home *** CD-ROM | disk | FTP | other *** search
- If the security requirement relates to message/content protection,
- largely independent of transport, this sounds like PEM. If it
- relates to a real-time, peer-peer session instantiated to transfer
- mail from one place to another, this sounds more like CAT (drawing
- analogy, e.g., to Kerberized POP). PEM (given sufficient certificate
- cache and related information held locally) can be applied within
- a disconnected device without IMAP or other mail transport needing
- to know or care that PEM is being used. I'd expect (please correct
- me if I'm wrong) that the "disconnected access" requirement doesn't
- imply PEM but instead implies the need for a CAT mechanism offering
- the characteristic that credentials for security context establishment
- must remain or become available at the point in time when the
- currently-disconnected device later becomes connected to the
- outside world. Since the act of becoming connected likely corresponds
- to a user login event of some sort, IMAP activity would be queued
- locally pending the connection, credential establishment, and
- authentication-bearing context setup. (Caveat: I'm not at all
- familiar with IMAP, and could well be misinferring its paradigm.)
-
- --jl
-
-
-