Re: [marf] Adrian Farrel's No Objection on draft-ietf-marf-as-15: (with COMMENT)

"Murray S. Kucherawy" <msk@cloudmark.com> Wed, 25 April 2012 20:17 UTC

Return-Path: <msk@cloudmark.com>
X-Original-To: marf@ietfa.amsl.com
Delivered-To: marf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EA45D21F88F5 for <marf@ietfa.amsl.com>; Wed, 25 Apr 2012 13:17:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.555
X-Spam-Level:
X-Spam-Status: No, score=-102.555 tagged_above=-999 required=5 tests=[AWL=0.044, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XmG6Ypm6bxeJ for <marf@ietfa.amsl.com>; Wed, 25 Apr 2012 13:17:37 -0700 (PDT)
Received: from mail.cloudmark.com (cmgw1.cloudmark.com [208.83.136.25]) by ietfa.amsl.com (Postfix) with ESMTP id 7ED7B21F88F7 for <marf@ietf.org>; Wed, 25 Apr 2012 13:17:36 -0700 (PDT)
Received: from ht1-outbound.cloudmark.com ([72.5.239.26]) by mail.cloudmark.com with bizsmtp id 2LHF1j0010as01C01LHF0e; Wed, 25 Apr 2012 13:17:24 -0700
X-CMAE-Match: 0
X-CMAE-Score: 0.00
X-CMAE-Analysis: v=2.0 cv=K4ag7lqI c=1 sm=1 a=QMZKka45TBd+hNGtXG2bIg==:17 a=LvckAehuu68A:10 a=Qrv36LpUKT8A:10 a=zutiEJmiVI4A:10 a=IkcTkHD0fZMA:10 a=xqWC_Br6kY4A:10 a=AEDFM0qtAAAA:8 a=48vgC7mUAAAA:8 a=BKtCKEuFW1E-ie4T75AA:9 a=DcKsNv578sS9B2pPO8oA:7 a=QEXdDO2ut3YA:10 a=jqlaW5bC1iAA:10 a=ObgSaLnxuQYGMWPp:21 a=g1xTM8VxK5Erw1K9:21 a=QMZKka45TBd+hNGtXG2bIg==:117
Received: from EXCH-MBX901.corp.cloudmark.com ([fe80::addf:849a:f71c:4a82]) by exch-htcas902.corp.cloudmark.com ([fe80::54de:dc60:5f3e:334%10]) with mapi id 14.01.0355.002; Wed, 25 Apr 2012 13:16:53 -0700
From: "Murray S. Kucherawy" <msk@cloudmark.com>
To: Adrian Farrel <adrian@olddog.co.uk>, The IESG <iesg@ietf.org>
Thread-Topic: Adrian Farrel's No Objection on draft-ietf-marf-as-15: (with COMMENT)
Thread-Index: AQHNIwXRTxBGS3SrIUOXRS0NLNxzHpar+fwA
Date: Wed, 25 Apr 2012 20:16:52 +0000
Message-ID: <9452079D1A51524AA5749AD23E00392810297C@exch-mbx901.corp.cloudmark.com>
References: <20120425170640.27848.77721.idtracker@ietfa.amsl.com>
In-Reply-To: <20120425170640.27848.77721.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [172.20.2.121]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudmark.com; s=default; t=1335385044; bh=gZmk7tJnOMM5goZUPsXL8ur7y9BktTEZtifhyfzNz9s=; h=From:To:CC:Subject:Date:Message-ID:References:In-Reply-To: Content-Type:Content-Transfer-Encoding:MIME-Version; b=hoTiyURvi46CzI9w0O9wmF1kdaFmG5DPunbAk/bOkUUzggKRXBeIgRNdQnsfdAOIt 9VwG2IOnVmpeAPEFSzG0BF2JPXwKAIh9fqJ/DktuNr1gHn66p427q9dweckPEq/uxZ TME9dseLX373xJNOxKAu07A4/0X6ZWIDtqfR4uTk=
Cc: "draft-ietf-marf-as@tools.ietf.org" <draft-ietf-marf-as@tools.ietf.org>, "marf-chairs@tools.ietf.org" <marf-chairs@tools.ietf.org>, "marf@ietf.org" <marf@ietf.org>
Subject: Re: [marf] Adrian Farrel's No Objection on draft-ietf-marf-as-15: (with COMMENT)
X-BeenThere: marf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Message Abuse Report Format working group discussion list <marf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/marf>, <mailto:marf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/marf>
List-Post: <mailto:marf@ietf.org>
List-Help: <mailto:marf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/marf>, <mailto:marf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 25 Apr 2012 20:17:38 -0000

Hi Adrian,

> -----Original Message-----
> From: Adrian Farrel [mailto:adrian@olddog.co.uk]
> Sent: Wednesday, April 25, 2012 10:07 AM
> To: The IESG
> Cc: marf-chairs@tools.ietf.org; draft-ietf-marf-as@tools.ietf.org
> Subject: Adrian Farrel's No Objection on draft-ietf-marf-as-15: (with
> COMMENT)
> 
> Adrian Farrel has entered the following ballot position for
> draft-ietf-marf-as-15: No Objection
> 
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
> 
> Please refer to http://www.ietf.org/iesg/statement/discuss-
> criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
> 
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
> 
> Forgive me, but doesn't section 8.2 say that forged abuse reports
> constitue a real problem and the two mechanisms available to protect
> against them may result in genuine abuse reports being discarded?

Yes to the first point.  The second point is true of all email, not just abuse reports; if the signer's infrastructure is causing signatures to break, there's no reason to trust the reports even though they bear some kind of signature.  The same goes for, say, a message from your bank that's signed but the signature fails to validate.

> Is the message here "chosse which you think might be the least worse
> problem" or is it "you should use DKIM and SPF, but be aware that you
> may lose some genuine reports"?

It's "You should use DKIM and/or SPF, but make sure they're working properly if you want to reap the benefits."

> I would have liked some clarification as to which message is being
> sent.

That section is only talking about reports.  Which part is unclear?

-MSK