[Emailcore] Re: [Last-Call] Re: Re: Re: Your (Roman's) DISCUSS on draft-ietf-emailcore-as and status of the document

Steffen Nurpmeso <steffen@sdaoden.eu> Mon, 28 September 2026 18:32 UTC

Received: from sdaoden.eu (sdaoden.eu [217.144.132.164]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id C8DE942; Mon, 28 Sep 2026 18:32:51 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=sdaoden.eu header.s=citron header.b=ID0DOrbK; dmarc=none; spf=pass (mx.ietf.org: domain of steffen@sdaoden.eu designates 217.144.132.164 as permitted sender) smtp.mailfrom=steffen@sdaoden.eu
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sdaoden.eu; s=citron; t=1790620369; x=1791287035; h=date:author:from:to:cc:subject: message-id:in-reply-to:references:mail-followup-to:openpgp:blahblahblah: author:from:subject:date:to:cc:resent-author:resent-date:resent-from: resent-sender:resent-to:resent-cc:resent-reply-to:resent-message-id: in-reply-to:references:mime-version:content-type: content-transfer-encoding:content-disposition:content-id: content-description:message-id:mail-followup-to:openpgp:blahblahblah; bh=IrzVr8c9cBOtaIVA8E1dgW80SIEzDNdWWU5b049aZxg=; b=ID0DOrbK623f+KZo7oHkX0Yo/PQDuZBUrGcaZH6PxND74pnN8JzviE42DnSIOJ2oTqBBXGbc yiTGh/JyxK+nirg9g53DZiylEMK+i2lpMCue+wJZLn3BHIi6joXAlIfkY08dfNamtBFdiQ2zEN cdSRL+qzpMvx2+tqPvpPb3CTEX0zBZp9HOUJM56hdmTMh5Gkh/2p4o6cryHw3/3DBmW5ulP8eO TKz2gTXqfymA/lhNvwzsU3oVY/ux8TdADIaPZcAvgLnO7Ru2xUSLMSsKdVnLNWGjZaKk8PoyjW K+oS//xmosAZV2ZiNBkRrA/8XcUK8NSWWLJ73hC2ZkrY9Q5A==
Date: Mon, 28 Sep 2026 20:32:48 +0200
Author: Steffen Nurpmeso <steffen@sdaoden.eu>
From: Steffen Nurpmeso <steffen@sdaoden.eu>
To: Paul Wouters <paul@nohats.ca>
Message-ID: <20260928183248.lwv8-Oca@steffen%sdaoden.eu>
In-Reply-To: <e25d713f-d268-0c68-4324-aff3ef12fc95@nohats.ca>
References: <e25d713f-d268-0c68-4324-aff3ef12fc95@nohats.ca>
Mail-Followup-To: Paul Wouters <paul@nohats.ca>, Eric Rescorla <ekr.ietf@gmail.com>, emailcore@ietf.org, last-call@ietf.org, rwilton@cisco.com, Steffen Nurpmeso <steffen@sdaoden.eu>
User-Agent: s-nail v14.10.0-alpha-84-g0cc35ec9e8-dirty
OpenPGP: id=EE19E1C1F2F7054F8D3954D8308964B51883A0DD; url=https://ftp.sdaoden.eu/steffen.asc; preference=signencrypt
BlahBlahBlah: Any stupid boy can crush a beetle. But all the professors in the world can make no bugs.
X-Spam-Level: ******
X-Spamd-Bar: ++++++
X-Spam: Yes
Message-ID-Hash: AXHFDRRC3HGFCZCK3IFQ7KRM4B773CDX
X-Message-ID-Hash: AXHFDRRC3HGFCZCK3IFQ7KRM4B773CDX
X-MailFrom: steffen@sdaoden.eu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Eric Rescorla <ekr.ietf@gmail.com>, emailcore@ietf.org, last-call@ietf.org, rwilton@cisco.com, Steffen Nurpmeso <steffen@sdaoden.eu>
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [Emailcore] Re: [Last-Call] Re: Re: Re: Your (Roman's) DISCUSS on draft-ietf-emailcore-as and status of the document
List-Id: EMAILCORE proposed working group list <emailcore.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/emailcore/pcTypauZlovWWnHymmsQDbwqs5o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emailcore>
List-Help: <mailto:emailcore-request@ietf.org?subject=help>
List-Owner: <mailto:emailcore-owner@ietf.org>
List-Post: <mailto:emailcore@ietf.org>
List-Subscribe: <mailto:emailcore-join@ietf.org>
List-Unsubscribe: <mailto:emailcore-leave@ietf.org>

Paul Wouters wrote in
 <e25d713f-d268-0c68-4324-aff3ef12fc95@nohats.ca>:
 ...
 |[.] But now the next step of EMAILCORE
 |is to work on phasing out unencrypted SMTP. That is to say, the argument
 |of "this has worked like this for 40 years" is a pretty weak argument
 |going forwards. Five years from now, if this comes up again, I believe
 |the argument of "this has worked for 45 years" should get 0 points.
 |
 |Since I was tired of the argument of it breaking things, I have just \
 |changed
 |my setup in postfix for my own domains to use smtpd_tls_security_level \
 |= encrypt

That is fine for you personally, but it will break communication
with remotes which explicitly do not do TLS, whether because of
the historical spirit of UUCP, or because they deem it ok because
"this here is public, so why would anyone encrypt the
communication?" (and .. understandably so!).
(And: email security was stated even by the IETF, for decades, as
being only for real with end-to-end stuff like OpenPGP or S/MIME.
So *that*.)

This goes beyond SMTP by the way, despite IETF sayings to obsolete
unencrypted communication.  For example, here a statement of
Antonio Diaz Diaz who maintains quite widely used code for
decades, has had short contacts with the IETF regarding his LZIP,
and he for example said in [1], on the topic that "URLs should be
updated from HTTP to HTTPS":

  To avoid breaking backwards compatibility, I do not plan to
  publish any https URLs until someone finds a way to retrofit
  current TLS support on not-so-old browsers (like SeaMonkey
  2.0.14), or a way to install current browsers on 32-bit machines
  (like AMD K6-2) with old-but-better-than-current operating
  systems (KDE 3.5).

  [1] https://lists.nongnu.org/archive/html/lzip-bug/2025-08/msg00011.html

And whoever finds this extreme or backwards or ridiculous, or
calls him "an oddball" (or whatever really is said in english), in
my opinion, should better look into the mirror.
At least as in, you know, live and let live.

Also to note certificate pools, and their members, maybe locally
adjusted even, in a company, in a government agency, whatever, of
dubious quality, possibly even in principle.
If they are used at all.

You possibly want to use "= secure" .. but i wish you fun with
that.

 |I believe the IESG should make the same changes for ietf.org, as it has
 |no old fax2email machines in their basements. If the IETF can disable FTP,
 |rlogin and telnet, the IETF can disable SMTP without TLS.

Yes, let us go on.

 |Paul
 --End of <e25d713f-d268-0c68-4324-aff3ef12fc95@nohats.ca>

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)