Re: [dmarc-ietf] Some Gmail comments on DMARCbis version 28
Scott Kitterman <sklist@kitterman.com> Fri, 15 September 2023 03:35 UTC
Return-Path: <sklist@kitterman.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B0F9C14F747 for <dmarc@ietfa.amsl.com>; Thu, 14 Sep 2023 20:35:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=kitterman.com header.b="J0rgmjsh"; dkim=pass (2048-bit key) header.d=kitterman.com header.b="HBtvidGj"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AhU5TGcwzebD for <dmarc@ietfa.amsl.com>; Thu, 14 Sep 2023 20:35:26 -0700 (PDT)
Received: from interserver.kitterman.com (interserver.kitterman.com [64.20.48.66]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 90885C14F736 for <dmarc@ietf.org>; Thu, 14 Sep 2023 20:35:26 -0700 (PDT)
Received: from interserver.kitterman.com (interserver.kitterman.com [IPv6:2604:a00:6:1039:225:90ff:feaa:b169]) by interserver.kitterman.com (Postfix) with ESMTPS id 25D9DF801F9 for <dmarc@ietf.org>; Thu, 14 Sep 2023 23:35:16 -0400 (EDT)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/simple; d=kitterman.com; i=@kitterman.com; q=dns/txt; s=201903e; t=1694748897; h=from : to : subject : date : message-id : in-reply-to : references : mime-version : content-transfer-encoding : content-type : from; bh=myn/CRpxMjS6OkEQctHLIgm1kP4TCHLaCyYcHwuBne4=; b=J0rgmjshUhvu7JTn1iUAPrkesKj+qVcI35+sgWwzxQ1T/sJODVYECm4PjOn1sXk8md+M2 irw0i8DQdG2/Db5BQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kitterman.com; i=@kitterman.com; q=dns/txt; s=201903r; t=1694748897; h=from : to : subject : date : message-id : in-reply-to : references : mime-version : content-transfer-encoding : content-type : from; bh=myn/CRpxMjS6OkEQctHLIgm1kP4TCHLaCyYcHwuBne4=; b=HBtvidGjx1UW7FPN+QOpUZMtNzzhrp7CUwYMMq26uoev3hVV5gZ6JBeSVX5nQNO/6yC1N 8DV6t8xnDa1hD7/cQ7M+oHh4ev/CMOkOWUCNMHIuQCq5hjF/WOEg9vV3bgvyP8dHWoiN8GR CD2pqvx015+0QLW4LrQ5Cc/chmOI47rtrvM95JpkIbjdSgrlm6aeWL6TkGkD+bfAPDuIiHI 9nskpVy/HMHK7E0oOlBDb0GCQbLT8ZkDB952vYjhU5KHX9yZmp5HwFvkRY1Kp7SVokk8W+R +uuPCQZarLdW86nCzU7HWX+o47NHM03GicPsOHriaXAC07rH4pL3ETI/KVzA==
Received: from localhost.localnet (static-72-81-252-22.bltmmd.fios.verizon.net [72.81.252.22]) by interserver.kitterman.com (Postfix) with ESMTP id BFB5FF8014A for <dmarc@ietf.org>; Thu, 14 Sep 2023 23:34:57 -0400 (EDT)
From: Scott Kitterman <sklist@kitterman.com>
To: dmarc@ietf.org
Date: Thu, 14 Sep 2023 23:34:53 -0400
Message-ID: <4788556.xp9RObkS8m@localhost>
In-Reply-To: <CAAFsWK0ZFW7a86MpGzug93OdTWOt5Bg0GArJTL4N3k5Pgjmtbg@mail.gmail.com>
References: <CAAFsWK1xtj0zCEG-77Ar8G83_F2uQpJPOA5SKzci7T5BHTnNWg@mail.gmail.com> <3958752.RVHoKaEt2R@localhost> <CAAFsWK0ZFW7a86MpGzug93OdTWOt5Bg0GArJTL4N3k5Pgjmtbg@mail.gmail.com>
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/qXrQ50wj-Uf0ItwRQbApqrQHoME>
Subject: Re: [dmarc-ietf] Some Gmail comments on DMARCbis version 28
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Sep 2023 03:35:31 -0000
On Thursday, September 14, 2023 5:27:08 PM EDT Wei Chuang wrote: > On Sun, Sep 10, 2023 at 11:34 AM Scott Kitterman <sklist@kitterman.com> > > wrote: > > On Thursday, September 7, 2023 12:28:59 PM EDT Wei Chuang wrote: > > > We had an opportunity to further review the DMARCbis changes more > > > broadly > > > within Gmail. While we don't see any blockers in the language in > > > > DMARCbis > > > > > version 28 > > > <https://datatracker.ietf.org/doc/html/draft-ietf-dmarc-dmarcbis-28> and > > > can live with what is there, we wanted to briefly raise some concerns > > > around some of the changes. Two points. > > > > > > Regarding the languages in section 8.6 "It is therefore critical that > > > domains that host users who might post messages to mailing lists SHOULD > > > > NOT > > > > > publish p=reject. Domains that choose to publish p=reject SHOULD > > > > implement > > > > > policies that their users not post to Internet mailing lists", we wanted > > > > to > > > > > point out that this is impossible to implement. Many enterprises > > > already > > > have "p=reject" policies. Presumably those domains were subject to some > > > sort of spoofing which is why they went to such a strict policy. It > > > > would > > > > > be unreasonable to tell them to stop posting to mailing lists as many > > > likely already use mailing list services and will want to continue to > > > use > > > them. The one thing that makes this tractable is the SHOULD language as > > > > we > > > > > may choose not to not follow this aspect of the specification. Our > > > suggestion is that there is not a lot of value in including this > > > language > > > in the bis document if the likely outcome is that it will be ignored, > > > and > > > rather more effort should be placed with a technical solution for > > > interop > > > with mailing lists. > > > > It might be helpful if you could describe this technical solution from > > your > > perspective. > > > > If there were a reasonable technical solution available, I think this > > would be > > a much easier change to support (in my opinion, and a believe a > > substantial > > number of others, rewriting From is not a reasonable technical solution). > > > > Scott K > > Apologies for the delay in getting back to this. > > So yes I believe there are two possible technical approaches broadly > speaking 1) Support rewriting From and being able to reverse it along with > message modifications to recover the original DKIM message hash to validate > the original DKIM signature. 2) Create a new message authentication method > that is tolerant of message modifications and message forwarding, and > supported by DMARC. From header rewriting would not be necessary in this > scenario. Beyond the complexity of supporting either method, another > tricky thing in both cases is supporting an ecosystem with diverse adoption > of said technique. More concrete proposals for 1) and 2) are 1) > draft-chuang-mailing-list-modifications > <https://datatracker.ietf.org/doc/draft-chuang-mailing-list-modifications/> > and 2) draft-chuang-replay-resistant-arc. And there are other I-Ds out > there particularly for the first approach. > > -Wei Thanks. That's helpful. I interpret that as confirming my view that there is not currently a reasonable technical solution available. While these may be promising for the future, it's not like any of those solutions are things that are currently available to email list administrators. I don't think any of those things are going to mature quickly, so I would find it concerning to delay publication of DMARCbis until they are ready. If we aren't going to put DMARCbis on ice for a few years (please, let's not), then I think we're left with something like the language that's there now or some variation of NOT RECOMMENDED unless [unobtainium] which amounts to the same thing, but is in my view less clear. I think in a couple of years we could do some kind of an update that relaxes the current language based on one of these techniques if they become deployable, but I don't think we can do it now. Scott K
- [dmarc-ietf] Some Gmail comments on DMARCbis vers… Wei Chuang
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Alessandro Vesely
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] pct flag, Some Gmail comments on… John Levine
- Re: [dmarc-ietf] pct flag, Some Gmail comments on… Richard Clayton
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Scott Kitterman
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Jim Fenton
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Dotzero
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Dotzero
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Jim Fenton
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Dotzero
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Richard Clayton
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Alessandro Vesely
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Dotzero
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Dotzero
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Wei Chuang
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Scott Kitterman
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Alessandro Vesely
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Barry Leiba
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Barry Leiba
- Re: [dmarc-ietf] not demunging yet, Some Gmail co… John Levine
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Murray S. Kucherawy
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Douglas Foster
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos
- Re: [dmarc-ietf] Some Gmail comments on DMARCbis … Hector Santos