ietf-asrg
[Top] [All Lists]

Re: [Asrg] Implementing IPv6 DNSBLs

2010-12-14 00:33:14
On Mon, Dec 13, 2010 at 11:37 PM, Douglas Otis 
<dotis(_at_)mail-abuse(_dot_)org> wrote:

For SMTP to survive, SMTP must cryptographically authenticate the domain of
the server publicly issuing the message.  This domain must also encompass

Not necessarily. IP-based whitelisting may be Good Enough[tm] for that purpose.

Unfortunately, anyone that assumes blocking lists will be able to
selectively exclude sections of the v6 Interface, or that these addresses
will be typically assigned manually is likely in for a very rude awakening.
 No doubt while people whisper sweet v6 DNSBLs into their ear. :^)

Do not think in DNSBL terms, but from a DNSWL angle. In whitelisting
scenarios, a sub-/64 assignments are both technically and
operationally feasible and can be useful in some scenarios:

* shared hosting environments (where I don't think each user will get
a full /64)
* E-mail service providers
* 4-to-6 NAT/PAT
* Likely some more...

-- Matthias
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>