[Emailcore] Re: [Last-Call] Re: Re: [secdir] draft-ietf-emailcore-as-28 ietf last call Secdir review

Rob Sayre <sayrer@gmail.com> Fri, 01 May 2026 19:32 UTC

Return-Path: <sayrer@gmail.com>
X-Original-To: emailcore@mail2.ietf.org
Delivered-To: emailcore@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9B1D3E786F97 for <emailcore@mail2.ietf.org>; Fri, 1 May 2026 12:32:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1777663979; bh=Vr187fRFWgWL74w/lKvhWzfQ7yOl7k6u9PKvKVkKtCw=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=g0347Sdysed6xfokEDqorAHU288Qi73IWtfbDvsTmzPE5hPwlfIFfMURvC8DYjilw PsrKNSZ8bWRSEZZqnoF67yirUDwltN2TWLqN6PfJoAZ+YchDYXq+Z+Hill/YuOLf9Z 93GzzsvcicrsGAbem8TTDOhFJxMXihP/TtwvzPVc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HvoxzDo_fFZf for <emailcore@mail2.ietf.org>; Fri, 1 May 2026 12:32:58 -0700 (PDT)
Received: from mail-pl1-x632.google.com (mail-pl1-x632.google.com [IPv6:2607:f8b0:4864:20::632]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id EE38DE786CEE for <emailcore@ietf.org>; Fri, 1 May 2026 12:31:57 -0700 (PDT)
Received: by mail-pl1-x632.google.com with SMTP id d9443c01a7336-2ad9516a653so11170865ad.0 for <emailcore@ietf.org>; Fri, 01 May 2026 12:31:57 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1777663910; cv=none; d=google.com; s=arc-20240605; b=k0mBVtIAUcHiV+k74TePhm1EVYyCGNd1X8Zjn4Ti8qKfmgSkmvkSpEwlwyea+qdvTA yzXedUpJiBHkp1+e9I/jmIjGWK0TF092u+VayTJB9tTRLpjnq/h29Lnn4r1LbLWWY9Ft LAGgdj5oyN3cH07w4S47ZHHVtLBn8sO7eoAqBDHdF1vIzktjnTaVb3hzyJUJhSnP6iAz iIGx4ttXmeKeVNIpCU+l53bJWE2zCeCLq7SPLTr38rFUZTuzS2mq7moh80swPMEktQzr yhKuWlwe7G7aAfzae/dVktt1kw/UXXjJbf8AkUM7+1kvu3UGcbCS9MHknnRhPHxANywu pTEQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=Vr187fRFWgWL74w/lKvhWzfQ7yOl7k6u9PKvKVkKtCw=; fh=vEgjT/VXeOzCNa7X/FLcLpVq2lTVECBjvnk1O+kcLSU=; b=a86mBohI7PoluAqNHPO1yxIrXJOryyXgQzObnE7l2QLlc56mFnhBsEE4quS3B3c6Y5 ql3MGZSZdbiiAIl2XUxZeGpFuQDvzikKoGZL7djDGTn9MiwA/5gnFZtsx8Td0DKCbR9Q 64yUjZCWY3rFTx3AUZ+Zzkq9U5TcM//7cGGSHdj4I6cwPaJRwLu65SGiRaBekC+GezCG e4WS/cDO4oMtKb1rHxMGMNqwtZ2x2ht1QGFTjHUoFSG3EvdjjwMOg23LlQ8LO658GXfd I8qMRz3Xp8Bt9Up8bLfA9L+MhW4thXf3VQ9pE9nJ22CLNIdRtlkAjcMMeQ0PnzVdosAi 827g==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1777663910; x=1778268710; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=Vr187fRFWgWL74w/lKvhWzfQ7yOl7k6u9PKvKVkKtCw=; b=YVIfS3KH7oBd207iiCpQy640FkluqHK6z6DuLPlHPryvYonk1f/k1hYm/xi1ROa+XH t6P4T0R/jwL2n3xmP19AELsnCLEbgROYZNgvt/G5+Lqw91L7dtFjhHk0lVIFE3P+/e1A lWT+nqoHuGx48Ydq1t80ih+N1hZoefJpsKKIn+noJvI/tsIkvGiImvSPWJggSKUIHqOQ jRjimEmBef4iWV7G8/9jUIj2Dz+qFlcOUSUfpl8ph2/HHLk6XjCXvmRgX+kAVlGafFUn kzZP3MromkAQyy2aD/2ItjD1T8XhCp9nzCEvTNKfWDktzAbCFXNFjWtm/XWdE5uHqRem ZZ6g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777663910; x=1778268710; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=Vr187fRFWgWL74w/lKvhWzfQ7yOl7k6u9PKvKVkKtCw=; b=R4RVNOch7K3bVKSB16OjZeIbuMU6H820WbA3U1XEM5W2OCgs9jWRPwNmV1moOTvVv7 Y2Xjk/r+GY7ldqCM0RruYEDNb7dLa5O/u5liMH9LetxLuFZXUujsmlG/ri4/1boTxn++ jGHIVk5glqWBpYurZNItag7bBxUDnbMtS/uNvFG/+vltCOuXdPyL61txxiVe3XqTi5e0 sJNWvtpPynCdJIxOtChJ07fXXgXZ5eGWKwUtJqc94WNYuQd0LMkzvBfZj812uYuH0cSq i7EHXxVW5wG/Z/QPAU0hba7iL5WpVje+wW8N+wsAqxiWDQ8ypPwa1rn+f6W/l7D2cCQo fH7g==
X-Forwarded-Encrypted: i=1; AFNElJ91ehnSGRWCIfP1sG9KzBeNE8V1KX++1DatBj01QpZsCoSUEftz0wa1I0/dWcTxxQDImM4g39xeUWY=@ietf.org
X-Gm-Message-State: AOJu0Yy+EBUtaxpuKQllV5Pf2m57j/NbwGnfxWwRgWuZwDRexDlBhy/G hPebe+2GIPDwcCF0QSuQI3vIJKVcVCbu9hgV7VEcsIlFIVNjfIPBsmMawrkXPF91WwNW0UdSTuB h+SNR/uP+53NnEOBGH/pD/Euen8sfqONaiw==
X-Gm-Gg: AeBDievmAkKSIz5OxrK8FGnmqc4+W8g/kMoLRs8QrP3z6yvF+hThzoE4udLEkQvKDUU AvRmcV4o5bx1jTG9PYrC8Lesf9NxZMOlzdrRB3PQlekO1BajZCK97POSnGf5+gIPEf/YhHDygTx sLbS/AeoFOGnl2eRSqiia36GODVrbu3rVCwDQSQ6SkrDEQxTFD0KeoZH7/YE+4fRIaOaH/Oib1P 4A3jrUqoGuhagLkZk6SkWPPnchqWONqUJRa9QsWxZQ+yN5u0njspqYWbvZx6KZNpFtSFzREfxSz F2lFqwpHXU43kfKnsnwhuS9NsZtawTW62uU7i6HHIwF7A0Lo3Gg=
X-Received: by 2002:a17:903:1a84:b0:2b2:49a7:a5bc with SMTP id d9443c01a7336-2b9f2819d97mr4190685ad.39.1777663910581; Fri, 01 May 2026 12:31:50 -0700 (PDT)
MIME-Version: 1.0
References: <177735548849.818.15891659530280505461@dt-datatracker-b45949c58-t72jx> <CAL02cgTFzt9JWqjCaeJvjprw7A-CVxSsuACcGeq+5v2HswLisg@mail.gmail.com> <afLDxbSmB-EhfvfZ@chardros.imrryr.org> <593710E3-F462-49DF-AE9A-0EAB8F984851@episteme.net> <CABcZeBOCZ0COccyTHWRgJ3JGGtwC+N63742J1ak2=wOfzqeCZA@mail.gmail.com> <D6470493-E87E-409B-8F2B-C7635E3B7AEF@episteme.net> <CABcZeBMuTZc83NJeS+GS2K__EMUiAdnp71ix4x6a=aKtzDAOgA@mail.gmail.com> <DCA5D233-573B-4406-BD15-5CD3CD2BA5E4@episteme.net>
In-Reply-To: <DCA5D233-573B-4406-BD15-5CD3CD2BA5E4@episteme.net>
From: Rob Sayre <sayrer@gmail.com>
Date: Fri, 01 May 2026 12:31:38 -0700
X-Gm-Features: AVHnY4IyhEZS3wZZtvbFKQGVi-MAX-2bQOeL54Ck_XB_QUXcQ57j17jxytTAfEs
Message-ID: <CAChr6SzwTj04YeVKGumtnwNxHPy8Ckoix9SibTWgko0GwXqrDA@mail.gmail.com>
To: Pete Resnick <resnick=40episteme.net@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000eb9be10650c6a11e"
Message-ID-Hash: VTKCYVICSL4UOXZ5ISZA34ZTYFQHKIWA
X-Message-ID-Hash: VTKCYVICSL4UOXZ5ISZA34ZTYFQHKIWA
X-MailFrom: sayrer@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Eric Rescorla <ekr@rtfm.com>, emailcore@ietf.org, last-call@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Emailcore] Re: [Last-Call] Re: Re: [secdir] draft-ietf-emailcore-as-28 ietf last call Secdir review
List-Id: EMAILCORE proposed working group list <emailcore.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/emailcore/rllqxvwVg2-kIwzN-AZshkqeYwo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emailcore>
List-Help: <mailto:emailcore-request@ietf.org?subject=help>
List-Owner: <mailto:emailcore-owner@ietf.org>
List-Post: <mailto:emailcore@ietf.org>
List-Subscribe: <mailto:emailcore-join@ietf.org>
List-Unsubscribe: <mailto:emailcore-leave@ietf.org>

On Fri, May 1, 2026 at 12:24 PM Pete Resnick <resnick=
40episteme.net@dmarc.ietf.org> wrote:

> On 1 May 2026, at 14:17, Eric Rescorla wrote:
>
> > With respect to your specific question, I reviewed Viktor's recent
> > messages
> > and just am not really sure what points you think he made that need
> > responses, as there seems to be quite a bit of material that I
> > wouldn't
> > really consider responsive. If you'd like to pick out specific points,
> > I'd be
> > happy to take a look.
>
> As I just responded to Rob, the primary objection seems to be that the
> current text somehow prevents implementations from being written with
> STARTTLS disabled completely, to which Viktor replied. Do you not think
> that addresses the objection? If so, why? Or did I mischaracterize the
> objection?
>

Hmm, I think you have it backward.

The current text requires implementations to have a mode without STARTTLS
being enforced. That's the objection I'm making.

thanks,
Rob