Re: [Uta] Require TLS=NO is very much needed

Jim Fenton <fenton@bluepopcorn.net> Fri, 17 November 2017 16:19 UTC

Return-Path: <fenton@bluepopcorn.net>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A12A3128B8D for <uta@ietfa.amsl.com>; Fri, 17 Nov 2017 08:19:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=bluepopcorn.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lcMmqkT9smcY for <uta@ietfa.amsl.com>; Fri, 17 Nov 2017 08:19:15 -0800 (PST)
Received: from v2.bluepopcorn.net (v2.bluepopcorn.net [IPv6:2607:f2f8:a994::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7ECA11243FE for <uta@ietf.org>; Fri, 17 Nov 2017 08:19:15 -0800 (PST)
Received: from splunge.local ([202.55.67.146]) (authenticated bits=0) by v2.bluepopcorn.net (8.14.4/8.14.4/Debian-8+deb8u2) with ESMTP id vAHGJB2K020638 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO) for <uta@ietf.org>; Fri, 17 Nov 2017 08:19:14 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=bluepopcorn.net; s=supersize; t=1510935554; bh=F4umQtv836uNMGBBo4KSh/vaPkWqC1/3xgkavtdH9RM=; h=Subject:To:References:From:Date:In-Reply-To; b=kr7hQHM0bxHs5DiXCF4kfOEOvDKfvdaWElm8V0nU56P+8Eci95En8hR601fyRuwwS CQdpuwF4voy61mR+ZF7DoBZAfifo4IvHw27EwcXHMcyi5uFtTJAW7pM6+D+wcoz9g+ uFI5+A9kI//hAI2LhGq6x7dKQJ+8ARejC3tP0DR8=
To: uta@ietf.org
References: <32C4B825-C3D6-4C25-9C1D-BCF4354CA326@dukhovni.org> <ed552e3e-00ce-5329-f38b-f763feacc17c@sunet.se> <7FD24C09-99A6-4847-BCE7-4455F62188FC@dukhovni.org> <5d638100-295a-8b05-7958-470abaaf3ac3@cisco.com>
From: Jim Fenton <fenton@bluepopcorn.net>
Message-ID: <847cec60-7cb6-4168-9916-71c835d5919c@bluepopcorn.net>
Date: Fri, 17 Nov 2017 08:19:10 -0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
In-Reply-To: <5d638100-295a-8b05-7958-470abaaf3ac3@cisco.com>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/hrL9mMvU-6AHJ0d3OnuT26Wk1DA>
Subject: Re: [Uta] Require TLS=NO is very much needed
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Nov 2017 16:19:17 -0000

On 11/17/17 6:28 AM, Eliot Lear wrote:
> I've been watching the back and forth and trying to get my hands around
> the technical issues between the two cases.  The closest I see for a
> technical explanation in this thread is this:
>
>
> On 11/17/17 3:55 AM, Viktor Dukhovni wrote:
>> As I pointed out in another message, BOTH REQUIRETLS=YES
>> *and* REQUIRETLS=NO need to be encapsulated in headers, but
>> the YES case *also* needs an ESMTP extension, while the
>> NO case does not.  It makes sense to define both in the
>> same document.
> For those of us who were not in the room, can someone explain the case
> in technical detail for *not* doing REQUIRETLS=NO in the same document? 
> Jim?

The "yes" and "no" cases solve different problems: in the case of "yes"
it's stating a security requirement, and in the case of "no" it's
enhancing deliverability in the presence of MTA-STS or DANE policies. I
can picture that some MTAs might deploy one and not the other, which
makes it confusing if we're calling them both REQUIRETLS and putting
them in the same specification.

The "yes" case involves negotiation of an SMTP extension and may also
involve the addition of a header field. The "no" case involves only the
addition of a header field.

-Jim