[Emailcore] Re: [Last-Call] draft-ietf-emailcore-as-28 ietf last call Secdir review

Eric Rescorla <ekr@rtfm.com> Wed, 29 April 2026 22:17 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: emailcore@mail2.ietf.org
Delivered-To: emailcore@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 2676AE5FD958 for <emailcore@mail2.ietf.org>; Wed, 29 Apr 2026 15:17:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777501043; bh=+ad7a3JJ4Mbaz4/FQ6bA3Y1q78SpZpe+Ftx28mA9O9E=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=x2BupsGBv6bFw1unNLBfgbkRMJ3jOdDU/T+UZ1waA3YrAfGZf/2yUpGDhbHJ45ehT erPvf0OwVSzbNfs+l46bxQCp1z2fc48o5tEunR3R77DqDLUdYqSuepS2l2INfr3Yk4 6kvAJ1VqItDW3hMgHKZGFUPVWHPnEimPdHmNyKB8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20251104.gappssmtp.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TL0RF3XX908H for <emailcore@mail2.ietf.org>; Wed, 29 Apr 2026 15:17:22 -0700 (PDT)
Received: from mail-yw1-x1129.google.com (mail-yw1-x1129.google.com [IPv6:2607:f8b0:4864:20::1129]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id CE065E5FD935 for <emailcore@ietf.org>; Wed, 29 Apr 2026 15:17:21 -0700 (PDT)
Received: by mail-yw1-x1129.google.com with SMTP id 00721157ae682-79a60975dc5so3238937b3.0 for <emailcore@ietf.org>; Wed, 29 Apr 2026 15:17:21 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1777501041; cv=none; d=google.com; s=arc-20240605; b=egoDKsTAJPKEIYuir6tQ0+VUWMfVYv17dEoIAhAnwSQKkKcxTcU0lISuEnBj9WCTXp VYkUCXQCl2UhMvjf62Q7bC3ibRroIfTlAHRIvXQdzA39uI7kocSZKnEI4tzVwvYCUAV6 RZ9gv+EgEf8jNg1T0jb0oKHPUv/nNOVOlKIyUmlLmBaRrrY+9o3XT2Ns3dnFhMVK/CqA enSoctkvjlHjySd1PRxpl132kfyaOkndCh0BdFOI6yfuKZQ3QbqLDek11G13WvNh1ZwP /220rehZp0LjIuN4+GbieLeDSdsF5P5AREryb5BJbz2A4gl9atz79+9qbBOpyjkBzpXT dagA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=+ad7a3JJ4Mbaz4/FQ6bA3Y1q78SpZpe+Ftx28mA9O9E=; fh=b3mkOnvJISwz5DAvaNNW73doWiNpy/HNGETUwa4DA94=; b=E1HzFcKZSl/8LmbRbHJyhHOg9Btow+E5zM3yrgXwIDPke87SN7oeXvxtnyHf9kaCkI /d8QO9CgxvEXvUYBsQxbXGyugUzd9O7fTtCR9xRWP1svE5mw/l+QHckUZ9hS6HG8TDId /W2C1RkhM+zE7JuOegRrujH1VU0hviZeS6LmjbzdlBOZJsTLPjBDSEEXDisE4wGXz0Dj SmNrI+4noGo3W2p/5rTa65iD+z4kJt/+c8nD+snYzrbHJM0ngXlNoinGe+Iqr0Kg19oL hbIpHJ55zcu0iMXi9WjDwQu9XD9VcbAtbbLoFfBOdaG+J3koCYfq01rRId3lYqCg7/ii wF4Q==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20251104.gappssmtp.com; s=20251104; t=1777501041; x=1778105841; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=+ad7a3JJ4Mbaz4/FQ6bA3Y1q78SpZpe+Ftx28mA9O9E=; b=EmU+KWNBfZRQ4pZAs8dMz9dS6KIuLlRWeVhiKYYkf7A4yZODgBeM5X2BQJtEN/Z/8J 2VFIlbsot2qQWRQBjAAMTupChr8t29uxu1GgLeODd9kYyQQEsCBELByu15MSaGvlOxIg g0MYAkLwqIN+CXcmbzb/I6jQBnFiWy3UadxzMUTK5TxEeT0u7RqcMNEtkRG5emFg89Tl IdgSmcvtkRe6D5CW34xXktcNU2Z6qJ8KiIczHAMfpIywmH6Fs6Xe2uNDjQUxh495z/T1 tPGGwbU0dlkI2JCb2gcSIMQjivp3M/cLUAp9ZnRY+KEYUwKdFUaf6xLCMeSMG//toOak dMlA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777501041; x=1778105841; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=+ad7a3JJ4Mbaz4/FQ6bA3Y1q78SpZpe+Ftx28mA9O9E=; b=THRYCx0QKpN1w5xzST1fFZ5dsCvoWhCYtDarCOZr2eWnq4+OsOy3gCmUIpz/24RtrY qzv7JXglIqJA/4ZK8C5YVZa24XtlRvbPYWcrgB0owiCR5XeSAOZnXS6oMr1SVATHFrOd uEUTagMmqsisTU4aVKvslETvC4enBgEt7K5DQ/zG2fadZC92VpT5KnIBQse26FsZTMoI gjUBrkpsTaHr3XwB8u+b2VAFLKl57upIOBcz5KItavuu/AgBO6/M8CPj6Pnvow02y7md ufo4gHxGs0JtIdZdeOvceGiV90Fo4XgcD2DHHrkEZ5o/95AkzwmMY0lJOfGDYH+ajRsz 9blQ==
X-Forwarded-Encrypted: i=1; AFNElJ/u+o+X13FiW0sqDhpJ+UNwwVX1bJwWiZBLbvCECXkycev8xTQwpp6pOHcq7I4sKaiZq3tSpmYVkt8=@ietf.org
X-Gm-Message-State: AOJu0YwBa2Z3htbO7mcisCRFFMijqO5pwCxbjiXIIYtM1CG8B4mqv5DQ s2tlVPVkLHJIEy01/7+4NAc9rNisRakMN7ZeIF9OBRenIIeOmIN8igZI8IGa15hvIgkNdaaPbGq cykAC4XAScxzsmmx/ZMEwmnOwVr3Eoj1HfRlm1VoDlg==
X-Gm-Gg: AeBDietoKW1IiWkXh45HxmHFBhuoHnb7jiVxkxSm9x+IYJ1fb+ip9ysmpuAQtQLOUyd TznAwkw4mbUCGeM6P4LPz3Ho1WHHbWEv4jeVZWk090NVIgRkt4nf9xz4XcSHH2+3Z7BVTCejK1B vaJODXgDzmt1HxMxEZjQNNj89b2n6nCt/fSSzGAVPxQPd2C/pRnrLFwRPNuKQry4N3t5YoG/stj UmhfhIztAnC239LiAWUSNd+f0IuGa4dxi5XZ070wpLyfSX1FAr6I4+f9xDVQvBCl9u06jrjiK9T UlIlhQhQpwdIVSa/pwdv/EVI12z3dI35G4pPKqita7n+1IujUHOLUv/Ehqtov98+JMaSP48qj4T +fy5bM5/e7HcUn68DeayGPZ6xB3oSZlwt
X-Received: by 2002:a05:690c:93:b0:7b9:edca:ba97 with SMTP id 00721157ae682-7bd5286ecc3mr7533557b3.17.1777501041307; Wed, 29 Apr 2026 15:17:21 -0700 (PDT)
MIME-Version: 1.0
References: <177735548849.818.15891659530280505461@dt-datatracker-b45949c58-t72jx> <CALaySJLPRjnhP_SRCoKdBuHZkMsLYcQB5g-Pf3ra14mqYG86tg@mail.gmail.com> <5d69c4a4-e16c-4c0b-bb0e-09887d062da9@lear.ch> <CABcZeBOK0wR5i1Y9Lxa6JzgF6nxzLU25pZa4Sida01VaowBGGA@mail.gmail.com> <fc87c6da-4c02-4030-84f1-092a8511c5c3@lear.ch> <CABcZeBP5q4kWtSXYhkStC7Yc-OYmVNfEJ4Dn7Ef_RNf_g74ucA@mail.gmail.com> <16e19e54-7f69-4ecc-a5f0-dcffd7a0d3b2@lear.ch> <CABcZeBP0e0TS4F_aQvvER+pt87rgGiARudKTEKzD0roEyESvZQ@mail.gmail.com> <8DC02587-26C8-428A-9D88-44AEEFDFE1C2@episteme.net>
In-Reply-To: <8DC02587-26C8-428A-9D88-44AEEFDFE1C2@episteme.net>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 29 Apr 2026 15:16:44 -0700
X-Gm-Features: AVHnY4Kv12kCVs7_A8IwX2ynyA7xsJbqH-Bu7rV8C2lqOqy5-oejMQSjxcaKjoE
Message-ID: <CABcZeBMRsVsBnvbW_g0aR8M80RcQ0QWHqYxQk5dK_9-Dm1Tccw@mail.gmail.com>
To: Pete Resnick <resnick@episteme.net>
Content-Type: multipart/alternative; boundary="00000000000027bdd30650a0b670"
Message-ID-Hash: KDFVXBSE5U3YQ55OL6MNQOOXRN2IMHW5
X-Message-ID-Hash: KDFVXBSE5U3YQ55OL6MNQOOXRN2IMHW5
X-MailFrom: ekr@rtfm.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Eliot Lear <lear@lear.ch>, Barry Leiba <barryleiba@gmail.com>, Shivan Sahib <shivankaulsahib@gmail.com>, secdir@ietf.org, draft-ietf-emailcore-as.all@ietf.org, emailcore@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Emailcore] Re: [Last-Call] draft-ietf-emailcore-as-28 ietf last call Secdir review
List-Id: EMAILCORE proposed working group list <emailcore.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/emailcore/GZRJjdnWeYSrB7YA10WpbFbtDPM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emailcore>
List-Help: <mailto:emailcore-request@ietf.org?subject=help>
List-Owner: <mailto:emailcore-owner@ietf.org>
List-Post: <mailto:emailcore@ietf.org>
List-Subscribe: <mailto:emailcore-join@ietf.org>
List-Unsubscribe: <mailto:emailcore-leave@ietf.org>

On Tue, Apr 28, 2026 at 6:51 PM Pete Resnick <resnick@episteme.net> wrote:

> On 28 Apr 2026, at 19:15, Eric Rescorla wrote:
>
As I said earlier, it is the introduction of the new requirement for
> STARTTLS (more precisely, confidentiality) that leads us to want to be
> clear that you also must provide for cleartext for the time being. There
> would not be a need for that requirement if the new requirement for
> confidentiality was not added in this document.
>
Let's see if we can perhaps get on the same page about the current state of
affairs: do you believe an SMTP implementation which requires STARTTLS and
does not allow you to disable TLS is presently conformant?

-Ekr