Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
Grant Taylor <gtaylor@tnetconsulting.net> Sun, 06 January 2019 05:54 UTC
Return-Path: <gtaylor@tnetconsulting.net>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A3136131016 for <uta@ietfa.amsl.com>; Sat, 5 Jan 2019 21:54:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=tnetconsulting.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Quzf_Xp42fRW for <uta@ietfa.amsl.com>; Sat, 5 Jan 2019 21:54:32 -0800 (PST)
Received: from tncsrv06.tnetconsulting.net (tncsrv06.tnetconsulting.net [IPv6:2600:3c00:e000:1e9::8849]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4379C131006 for <uta@ietf.org>; Sat, 5 Jan 2019 21:54:32 -0800 (PST)
Received: from Contact-TNet-Consulting-Abuse-for-assistance by tncsrv06.tnetconsulting.net (8.15.2/8.15.2/Debian-3) with ESMTPSA id x065sTLO024525 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NO) for <uta@ietf.org>; Sat, 5 Jan 2019 23:54:31 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=tnetconsulting.net; s=2015; t=1546754071; bh=UtejFQ8pvkcVNVgPx+vrm37g1pudlM/JcvmMnR4pZI0=; h=Subject:To:References:From:Message-ID:Date:User-Agent: MIME-Version:In-Reply-To:Content-Type:Cc:Content-Disposition: Content-Language:Content-Transfer-Encoding:Content-Type:Date:From: In-Reply-To:Message-ID:MIME-Version:References:Reply-To: Resent-Date:Resent-From:Resent-To:Resent-Cc:Sender:Subject:To: User-Agent; b=JQTB0YUmYcOqihdf3L0BkPq/X5cIkjS0so6UUvlDMlKq6FpUfwP+ypTG/0EY+LYNz v8iGCe1SzIegE+VzdzdF3OUyd55AlXBVq7IXHN4GasUrB/GlebZKlS1BdBcS+eM4VO OW2cYmP9JEQpnA806/rieU5Jync2wSFQkZMEa09E=
To: uta@ietf.org
References: <CAOEezJTyEf+Sn9ZqQPue1DFUSoFO211YogJ6ufYJxswWzXk=_A@mail.gmail.com> <20190106010828.CC431200C5ED52@ary.qy> <CAOEezJShOYkmy8-E+8zG=CPXxrWNcxf8q8W8MnW-v1RT0FzEWw@mail.gmail.com> <123cecc0-aba2-9530-c0d9-b6437f295140@domblogger.net> <5169b5ea-f092-5a59-b037-b0bb45a9ff7f@spamtrap.tnetconsulting.net> <e348be25-2bbf-47ad-cee6-3dc75486cdbb@domblogger.net> <13073cdf-b890-8c27-0347-f8070124085f@domblogger.net>
From: Grant Taylor <gtaylor@tnetconsulting.net>
Organization: TNet Consulting
Message-ID: <5faea82a-5dc3-9445-0697-ed6a14100d01@spamtrap.tnetconsulting.net>
Date: Sat, 05 Jan 2019 22:54:34 -0700
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.3.0
MIME-Version: 1.0
In-Reply-To: <13073cdf-b890-8c27-0347-f8070124085f@domblogger.net>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="------------ms090701020808010509060204"
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/xbz9eWp6N7f9nIiBxCScXLaUEbk>
Subject: Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 06 Jan 2019 05:54:34 -0000
On 1/5/19 10:28 PM, Alice Wonder wrote: > Requiring TLS is pointless if the MX record is not secure. I'm inclined to disagree. - I see value in requiring TLS via STARTTLS even if the MX record wasn't secured. - I say inclined because I can't articulate the combinations of unmodified / modified MX record in conjunction with all the other possibilities that connections can be tampered with. Be it hijacking / route poisoning / simply filtering out STARTTLS but not altering anything else. > That's why MTA-STS needs the https component, to secure the MX record > when DNSSEC is not used to do so. > > When DNSSEC is used, DANE then is better at securing the connection so > MTA-STS is only needed when the server and/or client do not support DANE > for SMTP. I disagree. I believe the value of MTA-STS (and HSTS) is the ability to signal that SMTP (HTTP) should -ONLY- be conducted over a secure connection via STARTTLS (TLS). Meaning that SMTP (HTTP) should fail if there isn't a secure connection. The signaling of this fact is what makes MTA-STS so valuable to me. To me, the other aspects of DNSSEC / HTTPS are simply infrastructure necessary to enable delivery of the STS signal. -- Grant. . . . unix || die
- [Uta] SMTP Over TLS on Port 26 - Implicit TLS Pro… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jeremy Harris
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Grant Taylor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Grant Taylor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jim Fenton
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Daniel Margolis
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Viruthagiri Thirumavalavan
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Franck Martin
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jim Fenton
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann
- [Uta] Deprecating "Opportunistic TLS" (not) Viktor Dukhovni
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Alice Wonder
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Daniel Kahn Gillmor
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Jeremy Harris
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Vittorio Bertola
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… John R Levine
- Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS… Peter Gutmann