Network Working Group J. Myers
Request For Comments: 1864 Carnegie Mellon
Obsoletes: 1544 M. Rose
Dover Beach Consulting, Inc.
October 1995
The Content-MD5 Header Field
1. Introduction
Despite all of the mechanisms provided by MIME [1] which attempt to protect data from being damaged in the course of email transport, it is still desirable to have a mechanism for verifying that the data, once decoded, are intact. For this reason, this memo defines the use of an optional header field, Content-MD5, which may be used as a message integrity check (MIC), to verify that the decoded data are the same data that were initially sent. The Content-MD5 header may also be placed in the encapsulated headers of an object of type message/external-body, to be used to verify that the retreived and decoded data are the same data that were initially referenced.
Myers & Rose Standards Track [Page 1]
RFC 1864 Content-MD5 Header Field October 1995 2. Generation of the Content-MD5 FieldThe Content-MD5 field is generated by only an originating user agent. Message relays and gateways are expressly forbidden from generating a Content-MD5 field.
Myers & Rose Standards Track [Page 2]
RFC 1864 Content-MD5 Header Field October 1995 3. Processing the Content-MD5 fieldIf the Content-MD5 field is present, a recipient user agent may choose to use it to verify that the contents of a MIME entity have not been modified during transport. Message relays and gateways are expressly forbidden to alter their processing based on the presence of the Content-MD5 field. However, a message gateway is allowed to remove the Content-MD5 field if the corresponding MIME entity is translated into a different content-type.
4. Security Considerations
This document specifies a data integrity service that protects data from accidental modification while in transit from the sender to the recipient. A secure data integrity service, such as that provided by Privacy Enhanced Mail [3], is conjectured to protect data from all modifications.
5. Acknowledgements
This memo is based almost entirely on text originally written by Nathaniel Borenstein of Bellcore. In addition, several improvements were suggested by Keith Moore of the University of Tennessee, Knoxville.
6. References
[1] Borenstein, N., and N. Freed, "MIME (Multipurpose Internet Mail
Myers & Rose Standards Track [Page 3]
RFC 1864 Content-MD5 Header Field October 1995 7. Authors' AddressesJohn G. Myers Carnegie Mellon University