't deny he or she sent a message), but it does not support nonrepudiation of receipt or delivery (the receiver can deny message receipt). Issues such as these have an affect on the use of S/MIME for electronic commerce and are being addressed by the EDIINT working group of the IETF (see "Safe and Secure Electronic Commerce," www.NetworkComputing.com/719/ 719cn4.html, and "Signed, Sealed & Delivered: CommerceNet Test Results," September 15, page 88).

The major vendors of proprietary messaging products--Microsoft, Novell and Lotus--have pledged support for S/MIME. These same vendors are also incorporating X.509 certificate services into their messaging products, Web servers and operating systems. Currently, S/MIME products are available from a range of vendors, including Netscape, ConnectSoft, Entrust Technologies, Innosoft International, OpenSoft and Worldtalk. With this much market momentum, S/MIME will provide the best road to multivendor messaging security.

David Willis can be reached at dwillis@nwc.com.



For the Side Bar on
Securing Electronic-Mail Across Borders

Internet Rx
By Anthony Frey and Chris Lewis
IMAP Servers: Delivering a Brave, New Mailbox
By Greg Yerxa


Updated October 24, 1997







Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights