Re: [TOOLS-DEVELOPMENT] Fwd: Problem with exploder for icnrg-chairs@ietf.org

John Levine <johnl@taugh.com> Fri, 01 July 2022 21:04 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: tools-development@ietfa.amsl.com
Delivered-To: tools-development@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0E86C15C12D for <tools-development@ietfa.amsl.com>; Fri, 1 Jul 2022 14:04:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.857
X-Spam-Level:
X-Spam-Status: No, score=-6.857 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.25, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b=oLcFWSeN; dkim=pass (2048-bit key) header.d=taugh.com header.b=ItgshAxy
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VPO7fWb3Hgta for <tools-development@ietfa.amsl.com>; Fri, 1 Jul 2022 14:04:34 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6D72BC15C12B for <tools-development@ietf.org>; Fri, 1 Jul 2022 14:04:34 -0700 (PDT)
Received: (qmail 26512 invoked from network); 1 Jul 2022 21:04:32 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:cleverness; s=678e.62bf6160.k2207; bh=Mx3ih3Z7YzRrOfFcUFSFQ6sgXb//YAobe48Dib43fRI=; b=oLcFWSeNt+IOQ39qsC83/4tPaGDwoqoU8YQm0e9c4WurkSkoqmMFSzfz6htsvZF6xwc630gurE8hG+/krRgHmHIgugP8UOXU8UyH8dBsM/CLg+ULUrHqgy/CAqEN5qPIVNiorf42DVBX4P7YGh0AKm8s62hWIABSMYOIxSmMqrwIjhfwxR5wnTrBoFmYAh+sKd360qcPGa4Z57JKv+e2y9OPK5n4rx+HU9hNmOk2Jl6hjJW3pFhiWwAxj5SgEOhOzT/KgvSAEf2vM2+R/yQZIu7aOJgu7oucsSjwWp/2ptfGqZrBCDbVAvEBr02Uju+rUnl2FUuVyNpN+wh1NpRXng==
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:cleverness; s=678e.62bf6160.k2207; bh=Mx3ih3Z7YzRrOfFcUFSFQ6sgXb//YAobe48Dib43fRI=; b=ItgshAxyUXA4lRNZ06eWyNKkNzzWwmO3Iyn1wJnVDhvKaD/Dplvn5xx+e96bkYCmtC82oS0BXrrXQrld7voBY4ZYvnxx0gUq7OL+1QijUOjF3IojPSj/JjhphC7HZD/sxmMj1r/An2RHqYZsWCFEUwKi6IkaXe9FX7Rvqi7nY4CXl8R5JmnyGkJpbd+X1M4qu0a3ssYd+6xJSXPdEP7oKxiVRbQCESFB1SuK2cEA8zdbTBBDBYBqly3H/iuS14htsvjVJOV1Zq4J20xF90q4IjxkfD27Y3owa+9Pmm0pX0iSGuIZjJ8XvCKLsS+mFwGqN8lW4xggXVpEY4JqsCFL+Q==
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.3 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 01 Jul 2022 21:04:31 -0000
Received: by ary.qy (Postfix, from userid 501) id 9EB2044C8431; Fri, 1 Jul 2022 17:04:30 -0400 (EDT)
Date: Fri, 01 Jul 2022 17:04:30 -0400
Message-Id: <20220701210431.9EB2044C8431@ary.qy>
From: John Levine <johnl@taugh.com>
To: tools-development@ietf.org
Cc: daveoran@orandom.net
In-Reply-To: <318BD004-BEB7-4525-A063-559830113B75@orandom.net>
Organization: Taughannock Networks
X-Headerized: yes
Cleverness: minimal
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/tools-development/lqovSMVUCNcWCXUX5xyW734DhAc>
Subject: Re: [TOOLS-DEVELOPMENT] Fwd: Problem with exploder for icnrg-chairs@ietf.org
X-BeenThere: tools-development@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Tools Development mail list <tools-development.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tools-development>, <mailto:tools-development-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tools-development/>
List-Post: <mailto:tools-development@ietf.org>
List-Help: <mailto:tools-development-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tools-development>, <mailto:tools-development-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Jul 2022 21:04:40 -0000

It appears that David R. Oran  <daveoran@orandom.net> said:
>>>    <daveoran@orandom.net> (expanded from
>>>    <expand-icnrg-chairs@virtual.ietf.org>):
>>>    host mail.crystalorb.net[45.79.114.168] said: 550 [SPF] 50.223.129.194 is
>>>    not allowed to send mail from intel.com. (in reply to RCPT TO command)

The mail system that handles mail for orandom.net is rejecting mail
from sources that publish an SPF policy record with "-all" which essentially
says don't let anyone forward our mail. Don't do that.
Semi-pro mail admins often claim that doing so is "more secure", but
only in the sense that accepting no mail at all would be "most secure."

The way that the IETF forwards mail for aliases leaves a lot to be
desired, but this particular forwarding issue is a well known
fundamental flaw in SPF that cannot be fixed. That is why no sensible
mail system does what "-all" nominally says.

R's,
John