ietf-dkim
[Top] [All Lists]

RE: [ietf-dkim] NEW ISSUE: Security Threat: Unexpected ThirdPartySenders

2008-02-12 15:56:49
Ellen gently disagreed with me, as I thought she might:

That's not quite what we had in mind.  As I see it, 3rd party signing
is
only acceptable when the domain owner wants to permit it -- so if
there's no agreement, the entire discussion of 3rd party signing is
irrelevant.
 [ . . . ]
 3rd party signing is acceptable as long as the domain owner doesn't
explicitly forbid it by publishing a policy to that effect. Some
domain
owners may be willing to leave the decision to their individual
account
owners rather than enforce a domain wide policy one way or the other.

This is why we need to leave it out of scope, and debate more later.
*grin*

--
J.D. Falk
Receiver Products
Return Path 

_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html