[Mailsec] Re: SMTP headers in DATA block?

Steffen Nurpmeso <steffen@sdaoden.eu> Fri, 06 June 2025 23:13 UTC

Return-Path: <steffen@sdaoden.eu>
X-Original-To: mailsec@mail2.ietf.org
Delivered-To: mailsec@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B02BC31F93F5 for <mailsec@mail2.ietf.org>; Fri, 6 Jun 2025 16:13:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=sdaoden.eu header.b="DS6bWjzr"; dkim=neutral reason="invalid (unsupported algorithm adaed25519-sha256)" header.d=sdaoden.eu header.b="xPiJ+CZg"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LcGtMGV5KMHq for <mailsec@mail2.ietf.org>; Fri, 6 Jun 2025 16:13:03 -0700 (PDT)
Received: from sdaoden.eu (sdaoden.eu [217.144.132.164]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 202AF31F93F0 for <mailsec@ietf.org>; Fri, 6 Jun 2025 16:13:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sdaoden.eu; s=citron; t=1749251580; x=1749918246; h=date:author:from:to:subject: message-id:in-reply-to:references:mail-followup-to:openpgp:blahblahblah: author:from:subject:date:to:cc:resent-author:resent-date:resent-from: resent-sender:resent-to:resent-cc:resent-reply-to:resent-message-id: in-reply-to:references:mime-version:content-type: content-transfer-encoding:content-disposition:content-id: content-description:message-id:mail-followup-to:openpgp:blahblahblah; bh=N9QT+aY2VdmuXV9r0vKQbLSTuEQzJqM5wUirxpPpuQU=; b=DS6bWjzrxwu76bOj6FPdTcqexzcO00ImkMfvmdvxJ81u9U99O0kkTjn5doEbbeubHjE6w8Sn 2xALMh41ySmRMvc+NSm3FAuPAwC45zNm/T3GC9uPknSaizGBrYTodjvQFm5LXVvGoQKvVsJ3t0 4omxXMRgr45dJJty1yBGDYcqW/USNYlvpYSJOZBnL3LTI9xOQ2qB3IZVkUHYRjdzFK8w2ZKy6x kZFn0XsjJXjRttjo1nqI/IT14Z39QrNRsZsijvklECHksO6iPshh71hn8uthRnooiuZD4cGhlb Wep7n6NM5niC1+WaDfjMrEs9IJLGjs25ytM7xctcaZG8FLdA==
DKIM-Signature: v=1; a=adaed25519-sha256; c=relaxed/relaxed; d=sdaoden.eu; s=orange; t=1749251580; x=1749918246; h=date:author:from:to:subject: message-id:in-reply-to:references:mail-followup-to:openpgp:blahblahblah: author:from:subject:date:to:cc:resent-author:resent-date:resent-from: resent-sender:resent-to:resent-cc:resent-reply-to:resent-message-id: in-reply-to:references:mime-version:content-type: content-transfer-encoding:content-disposition:content-id: content-description:message-id:mail-followup-to:openpgp:blahblahblah; bh=N9QT+aY2VdmuXV9r0vKQbLSTuEQzJqM5wUirxpPpuQU=; b=xPiJ+CZgJBlIgkPBG4VkHjSWKvJD4qA6vsO/XUlj+geUBh1S4EROJT5xawKenDryH6/CxoRN /argeLL8g3wQCQ==
Date: Sat, 07 Jun 2025 01:12:59 +0200
Author: Steffen Nurpmeso <steffen@sdaoden.eu>
From: Steffen Nurpmeso <steffen@sdaoden.eu>
To: mailsec@ietf.org
Message-ID: <20250606231259.aOiuVlbH@steffen%sdaoden.eu>
In-Reply-To: <20250606223156.rzojSdtc@steffen%sdaoden.eu>
References: <5223991.nocEyzAEji@workstation.vm.ideapad.lan> <20250606223156.rzojSdtc@steffen%sdaoden.eu>
Mail-Followup-To: mailsec@ietf.org
User-Agent: s-nail v14.9.25-663-g0c41f463ef
OpenPGP: id=EE19E1C1F2F7054F8D3954D8308964B51883A0DD; url=https://ftp.sdaoden.eu/steffen.asc; preference=signencrypt
BlahBlahBlah: Any stupid boy can crush a beetle. But all the professors in the world can make no bugs.
Message-ID-Hash: 5KEBIRJ3O6ENELCLT6T4TNPHASMM2DEZ
X-Message-ID-Hash: 5KEBIRJ3O6ENELCLT6T4TNPHASMM2DEZ
X-MailFrom: steffen@sdaoden.eu
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Mailsec] Re: SMTP headers in DATA block?
List-Id: Email Security Issues <mailsec.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/mailsec/dpPkNv5me8P93IRfYOJ11XqxsvQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/mailsec>
List-Help: <mailto:mailsec-request@ietf.org?subject=help>
List-Owner: <mailto:mailsec-owner@ietf.org>
List-Post: <mailto:mailsec@ietf.org>
List-Subscribe: <mailto:mailsec-join@ietf.org>
List-Unsubscribe: <mailto:mailsec-leave@ietf.org>

Steffen Nurpmeso wrote in
 <20250606223156.rzojSdtc@steffen%sdaoden.eu>:
 ...
 |In my opinion thus: if the DKIM signature of a sender verifies,
 |then this implies that in your example the RFC 5321.MAIL FROM is
 |allowed to send a message for the RFC 5322.From, period.

Not to mention that 5322 really says that if there are multiple
entries in 5322.From, 5322.Sender should be set.
That never made it to DKIM, not to talk about standards which
started to talk about 5322.From.
Though we now have Author, and even though it seems to finally get
some traction, not so in the IETF aka iterated DKIM / xy, where
there is no talk whatsover, also not in regard what to do with
Author as an indicator.

I want to express my doubts on the quality of software
surrounding all that, explicitly not leaving out my own, how tiny
it may be.

Outsourcing user identification issues downstream seems to be
a very strange thing to do.  It is impossible.
Actually, to be very very honest.  It is laughable.

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)