Re: [Uta] I-D Action: draft-ietf-uta-smtp-tlsrpt-08.txt

James Cloos <cloos@jhcloos.com> Wed, 16 August 2017 19:14 UTC

Return-Path: <cloos@jhcloos.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C66111326AE for <uta@ietfa.amsl.com>; Wed, 16 Aug 2017 12:14:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=jhcloos.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yrO9uQZOwSzD for <uta@ietfa.amsl.com>; Wed, 16 Aug 2017 12:14:30 -0700 (PDT)
Received: from ore.jhcloos.com (ore.jhcloos.com [IPv6:2604:2880::b24d:a297]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EEA1A1323A8 for <uta@ietf.org>; Wed, 16 Aug 2017 12:14:29 -0700 (PDT)
Received: by ore.jhcloos.com (Postfix, from userid 10) id 2D56E1E04D; Wed, 16 Aug 2017 19:14:29 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jhcloos.com; s=ore17; t=1502910869; bh=dpMUezZ16nksDqgDMIiE9vrNpQdXdsZr1kJNbld3qyU=; h=From:To:Subject:In-Reply-To:References:Date:From; b=Iua8Jivhuy/uK5PxK6wfFJVF+ljwIJtw9bUZouivD/FPzzD7ssbQx26x9GJjTb0KA swJiWJNdLqYdrF9fixvdpoRpdWg1ZWiyqfApUXKeaqk2JDRkE9YFC6bhj8VssbR0aV C/xtzjQyQcrkOQxEDzUb+9A/LGnrLoAB1gUgkpBXzcLbqV6ht2B5BW5Jkf4yWvSWU2 9UYySQpRtFKerIcvZK6ns5TVxnUZ3Luql9o7gPNDtVNuThsiKSnguX3aR76yFf4yqx CVsnHo2gHa8J3b2/pbjAl1bIQPm8zJKtHTj7h7MXPdXtWalx7H0a7lr+GcxHnuErzG y29PFd8XbbJ9A==
Received: by carbon.jhcloos.org (Postfix, from userid 500) id 8B75F107AC445; Wed, 16 Aug 2017 19:12:58 +0000 (UTC)
From: James Cloos <cloos@jhcloos.com>
To: uta@ietf.org
In-Reply-To: <150281667771.21036.3537636324107400513@ietfa.amsl.com> (internet-drafts's message of "Tue, 15 Aug 2017 10:04:37 -0700")
References: <150281667771.21036.3537636324107400513@ietfa.amsl.com>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.0.50 (gnu/linux)
Face: iVBORw0KGgoAAAANSUhEUgAAABAAAAAQAgMAAABinRfyAAAACVBMVEX///8ZGXBQKKnCrDQ3 AAAAJElEQVQImWNgQAAXzwQg4SKASgAlXIEEiwsSIYBEcLaAtMEAADJnB+kKcKioAAAAAElFTkSu QmCC
Copyright: Copyright 2017 James Cloos
OpenPGP: 0x997A9F17ED7DAEA6; url=https://jhcloos.com/public_key/0x997A9F17ED7DAEA6.asc
OpenPGP-Fingerprint: E9E9 F828 61A4 6EA9 0F2B 63E7 997A 9F17 ED7D AEA6
Date: Wed, 16 Aug 2017 15:12:58 -0400
Message-ID: <m3d17vl41x.fsf@carbon.jhcloos.org>
Lines: 19
MIME-Version: 1.0
Content-Type: text/plain
X-Hashcash: 1:28:170816:uta@ietf.org::aLr8iGxi23uscCdO:0000S3zWH
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/AG_WRl1csE3sB-muX-OSW19oayQ>
Subject: Re: [Uta] I-D Action: draft-ietf-uta-smtp-tlsrpt-08.txt
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Aug 2017 19:14:32 -0000

One thought:

The https section should specify a recomendation of what the web site
should return when it sees a POST, and what if anything the generator
should do if the web site replies that the report is not to spec.  Ie,
bad syntax or bad contents or the like.

It probably should be json and could be as simple as {true} or {false}.

Any uri which just accepts reports w/o trying to verify would then be
expected to give the ok reply.

OTOH, if the reporters SHOULDN'T care at all about whether the uri
accepted its report, and should just drop the socket as soon as the
packets are ACKed, then the document should specify that.

-JimC
-- 
James Cloos <cloos@jhcloos.com>         OpenPGP: 0x997A9F17ED7DAEA6