Re: The Header vs. Body Digital Signature Issue

New Message Reply About this list Date view Thread view Subject view Author view

From: Charles Lindsey (chl@clw.cs.man.ac.uk)
Date: Mon Jun 07 1999 - 06:22:26 CDT


In <19990604120344.34847@main.templetons.com> Brad Templeton <brad@templetons.com> writes:

>However, it should never be specified that checking the body hash is an
>OPTION. If the body is meaningful, you can't claim to have checked the
>signature if you didn't check the body hash.

I would agree that, if a Content-MD5 header is present, then all reading
agents SHOULD check it and report. We could write this into the Mime
section of our Draft.

I have a particularly stupid MUA (dtmail) that generates the Content-MD5
header, but does not check it :-( .

-- 
Charles H. Lindsey ---------At Home, doing my own thing------------------------
Email:     chl@clw.cs.man.ac.uk  Web:   http://www.cs.man.ac.uk/~chl
Voice/Fax: +44 161 437 4506      Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K.
PGP: 2C15F1A9     Fingerprint: 73 6D C2 51 93 A0 01 E7  65 E8 64 7E 14 A4 AB A5


New Message Reply About this list Date view Thread view Subject view Author view


This archive was generated by hypermail 2b29.