Re: [Uta] Require TLS=NO is very much needed

Bron Gondwana <brong@fastmailteam.com> Sun, 19 November 2017 09:46 UTC

Return-Path: <brong@fastmailteam.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AF3F1126CD8 for <uta@ietfa.amsl.com>; Sun, 19 Nov 2017 01:46:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.72
X-Spam-Level:
X-Spam-Status: No, score=-2.72 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fastmailteam.com header.b=Ol1etMOU; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=LSIQwdnr
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rmQvHDKGR2ys for <uta@ietfa.amsl.com>; Sun, 19 Nov 2017 01:45:59 -0800 (PST)
Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3B1DB126D0C for <uta@ietf.org>; Sun, 19 Nov 2017 01:45:55 -0800 (PST)
Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailout.nyi.internal (Postfix) with ESMTP id 75A7920A7C for <uta@ietf.org>; Sun, 19 Nov 2017 04:45:54 -0500 (EST)
Received: from web4 ([10.202.2.214]) by compute6.internal (MEProxy); Sun, 19 Nov 2017 04:45:54 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= fastmailteam.com; h=content-transfer-encoding:content-type:date :from:in-reply-to:message-id:mime-version:references:subject:to :x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=8al9lScZK7Y2QbQUk hdGRKcms5uHGqf4gIUvQ/EO+r0=; b=Ol1etMOUS47MtYMEM8KKblBeZbRiLTpd0 YnzEia/29UBY0QVMp3q5yfIoOzMECRA93DpSQ82hx/7qeUL074ARsjN8XKz8G97z S5OjxCFzzhf2Brp33L5+h26pp+O1rRq1cOTiEtteGYJbUzI0elDQbhFolI1ZlJFX 2yNM1WJwFOrsa/qhYLIIqg24e+bE1b4UM8ztdfv7EplOMpQ5ULSZ8U+Q1z6DeQKw P7SAlnUuVbkHh9/3Y452al91yVFYjbTNHmFdiyQ4roTUF8XpNgupIDkP5oejdfGh yJ7XEzuwsQCkuUWpGw5KMaGe/ROK3/54Oma1wRoUamBSfUovV/efw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=8al9lS cZK7Y2QbQUkhdGRKcms5uHGqf4gIUvQ/EO+r0=; b=LSIQwdnrY0SHLaPhfdcjXv X8UyqCfL6xLMWB5xZ9Vncwi8CD64PAVg3v6SD0KW3KwU0lUaEJ9YyN8BFyA2zcWg 2Nx8vOgXHoTXse1CZSZEzh7Hn1yum/pHT9LM6bS2fpdsg4T0k9SLtC8Y7ZansX/N NqQPy+hwlX6y52wqRqwA99ylAK6AtWg62oLogcXJfGOCVJuAYKE7cQ+qpgQL9HoG EgevabweRwn1+gV3zMGtNZ56oI7fiHzqdb7XxMmPKlqzPM1xwXg9f3GQ+IgnVmHB mUwyfwMhGPoqPtyWMyzvX0gvcFvfIcr0Q+df/PjEwDl2QVQIiPwaZwQKSOUfgBUQ ==
X-ME-Sender: <xms:0lIRWojMjOCGM2mP9wqGnWFlSIWFnnCPUeLGx4DTqzWToqBt42UN-Q>
Received: by mailuser.nyi.internal (Postfix, from userid 99) id 4F394BAB61; Sun, 19 Nov 2017 04:45:54 -0500 (EST)
Message-Id: <1511084754.1013830.1177377576.08837C8D@webmail.messagingengine.com>
From: Bron Gondwana <brong@fastmailteam.com>
To: uta@ietf.org
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: multipart/alternative; boundary="_----------=_151108475410138301"
X-Mailer: MessagingEngine.com Webmail Interface - ajax-4ef04c51
Date: Sun, 19 Nov 2017 20:45:54 +1100
References: <32C4B825-C3D6-4C25-9C1D-BCF4354CA326@dukhovni.org> <ed552e3e-00ce-5329-f38b-f763feacc17c@sunet.se> <5A0E7D70.6060302@isode.com> <eb82779b-bed0-ba40-e642-6d7ec2aec387@sunet.se> <0620480C-32FB-43B3-8C5A-C4752C1C62E3@dukhovni.org> <AEA98959-039D-49D4-B1E6-76882A34CB17@akamai.com> <3C48EC8E-FA2E-4E16-9C02-63ED5E4C46A1@dukhovni.org>
In-Reply-To: <3C48EC8E-FA2E-4E16-9C02-63ED5E4C46A1@dukhovni.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/XAowKzl2Dges5wptdI3BDRwG2es>
Subject: Re: [Uta] Require TLS=NO is very much needed
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 19 Nov 2017 09:46:00 -0000

On Fri, 17 Nov 2017, at 20:15, Viktor Dukhovni wrote:
> 
> 
>> On Nov 17, 2017, at 3:49 AM, Salz, Rich <rsalz@akamai.com> wrote:
>> 
>> I was there and I disagree with your characterization.
> 
> I watched the entire session after the fact, I stand by my
> assessment that the conclusions were premature.  I've been
> focused on this space for ~15 years now, so I am probably
> not making stuff up...

I have, admittedly, only been focused on this space for 13 years, which
I guess means you win on pure number of years.
I was a person who stood up in both Prague and again in Singapore and
argued for a header rather than REQUIRETLS=NO at SMTP stage.  I see no
benefit to adding anything at SMTP stage, or even checking if the
receiver claims to support REQUIRETLS.  If you have a message that
doesn't want TLS checking, then you need to try your best to deliver
it regardless, so you won't be checking for this extension before
trying to send.
> We should also keep in mind that as DANE and STS gain more
> adoption, it will be the "NO" case that will be far more
> useful to the majority of users.  The "YES" case will see
> very little use.  In particular email reports from the
> "tlsrpt" draft, will need "NO", to make sure they get to
> the problem destination, despite their expired or otherwise
> invalid certificates, disabled STARTTLS, ...

I agree with this.  There needs to be a way to contact
misconfigured sites.
Bron.


--
  Bron Gondwana, CEO, FastMail Pty Ltd
  brong@fastmailteam.com