ietf-mxcomp
[Top] [All Lists]

Re: Authentication and Authorization

2004-03-11 13:20:16

Ted,


TH> I believe the point we're trying to reach is:

TH> "* The MTA from which my MTA received this message is listed as being 
TH> allowed to send mail on behalf of the domain listed in the message 
TH> (or not)."

"domain listed in the message"  could mean the RFC2822 From, RFC2822
Sender, the SMTP Mail-From, or possibly even the SMTP EHLO.

Beyond "listed in the message" is being authorized by the containing
service provider to act as a client MTA.

(I'll leave out RFC2822 Reply-To, since I do not think anyone considers
it a viable example.)

These involve very different identity roles.


d/
--
 Dave Crocker <dcrocker-at-brandenburg-dot-com>
 Brandenburg InternetWorking <www.brandenburg.com>
 Sunnyvale, CA  USA <tel:+1.408.246.8253>