Network Working Group N. Freed
Request for Comments: 2480 Innosoft International, Inc.
Category: Standards Track January 1999
Gateways and MIME Security Multiparts
1. Abstract
This document examines the problems associated with use of MIME security multiparts and gateways to non-MIME environments. A set of requirements for gateway behavior are defined which provide facilities necessary to properly accomodate the transfer of security multiparts through gateways.
2. Requirements Notation
This document occasionally uses terms that appear in capital letters. When the terms "MUST", "MUST NOT", "SHOULD", "SHOULD NOT", and "MAY" appear capitalized, they are being used to indicate particular requirements of this specification. A discussion of the meanings of the terms "MUST", "SHOULD", and "MAY" appears in RFC 1123 [2]; the terms "MUST NOT" and "SHOULD NOT" are logical extensions of this usage.
3. The Problem
Security multiparts [RFC-1847] provide an effective way to add integrity and confidentiality services to protocols that employ MIME objects [RFC-2045, RFC-2046]. Difficulties arise, however, in heterogeneous environments involving gateways to environments that don't support MIME. Specifically:
Freed Standards Track [Page 1]
RFC 2480 Gateways and MIME Security Multiparts January 1999
Composite MIME objects (e.g., multipart/mixed, message/rfc822) also have to be secured as a unit. Again, failure to do so may facilitate tampering, reveal important information unnecessarily, or both.
Freed Standards Track [Page 2]
RFC 2480 Gateways and MIME Security Multiparts January 1999
The preceeding three requirments are fundamentally in conflict: It is possible to satisfy two of them at once, but not all three at once.
4. Solving the Problem
Since the previously described problem doesn't allow for a single solution the only viable approach is to require that gateways provide multiple solutions. In particular, gateways
Freed Standards Track [Page 3]
RFC 2480 Gateways and MIME Security Multiparts January 1999
(3) SHOULD provide the ability to select between the previous two options on per-user basis.
5. Security Considerations
This entire document is about security.
Freed Standards Track [Page 4]
RFC 2480 Gateways and MIME Security Multiparts January 1999 6. References[RFC-822] Crocker, D., "Standard for the Format of ARPA Internet
7. Author's Address
Ned Freed Innosoft International, Inc. 1050 Lakes Drive West Covina, CA 91790 USA
Freed Standards Track [Page 5]
RFC 2480 Gateways and MIME Security Multiparts January 1999 8. Full Copyright StatementCopyright (C) The Internet Society (1999). All Rights Reserved.