ietf-mailsig
[Top] [All Lists]

RE: mailing list software, was What does the mailsig mechanismmean?

2004-11-03 15:52:04


On Wed, 3 Nov 2004, Tony Finch wrote:

On Wed, 3 Nov 2004, David Woodhouse wrote:

You may reject (or mark as spam or otherwise disadvantage) the mail only
if the most recent sender (that's the Resent-Sender from the most recent
Resent- block, the Resent-From from the most recent Resent-block, the
Sender or the From header, in that order) advertises that they will
always sign mail and there is no valid signature.

That algorithm gets the wrong "most recent sender" if you resend a message
to a mailing list. In that case the most recent sender is the mailing list
identified in the Sender: field, but the algorithm chooses your address
from the Resent-Sender: or Resent-From: field.

See my objection to PRA on exactly this point (it was hardly noticed because
of larger objection on that PRA is not compatible with current RFC2822 
recomendation for forwarding):
 http://www.imc.org/ietf-mxcomp/mail-archive/msg04750.html 

-- 
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net


<Prev in Thread] Current Thread [Next in Thread>