Received: from mail-pz2-x0c.google.com (mail-pz2-x0c.google.com
 [IPv6:2607:f8b0:4864:3b::c])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange x25519 server-signature ECDSA (prime256v1) server-digest
 SHA256)
	(No client certificate requested)
	by mx.ietf.org (Postfix) with ESMTPS id 3A65144
	for <emailcore@ietf.org>; Sun, 20 Sep 2026 22:14:04 +0000 (UTC)
Authentication-Results: mx.ietf.org;
	dkim=pass header.d=gmail.com header.s=20251104 header.b=SseWQJSe;
	arc=pass ("google.com:s=arc-20260327:i=1");
	dmarc=pass (policy=none) header.from=gmail.com;
	spf=pass (mx.ietf.org: domain of sayrer@gmail.com designates
 2607:f8b0:4864:3b::c as permitted sender) smtp.mailfrom=sayrer@gmail.com
Received: by mail-pz2-x0c.google.com with SMTP id
 41be03b00d2f7-cc5121bcf1aso1963896a12.1
        for <emailcore@ietf.org>; Sun, 20 Sep 2026 15:14:04 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789942437; cv=none;
        d=google.com; s=arc-20260327;
        b=LlmoqFtSrsMb0WQ+piaxeUQaSBesCE3cOKQvce5SO5/pqSXJJIh4d5OzBa3cdYc11H
         DRCywRGKV8sJKyk+ckhwAfm2pLRD8bS+R/GNnRC/a1V054o8VXS2bHaQF0qToGTbf0k+
         8KZg5PPvM2P37CqNciO4Uo/xSEAZLtieETW78JU97xLRLArH6hv2XsuwvY3w6654ujET
         eEIVrMb1gBaUVQJjCUSJwzYzbm29FtlPgmkb2e912/ZGQug9JY4F2Lqvz5+QxwAxQMdB
         4Em9LKtSApqDK10JWV2jqRzR6f+PZIRwKxuDWG93COZuwXyuTW70sz8j0rXhUH8dpRF3
         +ddw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
 s=arc-20260327;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:dkim-signature;
        bh=xVFGvNsNsrnuMz3YLHYgBzBwCSTULPUB4n1XtvIsBkE=;
        fh=krrbi57g2xaU5hQlwEkpar7BrmglhgmkSNkoY7Cuo7c=;
        b=bJ9k6FfoPNG/H6W/Li1PN4wPFXViat8CynhEnm8+gCYt7ZPwNmjImlK8so9c6SPzu5
         ZPk3W6MJPyMxe6oo0KYscYcxmNCysq/yPX0VEdjcCtIRrgISKyyQrDyTS2Go1BBnv0Pq
         LcfUmj3psJO2KoQnrCr99pkX0gxQYGiwdzIKC2mH8IA7ApVY6fcPi9a5KMF9oo6xN3Vk
         0FBZRbWl3xLaEqoV6okBvE58iRUiRSteH6A0uZEvhbiOl/T2t7X2i8ywSFAiigOdn/wL
         Ua6quzxKLAf+So3/LMW4YYMiOv9Oax7/HKpIrLZZeSFNy5zVIxHWaE2Ohg4Y4OAkqh3M
         R/sw==;
        darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20251104; t=1789942437; x=1790547237; darn=ietf.org;
        h=content-type:cc:to:subject:message-id:date:from:in-reply-to
         :references:mime-version:from:to:cc:subject:date:message-id:reply-to
         :content-type;
        bh=xVFGvNsNsrnuMz3YLHYgBzBwCSTULPUB4n1XtvIsBkE=;
        b=SseWQJSeCO7o3WZCz38W4oe9ttHSB52uryl5zwV2C0E+Ork0f8p/a0CX1YlV61r6HY
         dNdgzDMGfJLXfooq0mXLI+leFb05uf8Dt+DqBJq2N2TTxrWZrnJMIrxJTl6XWhMx2T2K
         FsCrp9MEAGjGxbhvxEc7JyqgFyNt/e2sQyGHsrchiDguBIrn9k6gn+I8DDiizn2i6S2G
         7UG9aEem+2nkFVwDBQg8jS/uD2QBUrNsC52IuUxLD0/uvc9d5gQkAl4bbT67JTeHyDXG
         TavBVG7HJOfHTUaRH+6Gn3+ZeAQgh7tqg5a2QLbTbME8KmdLquOJWFwQ2jXT7/oRisfd
         ZocA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20260707; t=1789942437; x=1790547237;
        h=content-type:cc:to:subject:message-id:date:from:in-reply-to
         :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc
         :subject:date:message-id:reply-to:content-type;
        bh=xVFGvNsNsrnuMz3YLHYgBzBwCSTULPUB4n1XtvIsBkE=;
        b=zxY/P84ZxSkZolVNTv40zLvLbCRMlIn8ABbI1aaREleoS/aM6OoA4j4xgeK1oh/lPD
         NGPcRtC4TEjEAk2E6L3F80g5MpLPULH/RaLGLb4Vz4cwNzRcidzXXbKBAITEMDs8nBNd
         G815J1SH3iwguxVORjKgOCyboiwoPeXWzHmLHWQemUAruGRCGpUfHlla2xzh3PC4nnS7
         aYQZ4wkm49fG0qSuJaqwdLVFquJszDog9hDnJrLYwJkTwTiJUpdvIBs2xaQoRGWaXguh
         OPhappYl6s27EKaAyOPW3ZRA2pU+RaO3KE2EnLRmcMrDA7uUnEG/CAZIRRsmkAMMxycO
         ZAhA==
X-Gm-Message-State: AFuF++l/R7IOVoQJWWN8imYXodnvb9DV8XF379ArfFefvV4kYaRE3Ho2
	YM77KD+ksaYSGMdb+bl55WXxvhIW9IDJpvxszYMKcrE2BbmR2D7i+JNB/1DJviSPnWKgQTbwlTm
	FwRohzdMqyx0QC6XNzepVAmoMkVX3xHc=
X-Gm-Gg: AYBFou2Hw1/S2uZdisk3ucCkLnXXazSefnUHDvVU3cjq7Monjhurs0X6aJiv6x3RaPP
	qpTx0a1f/lfnet3rWJldUGqc8Ud1ieAyLkLWieYHlRh5oBS93uRiSvxKC/3PcjNxh04qXRNEszX
	kHAUl/pfpnme3I3DgHQw26jrv5vpc014S6847GI7qPfXw5GhcsH2N4JRrhkBbKdZfTn1dSJKOc3
	hlKe/r2fMfuuPdwrIFwZ4YOKfqrVVMncy+w4OXOWK3kNPq23Yr3MVnZELpRaTS5QAU3Y2WaL6KF
	1TByvQ+00ffD/Q+GkQ2RRln1ndd7xEaEEfImlYkumYNPGFf/KZ2B/m6qk8mvLk7UDLmmYlaFJC/
	MyDmLagbZbm0I
X-Received: by 2002:a05:6a21:6e43:b0:3dd:a196:539d with SMTP id
 adf61e73a8af0-3dda196550emr8701667637.63.1789942436872; Sun, 20 Sep 2026
 15:13:56 -0700 (PDT)
MIME-Version: 1.0
References: <0786af40-4c4a-4670-a71e-eeed0596c7d8@lear.ch>
 <arADNYbear-_QgRh@chardros.imrryr.org>
 <1FE6D8319E6156C7A0044D7E@PSB>
In-Reply-To: <1FE6D8319E6156C7A0044D7E@PSB>
From: Rob Sayre <sayrer@gmail.com>
Date: Sun, 20 Sep 2026 15:13:45 -0700
X-Gm-Features: AcwNN1U-dGwLaTGjRTWMlvg89hxx19FpNlEsW-ZXLsghGDRVczrFQwU7knd09r4
Message-ID: 
 <CAChr6SzLtYQczhK+ErEhP0g=8=FuDCEFy1FRTguX1KYdjwG=0A@mail.gmail.com>
To: John C Klensin <john-ietf@jck.com>
Content-Type: multipart/alternative; boundary="0000000000001e441e065bf173fa"
X-Spamd-Bar: --
Message-ID-Hash: R5ACQQR6G5KYUYSVYYKOGISO5MICJH6C
X-Message-ID-Hash: R5ACQQR6G5KYUYSVYYKOGISO5MICJH6C
X-MailFrom: sayrer@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop;
 banned-address; emergency; member-moderation; nonmember-moderation;
 administrivia; implicit-dest; max-recipients; max-size; news-moderation;
 no-subject; digests; suspicious-header
CC: emailcore@ietf.org, Last Call <last-call@ietf.org>
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Emailcore] Re: [Last-Call] Re: Re: Re: Your (Roman's) DISCUSS on
 draft-ietf-emailcore-as and status of the document
List-Id: EMAILCORE proposed working group list <emailcore.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/emailcore/dqMODjWNc5JztczqcMSkhg065oc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emailcore>
List-Help: <mailto:emailcore-request@ietf.org?subject=help>
List-Owner: <mailto:emailcore-owner@ietf.org>
List-Post: <mailto:emailcore@ietf.org>
List-Subscribe: <mailto:emailcore-join@ietf.org>
List-Unsubscribe: <mailto:emailcore-leave@ietf.org>

--0000000000001e441e065bf173fa
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Sun, Sep 20, 2026 at 10:41=E2=80=AFAM John C Klensin <john-ietf@jck.com>=
 wrote:

>
>
> --On Monday, September 21, 2026 02:00 +1000 Viktor Dukhovni
> <ietf-dane@dukhovni.org> wrote:
>
> > On Sun, Sep 20, 2026 at 11:05:37AM +0200, Eliot Lear wrote:
> >
> >> We are not the protocol police, and we have no army.  MUST is
> >> *practical* *advice* to deployments about how best to
> >> interoperate with others, in this case balanced against potential
> >> harm.  That balance has already been decided operationally by
> >> public deployments, [...]
> >>
> >> Moreover, I am one of but a very few people party to this
> >> discussion who is in a position to reject unencrypted SMTP
> >> transactions (of course I don't).  I know of nobody who does.
> >
> > I concur, but should perhaps concede that a small minority of
> > Postfix MTA operators have self-reported choosing (against
> > generally better advice) to reject non-TLS mail transactions.
> > Their MTA is "able to accept mail with or without confidentiality",
> > their "particular circumstances" apparently make rejecting
> > cleartext transactions an acceptable risk.
>
> Ok.  But what does it mean _for the document_ to "concede" that?
>

Just say less. The document does a good job describing the interoperability
concern in the paragraph above.

TLS can be a compliance requirement, and a great way to ensure compliance
is to use an SMTP server that doesn't support cleartext at all.

thanks,
Rob


Here are the Google Workspace settings:

You can reject non-TLS emails in Google Workspace by configuring a Secure
transport (TLS) compliance setting or requiring TLS on an inbound mail
gateway in the Google Admin Console.

How to Require TLS for Specific Senders or Domains:
Sign in to the Google Admin Console using an administrator account.
Go to Menu > Apps > Google Workspace > Gmail > Compliance.On the left,
select your target organizational unit.
Find Secure transport (TLS) compliance and click Configure (or Add another)=
.
Enter a setting name, choose Inbound, Outbound, or both, and select or
create an address list for the domains/emails you want to enforce.
Check options like Require CA signed certificate and Validate certificate
hostname for robust security, then click Save.

How to Require TLS via an Inbound Gateway:
In the Google Admin Console, navigate to Apps > Google Workspace > Gmail >
Spam, phishing, and malware.
Select your organizational unit on the left, then scroll to Inbound gateway
and click Configure or Edit.
Enter your gateway's public IP address or range.
Check the box for Require TLS for connections to reject incoming connection
attempts that do not use TLS.

--0000000000001e441e065bf173fa
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Sep 20,=
 2026 at 10:41=E2=80=AFAM John C Klensin &lt;<a href=3D"mailto:john-ietf@jc=
k.com">john-ietf@jck.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail=
_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204=
,204);padding-left:1ex"><br>
<br>
--On Monday, September 21, 2026 02:00 +1000 Viktor Dukhovni<br>
&lt;<a href=3D"mailto:ietf-dane@dukhovni.org" target=3D"_blank">ietf-dane@d=
ukhovni.org</a>&gt; wrote:<br>
<br>
&gt; On Sun, Sep 20, 2026 at 11:05:37AM +0200, Eliot Lear wrote:<br>
&gt; <br>
&gt;&gt; We are not the protocol police, and we have no army.=C2=A0 MUST is=
<br>
&gt;&gt; *practical* *advice*=C2=A0to deployments about how best to<br>
&gt;&gt; interoperate with others, in this case balanced against potential<=
br>
&gt;&gt; harm.=C2=A0 That balance has already been decided operationally by=
<br>
&gt;&gt; public deployments, [...]<br>
&gt;&gt; <br>
&gt;&gt; Moreover, I am one of but a very few people party to this<br>
&gt;&gt; discussion who is in a position to reject unencrypted SMTP<br>
&gt;&gt; transactions (of course I don&#39;t).=C2=A0 I know of nobody who d=
oes.<br>
&gt; <br>
&gt; I concur, but should perhaps concede that a small minority of<br>
&gt; Postfix MTA operators have self-reported choosing (against<br>
&gt; generally better advice) to reject non-TLS mail transactions.<br>
&gt; Their MTA is &quot;able to accept mail with or without confidentiality=
&quot;,<br>
&gt; their &quot;particular circumstances&quot; apparently make rejecting<b=
r>
&gt; cleartext transactions an acceptable risk.<br>
<br>
Ok.=C2=A0 But what does it mean _for the document_ to &quot;concede&quot; t=
hat?=C2=A0<br></blockquote><div><br></div><div>Just say less. The document =
does a good job describing the interoperability concern in the paragraph ab=
ove.</div><div><br></div><div>TLS can be a compliance requirement, and a gr=
eat way to ensure compliance is to use an SMTP server that doesn&#39;t supp=
ort cleartext at all.</div><div><br></div><div>thanks,</div><div>Rob</div><=
div><br></div><div><br></div><div>Here are the Google Workspace settings:</=
div><div><br></div><div>You can reject non-TLS emails in Google Workspace b=
y configuring a Secure transport (TLS) compliance setting or requiring TLS =
on an inbound mail gateway in the Google Admin Console.<br><br>How to Requi=
re TLS for Specific Senders or Domains:<br>Sign in to the Google Admin Cons=
ole using an administrator account.<br>Go to Menu &gt; Apps &gt; Google Wor=
kspace &gt; Gmail &gt; Compliance.On the left, select your target organizat=
ional unit.<br>Find Secure transport (TLS) compliance and click Configure (=
or Add another).<br>Enter a setting name, choose Inbound, Outbound, or both=
, and select or create an address list for the domains/emails you want to e=
nforce.<br>Check options like Require CA signed certificate and Validate ce=
rtificate hostname for robust security, then click Save.<br><br>How to Requ=
ire TLS via an Inbound Gateway:<br>In the Google Admin Console, navigate to=
 Apps &gt; Google Workspace &gt; Gmail &gt; Spam, phishing, and malware.<br=
>Select your organizational unit on the left, then scroll to Inbound gatewa=
y and click Configure or Edit.<br>Enter your gateway&#39;s public IP addres=
s or range.<br>Check the box for Require TLS for connections to reject inco=
ming connection attempts that do not use TLS.</div></div></div>

--0000000000001e441e065bf173fa--
