Re: [ietf-smtp] Public Key Look Up

Valdis Kl ē tnieks <valdis.kletnieks@vt.edu> Wed, 12 May 2021 16:31 UTC

Return-Path: <valdis@vt.edu>
X-Original-To: ietf-smtp@ietfa.amsl.com
Delivered-To: ietf-smtp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8B8C23A0F2E for <ietf-smtp@ietfa.amsl.com>; Wed, 12 May 2021 09:31:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=vt-edu.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lU3_pEgnf8NV for <ietf-smtp@ietfa.amsl.com>; Wed, 12 May 2021 09:31:05 -0700 (PDT)
Received: from mail-qk1-x736.google.com (mail-qk1-x736.google.com [IPv6:2607:f8b0:4864:20::736]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DFAF93A0F0E for <ietf-smtp@ietf.org>; Wed, 12 May 2021 09:31:04 -0700 (PDT)
Received: by mail-qk1-x736.google.com with SMTP id o27so22759699qkj.9 for <ietf-smtp@ietf.org>; Wed, 12 May 2021 09:31:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vt-edu.20150623.gappssmtp.com; s=20150623; h=sender:from:to:cc:subject:in-reply-to:references:mime-version :content-transfer-encoding:date:message-id; bh=skmli7QLW0C5RDZmTqhIFsBnfuOFu/w0wYxF+VSZHpo=; b=JQgfIO7qGnvOWIfxUc0DRs5UUieHJlTd75t5ASnPdx4Nu3hREJEcSwVnIGpaSuikHW xwXGLCIll/GvWEyQ9Ew9VR77V4RFOWociqppyytryJfCzkX4u/NmbdMh82FWLfI2oIKO NFkK6ythIfTKhx1rKB9Gd/jYrnW+TuvVKjEVuYj+VFgOWskoEyu+/EsIutPlu3Eeqp4y gUB/Dr/iCuBqQxJjzdpqfvfc7G635SSigr6oDqLKDywNfTvgrao6IZgfUjOXkf2A0uYH nl7Vho/3Qz210Jx2woQPGTAPT2cSz2YIBzzEeCF4SZxt2puM0Tzokw8k7PjKCK54xEl8 cwfw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:in-reply-to:references :mime-version:content-transfer-encoding:date:message-id; bh=skmli7QLW0C5RDZmTqhIFsBnfuOFu/w0wYxF+VSZHpo=; b=tKcaR109DcPtWzVVTh5x9SO7Cle8ny3OU1H0qy00mPJJsEJBXQIcWhCqPLMV8rVZYh yyK5p6wxH0XkSH0Xz2/YF/a7rAwfAfsGf4mKDojnfJCgjmfhcXBj7P8xspK6R3pyfk8p jWsJWvEFFbONqBWXjdh5SFCmQt+tSRw5wo/yM9YkLNE0BZoWAsl9ppUTTSDjdK7gS6o0 t/7pYodFU1t3fP563Ibeywi9T2ETTvQPa+3jMtpKHoB4poPxD4VwFuihOWATDDbhucZs gbDR1qapFZSUG/UkoO4Bmv+Yb04RBz6krwbUduC8y+kDLdT03kpoRgAiy6TA9v+DHEEp Xf7A==
X-Gm-Message-State: AOAM530DOWyq/7t1/8Q3YdKmcuqsHhFy/RQLfJ/lrjPScuWQri5R/APp Asg82WaZB5IOGqO1riGZtoRwSQ==
X-Google-Smtp-Source: ABdhPJyVn92As9sBs9gkOCx6eOuutSjISCCoshQ5vWN8igake/qVX2fursZ/YEwlpP39TgC0H5Ut+w==
X-Received: by 2002:a37:6606:: with SMTP id a6mr30663664qkc.444.1620837063197; Wed, 12 May 2021 09:31:03 -0700 (PDT)
Received: from turing-police ([2601:5c0:c380:d61::359]) by smtp.gmail.com with ESMTPSA id u9sm342870qtf.76.2021.05.12.09.31.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 May 2021 09:31:02 -0700 (PDT)
Sender: Valdis Kletnieks <valdis@vt.edu>
From: Valdis Kl=?utf-8?Q?=c4=93?=tnieks <valdis.kletnieks@vt.edu>
X-Google-Original-From: "Valdis Klētnieks" <Valdis.Kletnieks@vt.edu>
X-Mailer: exmh version 2.9.0 11/07/2018 with nmh-1.7+dev
To: Alessandro Vesely <vesely@tana.it>
Cc: John C Klensin <john-ietf@jck.com>, John Levine <johnl@taugh.com>, ietf-smtp@ietf.org
In-Reply-To: <79ed2289-80af-5744-86f1-6d7a13b730ab@tana.it>
References: <20210511185543.C751179052B@ary.qy> <D7EABCF7E8976BE735927C69@PSB> <79ed2289-80af-5744-86f1-6d7a13b730ab@tana.it>
Mime-Version: 1.0
Content-Type: multipart/signed; boundary="==_Exmh_1620837061_577619P"; micalg="pgp-sha1"; protocol="application/pgp-signature"
Content-Transfer-Encoding: 7bit
Date: Wed, 12 May 2021 12:31:01 -0400
Message-ID: <676285.1620837061@turing-police>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-smtp/FNUY3BIpstAXFm-VER71XXawsIY>
Subject: Re: [ietf-smtp] Public Key Look Up
X-BeenThere: ietf-smtp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of issues related to Simple Mail Transfer Protocol \(SMTP\) \[RFC 821, RFC 2821, RFC 5321\]" <ietf-smtp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-smtp/>
List-Post: <mailto:ietf-smtp@ietf.org>
List-Help: <mailto:ietf-smtp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 12 May 2021 16:31:09 -0000

On Wed, 12 May 2021 12:09:28 +0200, Alessandro Vesely said:

> >> Personally, as a passive-aggressive mail system operator, the
> >> only keys my MX would publish would be proxy ones that let my
> >> MTA decode the mail and do spam and malware filtering.
>
>
> I was talking about /public/ keys.

Right.  Your MX publishes a public key to which it has the corresponding
private key.  This is well understood technology - see any company that
intercepts https:// and re-encrypts the user-side traffic using their own keys.