ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Delegating responsibility: a make vs. buy design decision

2006-08-18 11:04:48
Scott Kitterman wrote:

On Thursday 17 August 2006 16:50, Dave Crocker wrote:

This mechanism already exists, is notably simpler than the one being
discussed, and does not suffer the security hole that has been noted.

Simply stated:

    If the author's domain is to be used for assessment activities, then
have the signature be made with a domain that is directly related to the
author.

As was already discussed in the comments to the requirements draft, not all DNS providers give their customers the ability to do subdomain level NS delegation and so while that approach is good for those who can do it, it leaves out a portion of the potential user base.
Let's be very clear here: not every DNS provider has the ability to do TXT
records either. Those small businesses, etc, should either pressure their providers
or vote with their feet.

      Mike
_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>