Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
Vittorio Bertola <vittorio.bertola@open-xchange.com> Mon, 07 January 2019 10:46 UTC
Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55C47124BAA for <uta@ietfa.amsl.com>; Mon, 7 Jan 2019 02:46:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level:
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=open-xchange.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V905iqr77Hfc for <uta@ietfa.amsl.com>; Mon, 7 Jan 2019 02:46:26 -0800 (PST)
Received: from mx4.open-xchange.com (alcatraz.open-xchange.com [87.191.39.187]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2821B130E73 for <uta@ietf.org>; Mon, 7 Jan 2019 02:46:26 -0800 (PST)
Received: from open-xchange.com (imap.open-xchange.com [10.20.30.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx4.open-xchange.com (Postfix) with ESMTPS id 16F596A291; Mon, 7 Jan 2019 11:46:24 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com; s=201705; t=1546857984; bh=Ab7TxjR9ExO4h2ktweXLbN2zY5nWRBFUrv+1YzHvV2I=; h=Date:From:To:In-Reply-To:References:Subject:From; b=IgxK6HhtShgOvvohmWaIVavp+CrhL0dR4WAjBIgBHgPr7spScdsyVr/NMrro2UwVO XFKeokmzf1D+EJHNeqO6igb4QTKRa/rl1x7bS9i4WMSjMCgO3Tz39OXuNFjzvnWuE7 vnyfLliTNW2CrtjpwRvclSEF0Z9GLQ4KMw2P2KpLoL4jvxeehU1baj5t9A2A/9yQ5W pmLiez5IiZ3Dk7zTtwUKHV+HGO76fNDW8fdYlxdeoeWcELXsdMm5AMgOBe6zh2hG3o sOcuUHVU35WQAoq2Saj+cvNvIJBNeglbREgasL3G65HKh6dXppkr/l5ieFdZ2r3Ybe JIUGUUV3k0bRQ==
Received: from appsuite-gw1.open-xchange.com (appsuite-gw1.open-xchange.com [10.20.28.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by open-xchange.com (Postfix) with ESMTPSA id 0A6573C1E42; Mon, 7 Jan 2019 11:46:24 +0100 (CET)
Date: Mon, 07 Jan 2019 11:46:23 +0100
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: Viruthagiri Thirumavalavan <giri@dombox.org>, uta@ietf.org
Message-ID: <6153128.17277.1546857983981@appsuite.open-xchange.com>
In-Reply-To: <CAOEezJS+T3pP-GqwJFeT=HGbOu1TkY6W0kyjP9_FcVsaJ=hw7A@mail.gmail.com>
References: <CAOEezJTyEf+Sn9ZqQPue1DFUSoFO211YogJ6ufYJxswWzXk=_A@mail.gmail.com> <20190106010828.CC431200C5ED52@ary.qy> <CAOEezJShOYkmy8-E+8zG=CPXxrWNcxf8q8W8MnW-v1RT0FzEWw@mail.gmail.com> <123cecc0-aba2-9530-c0d9-b6437f295140@domblogger.net> <88fad90d-24b6-fe4d-5df8-bc294c4f6b33@bluepopcorn.net> <CAOEezJS+T3pP-GqwJFeT=HGbOu1TkY6W0kyjP9_FcVsaJ=hw7A@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_17276_1590069061.1546857983975"
X-Priority: 3
Importance: Medium
X-Mailer: Open-Xchange Mailer v7.10.1-Rev3
X-Originating-Client: open-xchange-appsuite
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/x6WyswQg9uBJe7-L9j0jWf-ajjA>
Subject: Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jan 2019 10:46:28 -0000
> Il 7 gennaio 2019 alle 9.19 Viruthagiri Thirumavalavan <giri@dombox.org> ha scritto: > > Hey all, revised my draft based on the feedback I received from this thread. > > Changelog: > > * Added starttls only support. > * Provided test cases for IDN names. > * Included Jim Fenton's proposal in the related projects section. > * No port hardcoding. Removed 26pref and 26only options. Now MX hosts can start with either "smtps-" or "starttls-" prefix > * Solution can be used along with STS and DANE > > https://gist.github.com/mistergiri/a4c9a5f1c26fd7003ebc0652af95d314 > Hello, I remember you from a few months ago on the DMARC-discuss list, when you tried to convince everyone that you had finally solved the problem of spam by introducing your proprietary standard "Sender Alias Domains" (where did that go?). So while I appreciate your ingenuity and willingness to approach big problems that are not completely solved yet, I must also point out that there are good reasons why those problems have not been addressed with easy solutions like the ones you propose. I would advise you to make sure that you fully appreciate the explanations that are given to you on why your proposal is fundamentally flawed, rather than just adjusting the original proposal a bit and keep posting it again. Specifically, adding whatever semantic value to DNS hostnames or parts thereof is a non-starter for many reasons that have already been pointed out, so please stop proposing that. Moreover, the IETF does not have the power to mandate people to turn on or off specific services at a specific time, nor to change or update their implementations, neither in theory (in regulatory terms) nor in practice, so any proposal should be backwards compatible with the status quo for an indefinite amount of time. So, in the end, your solution fails to prevent downgrade attacks, but even if it did, they have been addressed with two other technologies already (MTA-STS and DANE), so there is really no reason to develop a third one unless you can provide a compelling reason or use case in which both the other two do not work. On that point, you are right when you say that big systems that host mail for thousands or millions of domains are unlikely to ever implement MTA-STS, as that requires to activate one HTTP service per each domain - but we already have DANE for that case. Regards, -- Vittorio Bertola | Head of Policy & Innovation, Open-Xchange vittorio.bertola@open-xchange.com mailto:vittorio.bertola@open-xchange.com Office @ Via Treviso 12, 10144 Torino, Italy
- [Uta] SMTP Over TLS on Port 26 - Implicit TLS Pro… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jeremy Harris
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Grant Taylor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Grant Taylor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jim Fenton
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Daniel Margolis
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Franck Martin
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jim Fenton
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann
- [Uta] Deprecating "Opportunistic TLS" (not) Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Daniel Kahn Gillmor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jeremy Harris
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John R Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann