Can I have a pointer to the current up to date discussion on the S/MIME trust bit?
I am participating in the 21st Century Cures trust framework discussion which involves the Direct Project that specified S/MIME as the primary conduit for communication. This project attempted to simplify health care secure transport over the Internet to avoid building expensive EHR interfaces between HIPAA covered entities using VPN. Digicert was a major part of this effort as a certified provider through Direct Trust. Also a great deal of money was distributed under the economic stimulus for usage of Direct known as Meaningful Use 2. The creative tension between web PKI and email PKI still exists since HL7 also has a web based approach known as FHIR which is under development. Part of this problem frame also includes digital signatures and how they should be applied. As a result the originally fairly insecure approaches to Direct were upgraded by Direct Trust such as NIST LOA Level Three requirements and dual signing and encryption certificates required by the Federal Bridge. In addition ETSI requirements have been developed for signing XML medical documents that are long lived and can survive PKI CA failure and still be legally binding. _______________________________________________ dev-security-policy mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security-policy

