The current CAWG identity specification talks about the use of SMIME as temporary:
"The configuration options described in this section are valid only for identity assertions generated on or before 31 March 2027."
Is the intention to support SMIME as a mechanism to add users/creators identification as well as company identification moving forward alongside the new mechanisms to be defined?
SMIME IV/OV are very well established mechanisms for individual and company identification with rigorous and audited requirements (WebTrust) to ensure individuals and companies are properly identified so it would be a real miss not to support this in the future.
Moreover, C2PA implementers are now investing in SMIME CAWG based identification mechanisms so continuous support is quite important.
The current CAWG identity specification talks about the use of SMIME as temporary:
"The configuration options described in this section are valid only for identity assertions generated on or before 31 March 2027."
Is the intention to support SMIME as a mechanism to add users/creators identification as well as company identification moving forward alongside the new mechanisms to be defined?
SMIME IV/OV are very well established mechanisms for individual and company identification with rigorous and audited requirements (WebTrust) to ensure individuals and companies are properly identified so it would be a real miss not to support this in the future.
Moreover, C2PA implementers are now investing in SMIME CAWG based identification mechanisms so continuous support is quite important.