ietf-mta-filters
[Top] [All Lists]

Re: Security review of SIEVE vacation

2005-09-13 18:49:03



On Tuesday, September 13, 2005 06:25:06 PM -0700 Ned Freed <ned(_dot_)freed(_at_)mrochek(_dot_)com> wrote:

Just as one example, any address with a mailbox name beginning 'jhutz+'
or 'jhutz=' and a domain ending in 'cmu.edu' is is probably mine, and if
I used vacation, I'd certainly want it to treat mail sent to any such
address as belonging to me, regardless of the specific host the mail
went to or what, if anything, occurs after the plus.  I'd want that even
if the mail server weren't also at CMU, if I ever decided to forward my
CMU mail off-site.  One way to deal with this sort of problem would be
to allow a match type and comparator to be specified for the addresses.

This sort of thing really needs to be up to the implementation, and the
current specification specifically allows this (section 3.5 list item 1)
You really don't want to have to require that every user specify complex
matching criteria in every vacation action they write.

No, but I sort of want to allow them to do it, rather than depending on the policies of the mail server operator to match the address forms used wherever the user is sending their mail from.

I agree the spec allows implementations to know about extra addresses using more or less arbitrary policy. If the working group feels this is sufficient, I'll live with it.

-- Jeff