Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 55C47124BAA
 for <uta@ietfa.amsl.com>; Mon,  7 Jan 2019 02:46:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.3
X-Spam-Level: 
X-Spam-Status: No, score=-4.3 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3,
 SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=open-xchange.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id V905iqr77Hfc for <uta@ietfa.amsl.com>;
 Mon,  7 Jan 2019 02:46:26 -0800 (PST)
Received: from mx4.open-xchange.com (alcatraz.open-xchange.com [87.191.39.187])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 2821B130E73
 for <uta@ietf.org>; Mon,  7 Jan 2019 02:46:26 -0800 (PST)
Received: from open-xchange.com (imap.open-xchange.com [10.20.30.10])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by mx4.open-xchange.com (Postfix) with ESMTPS id 16F596A291;
 Mon,  7 Jan 2019 11:46:24 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com;
 s=201705; t=1546857984;
 bh=Ab7TxjR9ExO4h2ktweXLbN2zY5nWRBFUrv+1YzHvV2I=;
 h=Date:From:To:In-Reply-To:References:Subject:From;
 b=IgxK6HhtShgOvvohmWaIVavp+CrhL0dR4WAjBIgBHgPr7spScdsyVr/NMrro2UwVO
 XFKeokmzf1D+EJHNeqO6igb4QTKRa/rl1x7bS9i4WMSjMCgO3Tz39OXuNFjzvnWuE7
 vnyfLliTNW2CrtjpwRvclSEF0Z9GLQ4KMw2P2KpLoL4jvxeehU1baj5t9A2A/9yQ5W
 pmLiez5IiZ3Dk7zTtwUKHV+HGO76fNDW8fdYlxdeoeWcELXsdMm5AMgOBe6zh2hG3o
 sOcuUHVU35WQAoq2Saj+cvNvIJBNeglbREgasL3G65HKh6dXppkr/l5ieFdZ2r3Ybe
 JIUGUUV3k0bRQ==
Received: from appsuite-gw1.open-xchange.com (appsuite-gw1.open-xchange.com
 [10.20.28.81])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by open-xchange.com (Postfix) with ESMTPSA id 0A6573C1E42;
 Mon,  7 Jan 2019 11:46:24 +0100 (CET)
Date: Mon, 7 Jan 2019 11:46:23 +0100 (CET)
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: Viruthagiri Thirumavalavan <giri@dombox.org>, uta@ietf.org
Message-ID: <6153128.17277.1546857983981@appsuite.open-xchange.com>
In-Reply-To: <CAOEezJS+T3pP-GqwJFeT=HGbOu1TkY6W0kyjP9_FcVsaJ=hw7A@mail.gmail.com>
References: <CAOEezJTyEf+Sn9ZqQPue1DFUSoFO211YogJ6ufYJxswWzXk=_A@mail.gmail.com>
 <20190106010828.CC431200C5ED52@ary.qy>
 <CAOEezJShOYkmy8-E+8zG=CPXxrWNcxf8q8W8MnW-v1RT0FzEWw@mail.gmail.com>
 <123cecc0-aba2-9530-c0d9-b6437f295140@domblogger.net>
 <88fad90d-24b6-fe4d-5df8-bc294c4f6b33@bluepopcorn.net>
 <CAOEezJS+T3pP-GqwJFeT=HGbOu1TkY6W0kyjP9_FcVsaJ=hw7A@mail.gmail.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; 
 boundary="----=_Part_17276_1590069061.1546857983975"
X-Priority: 3
Importance: Medium
X-Mailer: Open-Xchange Mailer v7.10.1-Rev3
X-Originating-Client: open-xchange-appsuite
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/x6WyswQg9uBJe7-L9j0jWf-ajjA>
Subject: Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>,
 <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>,
 <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 07 Jan 2019 10:46:28 -0000

------=_Part_17276_1590069061.1546857983975
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit


> Il 7 gennaio 2019 alle 9.19 Viruthagiri Thirumavalavan <giri@dombox.org> ha scritto:
> 
>     Hey all, revised my draft based on the feedback I received from this thread. 
> 
>     Changelog:
> 
>     * Added starttls only support. 
>     * Provided test cases for IDN names. 
>     * Included Jim Fenton's proposal in the related projects section.
>     * No port hardcoding. Removed 26pref and 26only options. Now MX hosts can start with either "smtps-" or "starttls-" prefix
>     * Solution can be used along with STS and DANE
> 
>     https://gist.github.com/mistergiri/a4c9a5f1c26fd7003ebc0652af95d314
> 
Hello,

I remember you from a few months ago on the DMARC-discuss list, when you tried to convince everyone that you had finally solved the problem of spam by introducing your proprietary standard "Sender Alias Domains" (where did that go?). So while I appreciate your ingenuity and willingness to approach big problems that are not completely solved yet, I must also point out that there are good reasons why those problems have not been addressed with easy solutions like the ones you propose. I would advise you to make sure that you fully appreciate the explanations that are given to you on why your proposal is fundamentally flawed, rather than just adjusting the original proposal a bit and keep posting it again.

Specifically, adding whatever semantic value to DNS hostnames or parts thereof is a non-starter for many reasons that have already been pointed out, so please stop proposing that. Moreover, the IETF does not have the power to mandate people to turn on or off specific services at a specific time, nor to change or update their implementations, neither in theory (in regulatory terms) nor in practice, so any proposal should be backwards compatible with the status quo for an indefinite amount of time. So, in the end, your solution fails to prevent downgrade attacks, but even if it did, they have been addressed with two other technologies already (MTA-STS and DANE), so there is really no reason to develop a third one unless you can provide a compelling reason or use case in which both the other two do not work.

On that point, you are right when you say that big systems that host mail for thousands or millions of domains are unlikely to ever implement MTA-STS, as that requires to activate one HTTP service per each domain - but we already have DANE for that case.

Regards,

--

Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
vittorio.bertola@open-xchange.com mailto:vittorio.bertola@open-xchange.com 
Office @ Via Treviso 12, 10144 Torino, Italy

------=_Part_17276_1590069061.1546857983975
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<!doctype html>
<html>
 <head> 
  <meta charset="UTF-8"> 
 </head>
 <body>
  <div>
   <br>
  </div>
  <blockquote type="cite">
   Il 7 gennaio 2019 alle 9.19 Viruthagiri Thirumavalavan &lt;giri@dombox.org&gt; ha scritto: 
   <br>
   <br>
   <div dir="ltr">
    <div dir="ltr">
     Hey all, revised my draft based on the feedback I received from this thread.&nbsp;
     <div>
      <br>
     </div>
     <div>
      Changelog:
     </div>
     <div>
      <br>
     </div>
     <div>
      * Added starttls only support.&nbsp;
     </div>
     <div>
      * Provided test cases for IDN names.&nbsp;
     </div>
     <div>
      * Included Jim Fenton's proposal in the related projects section.
     </div>
     <div>
      * No port hardcoding. Removed 26pref and 26only options. Now MX hosts can start with either "smtps-" or "starttls-" prefix
     </div>
     <div>
      * Solution can be used along with STS and DANE 
      <br>
     </div>
     <div>
      <br>
     </div>
     <div>
      <a href="https://gist.github.com/mistergiri/a4c9a5f1c26fd7003ebc0652af95d314">https://gist.github.com/mistergiri/a4c9a5f1c26fd7003ebc0652af95d314</a>
      <br>
     </div>
    </div>
   </div>
  </blockquote>
  <div>
   Hello,
   <br>
  </div>
  <div>
   <br>
  </div>
  <div>
   I remember you from a few months ago on the DMARC-discuss list, when you tried to convince everyone that you had finally solved the problem of spam by introducing your proprietary standard "Sender Alias Domains" (where did that go?). So while I appreciate your ingenuity and willingness to approach big problems that are not completely solved yet, I must also point out that there are good reasons why those problems have not been addressed with easy solutions like the ones you propose. I would advise you to make sure that you fully appreciate the explanations that are given to you on why your proposal is fundamentally flawed, rather than just adjusting the original proposal a bit and keep posting it again.
   <br>
  </div>
  <div>
   <br>
  </div>
  <div>
   Specifically, adding whatever semantic value to DNS hostnames or parts thereof is a non-starter for many reasons that have already been pointed out, so please stop proposing that. Moreover, the IETF does not have the power to mandate people to turn on or off specific services at a specific time, nor to change or update their implementations, neither in theory (in regulatory terms) nor in practice, so any proposal should be backwards compatible with the status quo for an indefinite amount of time. So, in the end, your solution fails to prevent downgrade attacks, but even if it did, they have been addressed with two other technologies already (MTA-STS and DANE), so there is really no reason to develop a third one unless you can provide a compelling reason or use case in which both the other two do not work.
   <br>
  </div>
  <div>
   <br>
  </div>
  <div>
   On that point, you are right when you say that big systems that host mail for thousands or millions of domains are unlikely to ever implement MTA-STS, as that requires to activate one HTTP service per each domain - but we already have DANE for that case.
   <br>
  </div>
  <div>
   <br>
  </div>
  <div>
   Regards,
  </div>
  <div class="io-ox-signature">
   <p>-- <br class=""></p>
   <pre class="">Vittorio Bertola | Head of Policy &amp; Innovation, Open-Xchange<br><a href="mailto:vittorio.bertola@open-xchange.com">vittorio.bertola@open-xchange.com</a> <br>Office @ Via Treviso 12, 10144 Torino, Italy</pre>
  </div> 
 </body>
</html>
------=_Part_17276_1590069061.1546857983975--

