Re: [yam] draft-daboo-srv-email: POP3S/IMAPS?
Julien ÉLIE <julien@trigofacile.com> Mon, 18 January 2010 08:18 UTC
Return-Path: <julien@trigofacile.com>
X-Original-To: yam@core3.amsl.com
Delivered-To: yam@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 08EB63A6A36 for <yam@core3.amsl.com>; Mon, 18 Jan 2010 00:18:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.26
X-Spam-Level:
X-Spam-Status: No, score=-2.26 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, MIME_8BIT_HEADER=0.3, STOX_REPLY_TYPE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sbdKVn8zkvPK for <yam@core3.amsl.com>; Mon, 18 Jan 2010 00:18:03 -0800 (PST)
Received: from 6.mail-out.ovh.net (6.mail-out.ovh.net [91.121.25.210]) by core3.amsl.com (Postfix) with SMTP id CEF783A680F for <yam@ietf.org>; Mon, 18 Jan 2010 00:18:02 -0800 (PST)
Received: (qmail 5524 invoked by uid 503); 18 Jan 2010 07:22:36 -0000
Received: from b3.ovh.net (HELO mail413.ha.ovh.net) (213.186.33.53) by 6.mail-out.ovh.net with SMTP; 18 Jan 2010 07:22:36 -0000
Received: from b0.ovh.net (HELO queueout) (213.186.33.50) by b0.ovh.net with SMTP; 18 Jan 2010 07:17:59 -0000
Received: from aaubervilliers-151-1-66-216.w81-48.abo.wanadoo.fr (HELO Iulius) (julien%trigofacile.com@81.48.9.216) by ns0.ovh.net with SMTP; 18 Jan 2010 07:17:58 -0000
Message-ID: <75D72130D5F940E49B78BB10F879AC9A@Iulius>
From: Julien ÉLIE <julien@trigofacile.com>
To: yam@ietf.org, imap-protocol@u.washington.edu
References: <9A584868-5961-4871-B32E-915394043727@sabahattin-gucukoglu.com><01NIK8RBBRJK004042@mauve.mrochek.com><E3A31776-016E-4DD9-9F5B-B51821EFB0CF@sabahattin-gucukoglu.com> <01NIKSRRB7US004042@mauve.mrochek.com>
In-Reply-To: <01NIKSRRB7US004042@mauve.mrochek.com>
Date: Mon, 18 Jan 2010 08:17:59 +0100
Organization: TrigoFACILE -- http://www.trigofacile.com/
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"; charset="iso-8859-1"; reply-type="original"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Windows Mail 6.0.6002.18005
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6002.18005
X-Ovh-Tracer-Id: 803329584475995462
X-Ovh-Remote: 81.48.9.216 (aaubervilliers-151-1-66-216.w81-48.abo.wanadoo.fr)
X-Ovh-Local: 213.186.33.20 (ns0.ovh.net)
X-Spam-Check: DONE|U 0.5/N
Cc: ned.freed@mrochek.com
Subject: Re: [yam] draft-daboo-srv-email: POP3S/IMAPS?
X-BeenThere: yam@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Yet Another Mail working group discussion list <yam.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/yam>, <mailto:yam-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/yam>
List-Post: <mailto:yam@ietf.org>
List-Help: <mailto:yam-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/yam>, <mailto:yam-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Jan 2010 08:18:04 -0000
Hi Ned, > But we have documented this at this level of detail before now - in RFC 2595 > section 7. > > Now, I have no objection to adding a sentence to the security considerations > section saying that use of imaps/pops are discouraged and pointing to the > previous text on this issue. But I see little if any value in repeating the > explanation here. And I'll again repeat that if your goal really is to change > existing deployment practices, the only chance you have of doing that is with a > separate document specifically on this point and this point alone. For what it's worth, RFC 4642 for the STARTTLS command with NNTP mentions in its introduction: In some existing implementations, TCP port 563 has been dedicated to NNTP over TLS. These implementations begin the TLS negotiation immediately upon connection and then continue with the initial steps of an NNTP session. This use of TLS on a separate port is discouraged for the reasons documented in Section 7 of "Using TLS with IMAP, POP3 and ACAP" [TLS-IMAPPOP]. This specification formalizes the STARTTLS command already in occasional use by the installed base. The STARTTLS command rectifies a number of the problems with using a separate port for a "secure" protocol variant; it is the preferred way of using TLS with NNTP. [TLS-IMAPPOP] Newman, C., "Using TLS with IMAP, POP3 and ACAP", RFC 2595, June 1999. Same problem. That behaviour was never documented, but unfortunately is what is currently usually implemented :-/ -- Julien ÉLIE « The most effective way to remember your wife's birthday is to forget it once... » (Nash)
- [yam] draft-daboo-srv-email: POP3S/IMAPS? Sabahattin Gucukoglu
- Re: [yam] [Imap-protocol] draft-daboo-srv-email: … Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] [Imap-protocol] draft-daboo-srv-email: … Lyndon Nerenberg
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Sabahattin Gucukoglu
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Julien ÉLIE
- Re: [yam] [Imap-protocol] draft-daboo-srv-email: … Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Tony Finch
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Arnt Gulbrandsen
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Tony Finch
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Arnt Gulbrandsen
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Timo Sirainen
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Tony Finch
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Tony Finch
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Arnt Gulbrandsen
- Re: [yam] [Imap-protocol] Re: draft-daboo-srv-ema… Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Tony Finch
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Alfred Hönes
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Alexey Melnikov
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Ned Freed
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Lars Eggert
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Magnus Westerlund
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Lars Eggert
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Arnt Gulbrandsen
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Sabahattin Gucukoglu
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Joe Touch
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Joe Touch
- Re: [yam] draft-daboo-srv-email: POP3S/IMAPS? Lars Eggert