ietf-dkim
[Top] [All Lists]

[ietf-dkim] Re: New DKIM threat analysis draft

2005-10-14 06:17:52
Douglas Otis wrote:

Path registration and DKIM?

NAK.  We're talking about technical differences, and if Jim
mentions this at all he'll probably pick the aspect "works
independent of SMTP everywhere" adding "unless some idiot
mangled the DATA in transit beyond repair" detail.

In other words DKIM does not try to fix 1123 5.3.6 (a) by
deprecating it.  The price for this are crypto, a monstrous
header field (maybe we can trim it), and SMTP DATA checks.

It's of course possible to do both, and I hope that there
can be some shortcuts for systems supporting both checks -
but that has nothing to do with DKIM threats or a future WG.

Even the OA of the SSP is not compatible.

If the SSP is "always DKIM" or the (still missing) "never
DKIM", and if the relevant domain is identical, then and
only then it should be possible to offer short cuts for
receivers.  Generally off topic here, but the point of a
"default SSP" for domains without SSP will be important.

Not another "opt-out" stunt please, two appeals were enough.

                      Bye, Frank


_______________________________________________
ietf-dkim mailing list
http://dkim.org