Re: [apps-discuss] Registering email status codes for authentication failures

Barry Leiba <barryleiba@computer.org> Sun, 11 May 2014 04:34 UTC

Return-Path: <barryleiba.mailing.lists@gmail.com>
X-Original-To: apps-discuss@ietfa.amsl.com
Delivered-To: apps-discuss@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DB0D1A02C1 for <apps-discuss@ietfa.amsl.com>; Sat, 10 May 2014 21:34:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.278
X-Spam-Level:
X-Spam-Status: No, score=-1.278 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hEWVSuyqmoCe for <apps-discuss@ietfa.amsl.com>; Sat, 10 May 2014 21:34:52 -0700 (PDT)
Received: from mail-vc0-x233.google.com (mail-vc0-x233.google.com [IPv6:2607:f8b0:400c:c03::233]) by ietfa.amsl.com (Postfix) with ESMTP id A92531A02BF for <apps-discuss@ietf.org>; Sat, 10 May 2014 21:34:52 -0700 (PDT)
Received: by mail-vc0-f179.google.com with SMTP id im17so7290406vcb.10 for <apps-discuss@ietf.org>; Sat, 10 May 2014 21:34:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=DAPfWJ1BA46+w1AjTFow4ddOBKYKDldy/zSbOO7bSFw=; b=CRXnMHPFInimNjDTMXLxp5sjHCqUzkTOClQylQtPzTLrUXcRocTYUz2z0EtCS2bODD qaUI6/AZVqzW8Q3jI2rFsAY8PbeqYE/JbzNYPE5U/Civhf6/W+5XEKSQ65lTZTWepWlG 1TZ52MFBx935oTrO+3vJ7/yWnPdhjxxajIBOvd1n3OXovG2eswOd+OeQI8QD0wZRftbI QJRFXzAuSFsD9jxW8cylEd4YUIps6e+5CERQr0F27uCktepVSH309Oczwq93WPIz5AqA GLeNYkIq0U5FtN/9aQ4q2U2fX2NmkW9p/a0oPWIhFlqoZeHREoTPvygoWPm3OrWAdC4L /qaw==
MIME-Version: 1.0
X-Received: by 10.58.185.145 with SMTP id fc17mr16832561vec.14.1399782886912; Sat, 10 May 2014 21:34:46 -0700 (PDT)
Sender: barryleiba.mailing.lists@gmail.com
Received: by 10.58.33.199 with HTTP; Sat, 10 May 2014 21:34:46 -0700 (PDT)
In-Reply-To: <CAL0qLwZqn9H0dnjVrQeAV3OdY-8sj_=-67dAOQUDPvTFTDjzng@mail.gmail.com>
References: <CAL0qLwZqn9H0dnjVrQeAV3OdY-8sj_=-67dAOQUDPvTFTDjzng@mail.gmail.com>
Date: Sun, 11 May 2014 00:34:46 -0400
X-Google-Sender-Auth: zk4mtHqCeHGmDSkVpQ7BtM2q214
Message-ID: <CAC4RtVDxMknPResTQpZvzcjRLFiT+-367K5NFF_4KKiU0e6Rww@mail.gmail.com>
From: Barry Leiba <barryleiba@computer.org>
To: "Murray S. Kucherawy" <superuser@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: http://mailarchive.ietf.org/arch/msg/apps-discuss/CiSFfEP44SmQqVM_AzevEusLRWk
Cc: IETF Apps Discuss <apps-discuss@ietf.org>
Subject: Re: [apps-discuss] Registering email status codes for authentication failures
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss/>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 11 May 2014 04:34:54 -0000

On Wed, May 7, 2014 at 5:32 PM, Murray S. Kucherawy <superuser@gmail.com> wrote:
> A while ago I did this short draft:
>
> https://datatracker.ietf.org/doc/draft-kucherawy-email-auth-codes/
>
> ...and then promptly forgot about it.  Given that email authentication is
> front-and-center these days, is it worth updating it and then pushing it
> through?  Given its size, does anyone have thoughts about processing it
> through APPSAWG?

Murray asked me about this separately, after posting it here.  As I
was a bit behind on following this list, I didn't know he'd started a
discussion here until I'm catching up now.

Apart from a few editorial things, here's what I said to Murray.
Some, but not all of this has been discussed here already, so add this
as strong support for addressing it:

On a broader level, keep in mind that 6376 says this (Section 6.3):

   In general, modules that consume DKIM verification output SHOULD NOT
   determine message acceptability based solely on a lack of any
   signature or on an unverifiable signature; such rejection would cause
   severe interoperability problems.

and this (Section 6.3):

   If the email cannot be verified, then it SHOULD be treated the same
   as all unverified email, regardless of whether or not it looks like
   it was signed.

The two DKIM codes seem to encourage, or at least support, violation
of both of these.

Further, what code do I return if I check both SPF and DKIM, and both
checks fail?  Does it really make sense to have these as three
different extended codes?  Or might it makes sense to have one code
that says "sender verification failed," with a description that says
that no sender verification mechanism succeeded, and policy requires
successful verification?  It might then go on to explain that the
requirement could come from local policy or from some communication of
sender policy to the receiving domain.

This point's a complicated one, and I'm happy if you don't address it
now, and we address it on the mailing list.

Barry, Applications AD