ietf-mxcomp
[Top] [All Lists]

Re: Authentication and Authorization

2004-03-12 07:24:00

John,

  the domain owner is whoever has control over the RRs
in the DNS, that are associated with the domain name.

JL>    Here, I disagree with Dave. Rather than try to define "domain
JL> owner", we should try to define function; after that is agreed,
JL> we may or may not find that "ownership" of the domain makes a
JL> difference.

well, i was taking 'domain ownership' as the term already in use, but i
agree that it's better to drop the term and just talk about contents of
the RRs associated with the domain name.




Authentication   Verifying the Identity (TCP sequence numbers)
Authorization    Domain owner's statement

Which domain?

HD> The domain given in the sender's address (or whatever part of the
HD> message. That who's held responsible in case of spam).

I suggest we eliminate use of the word "sender", except as part of the
term "RFC2822 Sender".  When used without qualifiers, the term "sender"
is now ambiguous.  So which, exact, field provides the domain string on
which authorization is based?


d/
--
 Dave Crocker <dcrocker-at-brandenburg-dot-com>
 Brandenburg InternetWorking <www.brandenburg.com>
 Sunnyvale, CA  USA <tel:+1.408.246.8253>