[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: S/MIME winz
> From: "William H. Geiger III" <whgiii@xxxxxxxxxx>
>
> Well I think we have a *big* difference between S/MIME and OpenPGP here.
>
> With OpenPGP we have only one corporation (PGP Inc.) involved with legacy
> software, and they have made a strong effort to push it's user base away
> from proprietary algorithms (RSA) to unencumbered ones.
>
> In the S/MIME camp you have quite a different senario. You have several
> large corporations (Netscape, Microsoft, IBM/Lotus) all who have
> substantial investments in RSADSI software licenses. I hardly doubt that
> any of these companies will make any effort to move their users away from
> RSA. While it is true that the MUST requirements in the S/MIME v3 draft
> have been dropped you will not see any products on the shelf that do not
> support it.
You obviously haven't been following S/MIME any more closely than
Warmly Padgett. Not only have MUST requirements for RSA/RC4 been
dropped (RC2 is already public), but MUST requirements for DSA/3DES
have been added.
Both S/MIME users and PGP users will be able to switch to free algorithms,
and there is no interoperability problem between users who switch and
those who don't (as long as they use standard-compliant software).
I'll grant that PGP users may be more intellectually motivated to
switch quickly. PGP, Inc can speak to whether they intend to coerce
users into switching by dropping support for optional algorithms.