Re: [ietf-smtp] [OT] (signed TLDs)

Keith Moore <moore@network-heretics.com> Wed, 16 October 2019 01:56 UTC

Return-Path: <moore@network-heretics.com>
X-Original-To: ietf-smtp@ietfa.amsl.com
Delivered-To: ietf-smtp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB63E120848 for <ietf-smtp@ietfa.amsl.com>; Tue, 15 Oct 2019 18:56:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=messagingengine.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3F3C6r3DfXPM for <ietf-smtp@ietfa.amsl.com>; Tue, 15 Oct 2019 18:56:43 -0700 (PDT)
Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E533120846 for <ietf-smtp@ietf.org>; Tue, 15 Oct 2019 18:56:43 -0700 (PDT)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailout.west.internal (Postfix) with ESMTP id 9294570F; Tue, 15 Oct 2019 21:56:42 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute6.internal (MEProxy); Tue, 15 Oct 2019 21:56:42 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; bh=j3rnMuYhbaqg0iPBuCQovcFmE3Gh1snJzWbFc7b+K 4k=; b=wkW6DztXiI+VMJnnD2wzb8D11f+aQkI3fOQFU1zQZf0XGcmNt3H3/CUxK FryMJa3SXHaYro3zwOpTdKvxvlLM1M7VpO/yVZdBxWgSMxATJVILYHQKyoAmZoii i87TcuTnRNUtGVU/AsHoWDgtcJFxTFGimiuzub2XRHTZAYUeXY5OHQ7IJuGA74kI MWKAIwkbCQ2CNebKv5yrxswhURTj4p8Grv3WdU+Q2bp8cLU8WGg6+nssXbImrBwx s5NXFdOd9D3zMEbamoio8qMbbpo33c8A1h1cSgv455Q3K+IroBozh/X6u2ZYyJZK ZoZkHfHdozrUTQAK1SJt9XqQrGFwA==
X-ME-Sender: <xms:2XimXUPbsJJwuwrSFiurbIPr9nMJyygHiiU-0AWsoJ2_RQK1dQ80sw>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedufedrjeeggdehudcutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecunecujfgurhepuffvfhfhkffffgggjggtgfesthejre dttdefjeenucfhrhhomhepmfgvihhthhcuofhoohhrvgcuoehmohhorhgvsehnvghtfiho rhhkqdhhvghrvghtihgtshdrtghomheqnecukfhppedutdekrddvvddurddukedtrdduhe enucfrrghrrghmpehmrghilhhfrhhomhepmhhoohhrvgesnhgvthifohhrkhdqhhgvrhgv thhitghsrdgtohhmnecuvehluhhsthgvrhfuihiivgeptd
X-ME-Proxy: <xmx:2XimXRve0hjuok9aWY4N2LC-vMKE1jF__h_DJneB-IZonungWan5VQ> <xmx:2XimXdCz7GIiR7xnY8la-p07wsiBe0KixMfn6TkWo18qiTkzjsP1_w> <xmx:2XimXYZEM3Np7DsSkdjSdHT7T1xwFznSKsjZjI1hSPKA4bIIMOz2Aw> <xmx:2nimXW9JBP96cwYGdpud5vWQMohMJnSc7XhrDgj9Wm7lz2ReTCs-Bw>
Received: from [192.168.1.97] (108-221-180-15.lightspeed.knvltn.sbcglobal.net [108.221.180.15]) by mail.messagingengine.com (Postfix) with ESMTPA id 3AE44D6005A; Tue, 15 Oct 2019 21:56:41 -0400 (EDT)
To: ietf-smtp@ietf.org
References: <20191011160802.50C81C9B780@ary.qy> <alpine.DEB.2.20.1910141200120.8949@grey.csi.cam.ac.uk> <alpine.OSX.2.21.99999.368.1910141020460.72467@ary.local> <alpine.DEB.2.20.1910151228410.8949@grey.csi.cam.ac.uk> <5DA5F942.5030307@isdg.net> <96055.1571170998@turing-police> <5DA6743B.5070202@isdg.net>
From: Keith Moore <moore@network-heretics.com>
Message-ID: <0ab60cd9-759a-572a-622f-41c841e69350@network-heretics.com>
Date: Tue, 15 Oct 2019 21:56:40 -0400
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0
MIME-Version: 1.0
In-Reply-To: <5DA6743B.5070202@isdg.net>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-smtp/2peeWLLXI1nonsEyL0Fi6wIHb9U>
Subject: Re: [ietf-smtp] [OT] (signed TLDs)
X-BeenThere: ietf-smtp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of issues related to Simple Mail Transfer Protocol \(SMTP\) \[RFC 821, RFC 2821, RFC 5321\]" <ietf-smtp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-smtp/>
List-Post: <mailto:ietf-smtp@ietf.org>
List-Help: <mailto:ietf-smtp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Oct 2019 01:56:45 -0000

On 10/15/19 9:36 PM, Hector Santos wrote:

> The technical security aspect of encryption is no longer good enough 
> -- certs now have to be CA-signed now.

Certs that weren't signed by a trusted party were never worth anything 
anyway, unless maybe you manually pinned them.

Keith