ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] NEW ISSUE: Security Threat: Unexpected Third PartySenders

2008-02-12 21:57:01
That's not quite what we had in mind.  As I see it, 3rd party signing
is only acceptable when the domain owner wants to permit it --

Huh?  The various mail forwarders I use at ieee.org and my college
alumni association will eventually sign stuff on the way through.  In
some cases, they may even add a Sender header or something else that
breaks the original signature.  But I'm going to accept it no matter
how the original sender fulminates.

It would be possible to design a system in which domain A says that it
endorses domain B's signature on mail with an author address at A, but
if you dig through the list archives, you'll find that we rejected
that expansion of SSP quite a while ago.

Trying to forbid random other third party signatures is, as I expect
you'd agree, just silly.

R's,
John
_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html