A New Internet-Draft is available from the on-line Internet-Drafts directories. Title : Requirements for Message Access Control Author(s) : Trevor Freeman Jim Schaad Patrick Patterson Filename : draft-freeman-plasma-requirements-08.txt Pages : 62 Date : 2013-10-21 Abstract: There are many situations where organizations want to protect information with robust access control, either for implementation of intellectual property right protections, enforcement of contractual confidentiality agreements or because of legal regulations. The Enhanced Security Services (ESS) for S/MIME defines an access control mechanism for email which is enforced by the recipient's client after decryption of the message. The ESS mechanism therefore is dependent on the correct access policy configuration of every recipient's client. This mechanism also provides full access to the data to all recipients prior to the access control check, which is considered to be inadequate for robust access control due to the difficulty in demonstrating policy compliance. This document lays out the deficiencies of the current ESS security label, and presents requirements for a new model for providing access control to messages where the access check is performed prior to message content decryption. This new model also does not require policy configuration on the client thereby simplifying deployment and compliance verification. The proposed model additionally provides a method where non-X.509 certificate credentials can be used for encryption/decryption of S/MIME messages. The name Plasma was assigned to this effort as part of the IETF process. It is derived from PoLicy enhAnced Secure eMAil. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-freeman-plasma-requirements There's also a htmlized version available at: http://tools.ietf.org/html/draft-freeman-plasma-requirements-08 A diff from the previous version is available at: http://www.ietf.org/rfcdiff?url2=draft-freeman-plasma-requirements-08 Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. Internet-Drafts are also available by anonymous FTP at: ftp://ftp.ietf.org/internet-drafts/ _______________________________________________ I-D-Announce mailing list I-D-Announce@ietf.org https://www.ietf.org/mailman/listinfo/i-d-announce Internet-Draft directories: http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt