Re: [ietf-smtp] SMTP Over TLS on Port 26 - Implicit TLS Proposal

Mark Andrews <marka@isc.org> Thu, 17 January 2019 11:57 UTC

Return-Path: <marka@isc.org>
X-Original-To: ietf-smtp@ietfa.amsl.com
Delivered-To: ietf-smtp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 28D5112950A for <ietf-smtp@ietfa.amsl.com>; Thu, 17 Jan 2019 03:57:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.901
X-Spam-Level:
X-Spam-Status: No, score=-6.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wUf5Lp4Nm1WT for <ietf-smtp@ietfa.amsl.com>; Thu, 17 Jan 2019 03:57:10 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C86C1130F13 for <ietf-smtp@ietf.org>; Thu, 17 Jan 2019 03:57:10 -0800 (PST)
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.pao1.isc.org (Postfix) with ESMTPS id AABF93AB05C; Thu, 17 Jan 2019 11:57:08 +0000 (UTC)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTPS id 9787E160055; Thu, 17 Jan 2019 11:57:08 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id 806D216005C; Thu, 17 Jan 2019 11:57:08 +0000 (UTC)
Received: from zmx1.isc.org ([127.0.0.1]) by localhost (zmx1.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id u9PNy1gYL90d; Thu, 17 Jan 2019 11:57:08 +0000 (UTC)
Received: from [172.30.42.67] (c27-253-115-14.carlnfd2.nsw.optusnet.com.au [27.253.115.14]) by zmx1.isc.org (Postfix) with ESMTPSA id CE6F8160055; Thu, 17 Jan 2019 11:57:07 +0000 (UTC)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <de23b577-5e3a-fb2c-2af8-0aa1bcd9f68f@evert.net>
Date: Thu, 17 Jan 2019 22:57:05 +1100
Cc: ietf-smtp@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <BBD0C903-1B61-415D-9FB4-C2F224D17986@isc.org>
References: <CAOEezJQL_2_YUDJ3UW6MJ2pDtBzEwKDMV3a5PAvDqwmg5Gd6Xw@mail.gmail.com> <20190107085807.GA9513@ams-1.poolp.org> <CAOEezJSnPcz919k87fS5RFK5dtVSfqn00ow-QtxudDdm9rP9_w@mail.gmail.com> <20190107111354.GA63927@ams-1.poolp.org> <9e5c4dd8-7acf-8da7-4d4e-9337ef6e6101@pscs.co.uk> <I8HxJeDFDKNcFAQA@highwayman.com> <CAOEezJQiH=HNFw5rRbNEH1VjCuqyLxwtP6rRdLyxpHVA6sbHTQ@mail.gmail.com> <CAOEezJSV3HJ1Shd4izCfXvSYUyF4ddOUx4C2MMOZsYi5NVM0Tw@mail.gmail.com> <3742.1546968196@turing-police.cc.vt.edu> <ABDA536C-10AA-4C66-808C-D8464982C6F9@fugue.com> <0ddeaf40-d55d-84b7-00ce-efe7fb36c313@tana.it> <CAPt1N1k6Yaa8x177+xn5u5V2LTiYHZXSB2kuveSadfxied0SpQ@mail.gmail.com> <a76d27a1-2bee-c473-61b0-98461b2ce067@tana.it> <ce508d2e-a8b7-9d6a-6e05-27dc71465b25@pscs.co.uk> <8c76cb49-3341-9173-f176-e45346a0ad57@alameth.org> <7910.1547069205@turing-police.cc.vt.edu> <de23b577-5e3a-fb2c-2af8-0aa1bcd9f68f@evert.net>
To: Evert Mouw <post=40evert.net@dmarc.ietf.org>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-smtp/GzN_I2Ubadrx0GZ87VdSmhXIo5I>
Subject: Re: [ietf-smtp] SMTP Over TLS on Port 26 - Implicit TLS Proposal
X-BeenThere: ietf-smtp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of issues related to Simple Mail Transfer Protocol \(SMTP\) \[RFC 821, RFC 2821, RFC 5321\]" <ietf-smtp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-smtp/>
List-Post: <mailto:ietf-smtp@ietf.org>
List-Help: <mailto:ietf-smtp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Jan 2019 11:57:13 -0000


> On 17 Jan 2019, at 8:43 pm, Evert Mouw <post=40evert.net@dmarc.ietf.org> wrote:
> 
> Hi,
> 
> On 09/01/2019 01.43, Viruthagiri Thirumavalavan wrote:
> > There are people out there who has personal websites like firstnamelastname.com and email address like me@firstnamelastname.com
> 
> Yeah and I'm one of them. I run my private mailserver for 3 users, one domain name for each.
> 
> On 07/01/2019 12.34, Paul Smith wrote:
> > Note that port 465 is defined as for SMTPS for *submission*, so it's the SMTPS version of 587, not the SMTPS version of 25.
> 
> That is correct, but for most mailservers relaying is disabled anyway, so in practice even port 25 has become a submission gate. Also, you could configure port 465 to allow relaying... out of the box many mail daemons allow this, e.g. I "submit" my outgoing mail to 465 using Postfix. It is messy.
> 
> On 09/01/2019 20.11, Alessandro Vesely wrote:
> > *Port 26 is simple*.  Straightforward for servers that already implement 465.
> > No-brainer for clients.  The only risk is connection timeout on a
> > non-interactive job.  Does it hurt?
> 
> Exactly. Also, it makes it easier to recognize a secured mail transport. No possible plaintext as with STARTTLS (when the latter fails, mail could proceed over an unencrypted transport).
> 
> On 09/01/2019 21.37, Carl S. Gutekunst wrote:
> > Devil's advocate question: Do we (the community) care about improved connection latency?
> 
> I do.
> 
> On 09/01/2019 22.26, valdis.kletnieks@vt.edu wrote:
> > My intuition says that this proposal doesn't help improve latency, because
> > the hit you take waiting for a timeout on port 26 to a non-adopter server
> > is going to overwhelm any savings from the STARTTLS RTT not being
> > needed.
> 
> Good point. I would love a MXS record (Mail eXchanger Secure). Maybe such a MXS SHOULD be an alias to an already existent MX record.
> 
> As for the port number: if port 24 is already reserved for private mail systems (!! so no loss of port numbers !!), but not used anymore, it would also make a good candidate. I like the lower number, "try 24 before 25", but port 26 makes sense too. It makes way more sense (to me at least) to have both port numbers in one range, be it 25-25 or 25-26.
> 
> One of the benefits of a TLS-only port is the non-dependency on DNSSEC, DANE, and whatnot. It is *simple*, easy to implement (by using e.g. an SSL wrapper), fast, and pleasing to the eye.

DNSSEC is STILL needed with a TLS only port.  You have no TRUSTED name to pass to TLS to check the server certificate against without it.

SMTP is not HTTP.  SMTP has a different set of security properties to HTTP.

> Of course this matter doesn't prelude the end of the world ;-)
> 
> Regards, Evert
> 
>  _______________
> < Send me mail! >
>  ---------------
>         \   ^__^
>          \  (oo)\_______
>             (__)\       )\/\
>                 ||----w |
>                 ||     ||
> 
> 
> _______________________________________________
> ietf-smtp mailing list
> ietf-smtp@ietf.org
> https://www.ietf.org/mailman/listinfo/ietf-smtp

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org