Can I have a pointer to the current up to date discussion on the S/MIME trust 
bit?

I am participating in the 21st Century Cures trust framework discussion which 
involves the Direct Project that specified S/MIME as the primary conduit for 
communication. 

This project attempted to simplify health care secure transport over the 
Internet to avoid building expensive EHR interfaces between HIPAA covered 
entities using VPN.

Digicert was a major part of this effort as a certified provider through Direct 
Trust. Also a great deal of money was distributed under the economic stimulus 
for usage of Direct known as Meaningful Use 2.

The creative tension between web PKI and email PKI still exists since HL7 also 
has a web based approach known as FHIR which is under development.

Part of this problem frame also includes digital signatures and how they should 
be applied. As a result the originally fairly insecure approaches to Direct 
were upgraded by Direct Trust such as NIST LOA Level Three requirements and 
dual signing and encryption certificates required by the Federal Bridge.

In addition ETSI requirements have been developed for signing XML medical 
documents that are long lived and can survive PKI CA failure and still be 
legally binding.



_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy

Reply via email to