ietf-asrg
[Top] [All Lists]

Re: [Asrg] Proposal for transition to authenticated email

2003-04-28 22:56:22
On 29 Apr 2003 00:35:41 -0500 
wayne  <wayne(_at_)midwestcs(_dot_)com> wrote:
In <01be01c30e0a$4cdc1760$0201a8c0(_at_)DXHIRX1> "Ken Hirsch"
<kenhirsch(_at_)myself(_dot_)com> writes:

Every SMTP message carries a practically unforgeable token
identifying and authenticating the previous hop ISP.

Well, if you really consider message headers unforgeable, you can
skip the cryptographic authentication!

As quoted above, only the IP address of the previous hop is
practically unforgeable.  Most other headers can be trivially forged.

:mutters something about a forward chained Received: header proposal
that (potentially) makes the (entire) Received: chain reliably
auditable.


-- 
J C Lawrence                
---------(*)                Satan, oscillate my metallic sonatas. 
claw(_at_)kanga(_dot_)nu               He lived as a devil, eh?           
http://www.kanga.nu/~claw/  Evil is a name of a foeman, as I live.
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg