ietf-mxcomp
[Top] [All Lists]

Re: Authentication and Authorization

2004-03-12 05:03:13

Dave Crocker <dhc(_at_)dcrocker(_dot_)net> wrote:
[ned(_dot_)freed(_at_)mrochek(_dot_)com wrote:]
[Dave Crocker <dhc(_at_)dcrocker(_dot_)net> wrote:]
[   commenting on:
Hadmut: Policy      Receiving MTA's way to treat messages with or
Hadmut:             without Signature, LMAP authorization, or from
Hadmut:             domains without LMAP record, or DNS server down
]
That is, the policy comes from the domain owner; the server
SMTP decides whether to conform to it.

Right, although there might be some issues surrounding what
"domain owner" means.

indeed, I thought a bit about that, before sending the previous
note, but decided it was a factorable question.  (in other words,
our efforts at precision will require dealing with the point,
but it did not seem essential to include it in the previous round
of posting.)

   (I don't personally believe there's any hope that this WG can
agree on a single meaning for "policy". Nonetheless, there are
useful discussions to be held on what function(s) we envision for
the information in the DNS record(s).)

but now that you've brought it up, I suggest that we be strictly
operational:  the domain owner is whoever has control over the RRs
in the DNS, that are associated with the domain name.

   Here, I disagree with Dave. Rather than try to define "domain
owner", we should try to define function; after that is agreed,
we may or may not find that "ownership" of the domain makes a
difference.

   As the operator of a MTA, I would like to signal that I have
reason to believe the MAIL-From is a useful bounce address, and
that I will respond to <abuse(_at_)HELO(_dot_)domain> complaints if it isn't,
or if anything about the email itself is abusive. Note that I have
no desire to certify anything in particular about the contents of
the email.

   If we want to use the "authorize" word here, I take it to mean
that someone acting on behalf of HELO.domain has authorized me to
transfer email on behalf of that domain, and that this particular
email is sent under that authorization.

   I believe the "authorization" makes little difference to the
operation of the 'net, while the signals about HELO and MAIL-From
are the important functions.

--
John Leslie <john(_at_)jlc(_dot_)net>